Skip to content

Risk-Based Approach

What is Risk-Based Approach?

A methodology that prioritises compliance activities and control implementation based on the level of risk they address. Risk-based approaches are central to ISO 27001, NIST CSF, GDPR, and most modern compliance frameworks.

Risk Management

Each of these is named in at least one of the same controls as risk-based approach. The number is how many controls name both.

What the standards actually require on risk-based approach

Requirements naming risk-based approach across 6 standards, quoted from the control text.

Section 11.10(a) requires VALIDATION of closed systems to ensure accuracy + reliability + consistent intended performance + the ability to discern invalid or altered records.

Part11.CSV · Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)

Customer due diligence procedures must be based on the level of ML/TF risk that different customers pose.

AMLCTF-PartB-RBA · Risk-Based Approach to CDD

Recommendation 1 (Risk-Based Approach): countries should identify + assess + understand their money laundering / terrorist financing risks + apply a RISK-BASED APPROACH to ensure that measures to prevent or mitigate ML/TF are commensurate with the risks identi...

FATF-R.1_2 · Risk-Based Approach + National Cooperation (FATF R.1 and R.2)

GAMP 5 RISK-BASED + LIFE-CYCLE + LEVERAGE-SUPPLIER + SCALABLE + CRITICAL-THINKING approach. KEY CONCEPT 1 RISK-BASED: validation effort proportional to risk to product quality + patient safety + data integrity + regulatory impact;

GAMP5-Risk-CriticalThinking · Risk-Based Approach, Critical Thinking and 5 Key Concepts

Requires that incident management be based on risk management principles and preparedness.

ISO-22320-4.3 · Risk-based approach

Audit approach considers risks and opportunities to ensure audits focus on matters significant to client.

4.g · Risk-Based Approach

Questions people ask about risk-based approach

What is Risk-Based Approach?
A methodology that prioritises compliance activities and control implementation based on the level of risk they address. Risk-based approaches are central to ISO 27001, NIST CSF, GDPR, and most modern compliance frameworks.
Why is Risk-Based Approach important for compliance?
Risk-Based Approach is a key concept in Risk Management. Understanding risk-based approach helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk-Based Approach?
Risk-Based Approach appears in the requirement text of FDA 21 CFR Part 11, AML/CTF Act 2006 (Australia), FATF 40 Recommendations, GAMP 5 - Good Automated Manufacturing Practice, ISO 22320:2018. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk-Based Approach?
Explore our compliance framework pages to see how risk-based approach applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk-Based Approach applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.