Skip to content

Risk Response

What is Risk Response?

The selection and implementation of options for addressing risk, including avoidance, reduction, sharing, transfer, or acceptance.

Risk Management

Each of these is named in at least one of the same controls as risk response. The number is how many controls name both.

What the standards actually require on risk response

Requirements naming risk response across 6 standards, quoted from the control text.

Strategic direction that describes appropriate risk response options is established and communicated

NIST-CSF-GV.RM-04 · Strategic direction that describes appropriate risk response options is established and communicated

Requires findings raised by assessments, monitoring activity and audits, covering both security and privacy, to be responded to in line with the organization's stated risk tolerance, so each is remediated, mitigated, transferred or formally accepted.

NIST800-RA-7 · Risk response

Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so identified risk is treated rather than only recorded.

RA-7 · Risk Response
FedRAMP High1 control

Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so identified risk is treated rather than only recorded.

RA-7 · Risk Response

Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so that identified risk is treated rather than only recorded.

fedramp-moderate::RA-7 · Risk Response

Responses to the AI risks deemed high priority as identified by the Map function, are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting.

AIRMF-MN-1.3 · Responses to the AI risks deemed high priority as identified by the MAP function are developed, planned, and documented, and risk response options can include mitigating, transferring, avoiding, or accepting

Questions people ask about risk response

What is Risk Response?
The selection and implementation of options for addressing risk, including avoidance, reduction, sharing, transfer, or acceptance.
Why is Risk Response important for compliance?
Risk Response is a key concept in Risk Management. Understanding risk response helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk Response?
Risk Response appears in the requirement text of NIST Cybersecurity Framework 2.0, NIST SP 800-53 Rev 5, COSO Internal Control - Integrated Framework (2013), FedRAMP High, FedRAMP Moderate. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Response?
Explore our compliance framework pages to see how risk response applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Response applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.