<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What are the five risk mitigation strategies?"
title: "What Are the Five Risk Mitigation Strategies"
seoTitle: "The 5 Risk Mitigation Strategies, Explained"
summary: "The five risk mitigation strategies are avoid, reduce, transfer, accept, and share. Avoid removes the activity, reduce lowers likelihood or impact through controls, transfer moves financial consequence to an insurer or counterparty, accept documents a decision to live with the risk, and share splits it across parties. Older frameworks list four by folding share into transfer. ISO 31000 uses different wording for the same set."
publishedAt: "2026-08-18"
keywords:
  - "five risk mitigation strategies"
  - "risk treatment options"
  - "avoid reduce transfer accept"
  - "ISO 31000 risk treatment"
  - "5 steps of the ORM process"
  - "5 parts of ORM"
  - "three main mitigation strategies"
pillar: "Beyond SOC 2"
faqs:
  - question: "What are the 5 risk mitigation strategies?"
    answer: "Avoid, reduce, transfer, accept, and share. Avoid stops the activity entirely, reduce applies controls to lower likelihood or impact, transfer shifts financial consequence to another party, accept records a decision to tolerate it, and share distributes it across several parties."
  - question: "Why do some sources list four instead of five?"
    answer: "Because share and transfer are closely related and older frameworks fold them together. Four is avoid, reduce, transfer, accept. The five-item version separates sharing (a joint venture, a consortium) from transferring (insurance, contractual indemnity)."
  - question: "Does accepting a risk satisfy an auditor?"
    answer: "Yes, when it is documented. Acceptance is a legitimate treatment provided the decision is recorded, the accepting party had authority, and the residual risk is stated. What fails an audit is an unrecorded acceptance, which is indistinguishable from having missed the risk."
---

## What are the five risk mitigation strategies?

The five risk mitigation strategies are **avoid, reduce, transfer, accept, and share**. Avoid removes the activity that creates the risk. Reduce applies controls that lower likelihood or impact. Transfer moves the financial consequence to another party, usually an insurer. Accept documents a deliberate decision to tolerate the risk. Share distributes it across several parties. Every risk in a register ends up with one of these five attached to it.

### The five strategies

| Strategy | What you do | Example |
|---|---|---|
| **Avoid** | Stop or never start the activity | Decline to store card data at all |
| **Reduce** | Apply controls that lower likelihood or impact | Enforce MFA, encrypt at rest, run backups |
| **Transfer** | Move the financial consequence elsewhere | Cyber insurance, contractual indemnity |
| **Accept** | Document a decision to tolerate it | Accept the residual risk of a legacy system due for decommission |
| **Share** | Distribute across parties | A joint venture where both parties carry part of the exposure |

## Four or five

Some frameworks list four by folding **share** into **transfer**, and the two are genuinely close. The distinction is that transfer moves consequence to someone whose business is absorbing it, while sharing splits it among parties who all carry part of the outcome.

**ISO 31000** uses different vocabulary for the same set, describing risk treatment options that include avoiding the risk, removing the source, changing likelihood, changing consequences, sharing, and retaining. The mapping is direct even though the words differ, so a register built on either vocabulary satisfies the other.

## Operational risk management, the five-step version

A related list answers "the 5 steps of the ORM process", which is a different thing: a procedure rather than a set of options.

1. Identify hazards
2. Assess the hazards
3. Make risk decisions
4. Implement controls
5. Supervise and review

The five mitigation strategies are what step 3 chooses between. Confusing the two lists is common because both are five items and both use the word risk.

## What an auditor actually tests

Not whether you chose the right strategy. Auditors test whether the decision was **made, recorded, and owned**.

- Every risk in the register has a treatment recorded against it
- The person who accepted a risk had the authority to accept it
- Residual risk is stated after treatment, not just inherent risk
- Treatments that were decided actually got implemented

Acceptance is the one that surprises people. Accepting a risk is entirely legitimate and auditors see it constantly. What fails is an *undocumented* acceptance, because from the outside it looks identical to having missed the risk altogether.

This is also the most common gap in a young risk register: risks are listed with owners and treatment plans, and the inherent and residual scores are blank.
