Skip to content

Risk Analysis

What is Risk Analysis?

The systematic examination of risk components including threat sources, vulnerabilities, likelihood, and potential impact to understand and characterize risk.

Risk Management

Each of these is named in at least one of the same controls as risk analysis. The number is how many controls name both.

What the standards actually require on risk analysis

Requirements naming risk analysis across 6 standards, quoted from the control text.

Establish and maintain a program of risk analysis and oversight covering operations and automated systems, to identify and minimise sources of operational risk through appropriate controls and procedures and through systems that are reliable, secure and have a...

CFTC-SS-1 · Program of Risk Analysis and Oversight

Combine likelihood and impact determinations to assign a risk level to each threat and vulnerability pairing using a defined risk matrix.

RA-RISK · Risk Analysis: Determine the Level of Risk
PCI DSS 4.010 controls

If periodic scans are used to meet 5.3.2, the frequency is defined in the entity's targeted risk analysis.

5.3.2.1 · Periodic scan frequency per targeted risk analysis

LkSG Sections 4-5 - risk management system + risk analysis. SECTION 4 RISK MANAGEMENT SYSTEM: companies must establish an APPROPRIATE + EFFECTIVE risk management system to identify + prevent + mitigate + remediate human rights and environmental risks arising f...

LkSG-Sec4-RiskMgmt-Sec5-RiskAnalysis · Section 4 Risk Management System + Section 5 Annual Risk Analysis

Analyse identified AI risks considering causes, consequences, controls, uncertainty, and AI-specific characteristics.

23894-6.4.3 · AI Risk Analysis
ISO 31000:20182 controls

Requirement defined in ISO 31000:2018, clause 6.4.3 (Risk analysis). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-31000-2018::6.4.3 · Risk analysis

Questions people ask about risk analysis

What is Risk Analysis?
The systematic examination of risk components including threat sources, vulnerabilities, likelihood, and potential impact to understand and characterize risk.
Why is Risk Analysis important for compliance?
Risk Analysis is a key concept in Risk Management. Understanding risk analysis helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk Analysis?
Risk Analysis appears in the requirement text of CFTC System Safeguards (17 CFR 37, 38, 39, 49), NIST SP 800-66 Rev 2, PCI DSS 4.0, German Supply Chain Due Diligence Act (LkSG), ISO/IEC 23894:2023. Across these standards we have identified 43 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Analysis?
Explore our compliance framework pages to see how risk analysis applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Analysis applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.