Risk Exposure
What is Risk Exposure?
The degree to which an organization is vulnerable to a particular risk, typically measured by the potential loss and likelihood of occurrence.
Frameworks that govern risk exposure
What the standards actually require on risk exposure
Requirements naming risk exposure across 6 standards, quoted from the control text.
IFRS S2 Metrics requires comprehensive quantification of climate-related risks + opportunities + emissions following established protocols.
ISSB-IFRS-S2-Metrics-Scope1-2-3-GHG-Emissions-PhysicalRisk-TransitionRisk-Opportunities-GHGProtocol · ISSB IFRS S2 Climate Metrics - Scope 1, 2, and 3 Greenhouse Gas (GHG) Emissions per GHG Protocol + Physical Risk Exposure + Transition Risk Exposure + Climate-Related Opportunities + Verification + Assurance →Above the enumerated list in Article 21(2) sits a duty to size the whole programme correctly. Measures must be technical, operational and organisational together, must protect both the network and information systems and the physical environment those systems...
nis2-directive::Art.21.1 · Take proportionate all-hazards measures calibrated to the entity's own risk exposure →Per NAIC ORSA Guidance Manual Section 2: assessment of risk exposure under normal and stressed conditions. Requires Quantitative Risk Assessment using actuarial + economic + statistical methods for material risk categories (underwriting + market + credit + liq...
ORSA-S2 · ORSA Manual Section 2: Insurer's Assessment of Risk Exposure →Disclose the seven cross industry metric categories: greenhouse gas emissions with Scope 1, Scope 2 and Scope 3 measured under the Greenhouse Gas Protocol and disaggregated as required, transition risk exposure, physical risk exposure, climate related opportun...
AASB-S2-P29 · Cross Industry Metric Categories →A bank should be able to capture and aggregate all material risk data across the banking group. Data should be available by business line, legal entity, asset type, industry, region and other groupings, as relevant for the risk in question, that permit identif...
BCBS239-P4 · Completeness →Subject the key management platform, together with its governing policy and process, to audit at a frequency proportionate to its risk exposure, no less than yearly and again after any security event.
CCM-CEK-09 · Encryption and Key Management Audit →Questions people ask about risk exposure
What is Risk Exposure?
Why is Risk Exposure important for compliance?
Which compliance frameworks address Risk Exposure?
Where can I learn more about Risk Exposure?
See how Risk Exposure applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.