Screenata

Beyond SOC 2

What are the five risk mitigation strategies?

August 18, 20263 min read

What are the five risk mitigation strategies?

The five risk mitigation strategies are avoid, reduce, transfer, accept, and share. Avoid removes the activity that creates the risk. Reduce applies controls that lower likelihood or impact. Transfer moves the financial consequence to another party, usually an insurer. Accept documents a deliberate decision to tolerate the risk. Share distributes it across several parties. Every risk in a register ends up with one of these five attached to it.

The five strategies

StrategyWhat you doExample
AvoidStop or never start the activityDecline to store card data at all
ReduceApply controls that lower likelihood or impactEnforce MFA, encrypt at rest, run backups
TransferMove the financial consequence elsewhereCyber insurance, contractual indemnity
AcceptDocument a decision to tolerate itAccept the residual risk of a legacy system due for decommission
ShareDistribute across partiesA joint venture where both parties carry part of the exposure

Four or five

Some frameworks list four by folding share into transfer, and the two are genuinely close. The distinction is that transfer moves consequence to someone whose business is absorbing it, while sharing splits it among parties who all carry part of the outcome.

ISO 31000 uses different vocabulary for the same set, describing risk treatment options that include avoiding the risk, removing the source, changing likelihood, changing consequences, sharing, and retaining. The mapping is direct even though the words differ, so a register built on either vocabulary satisfies the other.

Operational risk management, the five-step version

A related list answers "the 5 steps of the ORM process", which is a different thing: a procedure rather than a set of options.

  1. Identify hazards
  2. Assess the hazards
  3. Make risk decisions
  4. Implement controls
  5. Supervise and review

The five mitigation strategies are what step 3 chooses between. Confusing the two lists is common because both are five items and both use the word risk.

What an auditor actually tests

Not whether you chose the right strategy. Auditors test whether the decision was made, recorded, and owned.

  • Every risk in the register has a treatment recorded against it
  • The person who accepted a risk had the authority to accept it
  • Residual risk is stated after treatment, not just inherent risk
  • Treatments that were decided actually got implemented

Acceptance is the one that surprises people. Accepting a risk is entirely legitimate and auditors see it constantly. What fails is an undocumented acceptance, because from the outside it looks identical to having missed the risk altogether.

This is also the most common gap in a young risk register: risks are listed with owners and treatment plans, and the inherent and residual scores are blank.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.