Risk-Based Approach
What is Risk-Based Approach?
A methodology that prioritises compliance activities and control implementation based on the level of risk they address. Risk-based approaches are central to ISO 27001, NIST CSF, GDPR, and most modern compliance frameworks.
Terms that appear alongside risk-based approach
Each of these is named in at least one of the same controls as risk-based approach. The number is how many controls name both.
- audit 8 shared controls
- cybersecurity 7 shared controls
- risk assessment 7 shared controls
- governance 6 shared controls
- resilience 5 shared controls
- accountability 5 shared controls
- integrity 5 shared controls
- transparency 4 shared controls
Frameworks that govern risk-based approach
What the standards actually require on risk-based approach
Requirements naming risk-based approach across 6 standards, quoted from the control text.
Section 11.10(a) requires VALIDATION of closed systems to ensure accuracy + reliability + consistent intended performance + the ability to discern invalid or altered records.
Part11.CSV · Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft) →Customer due diligence procedures must be based on the level of ML/TF risk that different customers pose.
AMLCTF-PartB-RBA · Risk-Based Approach to CDD →Recommendation 1 (Risk-Based Approach): countries should identify + assess + understand their money laundering / terrorist financing risks + apply a RISK-BASED APPROACH to ensure that measures to prevent or mitigate ML/TF are commensurate with the risks identi...
FATF-R.1_2 · Risk-Based Approach + National Cooperation (FATF R.1 and R.2) →GAMP 5 RISK-BASED + LIFE-CYCLE + LEVERAGE-SUPPLIER + SCALABLE + CRITICAL-THINKING approach. KEY CONCEPT 1 RISK-BASED: validation effort proportional to risk to product quality + patient safety + data integrity + regulatory impact;
GAMP5-Risk-CriticalThinking · Risk-Based Approach, Critical Thinking and 5 Key Concepts →Requires that incident management be based on risk management principles and preparedness.
ISO-22320-4.3 · Risk-based approach →Audit approach considers risks and opportunities to ensure audits focus on matters significant to client.
4.g · Risk-Based Approach →Questions people ask about risk-based approach
What is Risk-Based Approach?
Why is Risk-Based Approach important for compliance?
Which compliance frameworks address Risk-Based Approach?
Where can I learn more about Risk-Based Approach?
See how Risk-Based Approach applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.