Business Risk
What is Business Risk?
The potential for events or conditions to adversely affect an organization's ability to achieve its business objectives and maintain operations.
Terms that appear alongside business risk
Each of these is named in at least one of the same controls as business risk. The number is how many controls name both.
- compliance 3 shared controls
- risk assessment 3 shared controls
- information security 3 shared controls
- data protection 2 shared controls
- due diligence 2 shared controls
- remediation 2 shared controls
- gap analysis 2 shared controls
- grc 2 shared controls
Frameworks that govern business risk
What the standards actually require on business risk
Requirements naming business risk across 6 standards, quoted from the control text.
VASPs must conduct periodic business risk assessments addressing operational, financial, and reputational risks.
CRM-4 · Business Risk Assessment →Test objectives, success criteria, and threat scenarios must be agreed in advance so findings and the final report can be assessed against business risk rather than raw vulnerability counts.
PTES-PRE-3 · Goals and Success Criteria →Classify physical and logical assets by the business risk they carry, and record the classification.
CCM-DCS-05 · Assets Classification →Recommendation 10 (Customer Due Diligence / CDD): financial institutions should be required to undertake CDD measures: (a) identifying the customer + verifying that customer's identity using reliable + independent source documents + data + information;
FATF-R.10_11 · Customer Due Diligence + Record Keeping (FATF R.10 and R.11) →HKMA SPM implementation roadmap + AI compliance + supervisory dialogue. ORGANIZATIONAL ROLES at AI: (a) BOARD + RISK COMMITTEE - SPM governance oversight + module-by-module compliance + sectoral risk integration + reporting;
HKMA-SPM-Implementation-AI-Compliance-SupervisoryDialogue · HKMA SPM Implementation Roadmap, AI Compliance Roles, Supervisory Dialogue and Sectoral Engagement →Capability + improvement + integration + coordination ensure that the IRM risk management framework matures and aligns with the wider ecosystem.
IRM-Capability-Training-CMIRM-Improvement-Integration-Coord-ISO31000-COSO-FRC-Walker-Basel-APRA · IRM Capability + Risk Training + CMIRM/Diploma Qualifications + Continual Improvement + Integration with Strategy + Coordination ISO 31000 + COSO ERM + UK FRC + Walker Review + Basel + APRA + GRC Software →Questions people ask about business risk
What is Business Risk?
Why is Business Risk important for compliance?
Which compliance frameworks address Business Risk?
Where can I learn more about Business Risk?
See how Business Risk applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.