<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What is risk management?"
title: "What Is Risk Management"
seoTitle: "What Is Risk Management? Definition and Process"
summary: "Risk management is the process of identifying what could stop an organisation meeting its objectives, assessing how likely and how damaging each of those things is, deciding what to do about them, and checking that the decision worked. ISO 31000 is the general standard. In compliance specifically it is the activity that produces the risk register every framework asks for, and the step most programmes skip before choosing controls."
publishedAt: "2026-08-18"
keywords:
  - "define risk management"
  - "what is risk management"
  - "cyber security risk management"
  - "define risk mitigation"
  - "risk control in risk management"
pillar: "Beyond SOC 2"
faqs:
  - question: "What is the definition of risk management?"
    answer: "The coordinated activity of identifying risks to an organisation's objectives, analysing their likelihood and impact, deciding how to treat them, implementing that treatment, and monitoring the result. ISO 31000 defines risk itself as the effect of uncertainty on objectives, which is why the objectives come first."
  - question: "What is the difference between risk management and risk mitigation?"
    answer: "Mitigation is one option within management. Risk management is the whole process; mitigation, more precisely called reduction, is the specific treatment of lowering likelihood or impact through controls. The other treatments are avoid, transfer, accept, and share."
  - question: "Why do compliance frameworks require risk management?"
    answer: "Because it is what makes a control set defensible. Without a risk assessment, controls are copied from a template and an auditor cannot tell whether they address anything real. SOC 2 CC3, ISO 27001 clause 6.1, and the HIPAA Security Rule risk analysis all exist to force that step."
---

## What is risk management?

Risk management is the process of **identifying what could stop an organisation meeting its objectives**, assessing how likely and how damaging each is, deciding what to do, and checking the decision worked. **ISO 31000** is the general standard and defines risk as the effect of uncertainty on objectives, which is why the objectives come first: without them there is no way to say what counts as a risk.

### The process

| Step | Question it answers |
|---|---|
| **Identify** | What could go wrong, and to what? |
| **Analyse** | How likely, and how bad? |
| **Evaluate** | Is that acceptable against our risk appetite? |
| **Treat** | Avoid, reduce, transfer, accept, or share |
| **Monitor and review** | Did the treatment work, and has anything changed? |

The output of steps one to four is a [risk register](/resources/answers/what-is-a-risk-register). Step five is what most programmes drop after the first year.

## Risk management, mitigation, and control

These get used interchangeably and are not the same.

- **Risk management** is the whole process above.
- **Risk mitigation**, more precisely **reduction**, is one of five treatments: lowering likelihood or impact through controls.
- **A control** is the specific safeguard implementing a treatment. MFA is a control; reducing account-takeover risk is the treatment; the register entry is the management.

The five treatments in full: avoid, reduce, transfer, accept, share. See [what are the five risk mitigation strategies](/resources/answers/what-are-the-five-risk-mitigation-strategies).

## Why compliance frameworks insist on it

Because it is what makes a control set defensible. A company that implements controls without a risk assessment has copied a template, and neither it nor its auditor can say whether those controls address anything the business actually faces.

| Framework | Where it appears |
|---|---|
| SOC 2 | CC3 series, risk identification and analysis |
| ISO 27001 | Clause 6.1, with a documented methodology |
| HIPAA | Security Rule risk analysis, the most frequently cited enforcement gap |
| NIST 800-53 | RA control family |

**HIPAA is the sharpest example.** A missing or inadequate risk analysis is one of the most common findings in HHS enforcement actions, more so than the technical failures people expect.

## Cyber security risk management specifically

Same process, narrowed to information assets and threats. The differences in practice are that the threat landscape changes faster, so review cadence matters more, and that many risks are concentrated in third parties rather than your own systems, which is why vendor risk gets its own register.

## The order that gets reversed

Most small compliance programmes start by collecting evidence, then work backwards to controls, and never do the risk assessment at all. That produces evidence for controls nobody chose, and gaps in the ones that mattered. Risk assessment first, controls from the assessment, evidence from the controls.
