Skip to content

Risk Review

What is Risk Review?

A periodic assessment of the risk landscape, control effectiveness, and risk management processes to ensure they remain current and effective.

Risk Management

Each of these is named in at least one of the same controls as risk review. The number is how many controls name both.

What the standards actually require on risk review

Requirements naming risk review across 6 standards, quoted from the control text.

ISO 223181 control

Identify and address concentration risk and systemic risk where multiple suppliers share common dependencies.

ISO22318-9.1 · Concentration and Systemic Risk Review

Review privacy risks periodically and on trigger events such as new processing, breaches, or regulatory updates.

ISO27557-9.2 · Privacy Risk Review

Sets out the broader list of critical raw materials (high economic importance and high supply risk), reviewed at least every three years, which triggers monitoring, circularity and reporting obligations across the Regulation.

CRMA-Art.4 · List of critical raw materials

Aviation supply chain cybersecurity covers: (a) Executive Order 14028 'Improving the Nation's Cybersecurity' SBOM + secure software development practices + NIST SSDF (SP 800-218) alignment;

FAA-CSA-SupplyChain · Supply Chain Cybersecurity (CISA + NIST SSDF + Executive Orders alignment)

GAMP 5 SUPPLIER ASSESSMENT + OPERATIONAL PHASE + CHANGE CONTROL + PERIODIC REVIEW. SUPPLIER ASSESSMENT: pre-engagement qualification + risk-based depth (lighter for Cat 1/3 + deeper for Cat 4/5);

GAMP5-Supplier-Operations-Change-Periodic · Supplier Assessment, Operational Phase, Change Control and Periodic Review

Section 1.6 introduces two key Pharmaceutical Quality System (PQS) Enablers - Knowledge Management and Quality Risk Management. Section 4.1 Knowledge Management: systematic approach to acquiring + analysing + storing + disseminating information related to prod...

ICH-Q10-Section1-Enablers-KnowledgeMgmt-QRM-FoundationICH-Q8-Q9 · ICH Q10 Section 1 - PQS Enablers + Knowledge Management + Quality Risk Management (ICH Q9 Foundation)

Questions people ask about risk review

What is Risk Review?
A periodic assessment of the risk landscape, control effectiveness, and risk management processes to ensure they remain current and effective.
Why is Risk Review important for compliance?
Risk Review is a key concept in Risk Management. Understanding risk review helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk Review?
Risk Review appears in the requirement text of ISO 22318, ISO/IEC 27557:2022 - Organisational Privacy Risk Management, Critical Raw Materials Act (Proposed Regulation COM(2023) 192), FAA Cybersecurity Framework for Aviation, GAMP 5 - Good Automated Manufacturing Practice. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Review?
Explore our compliance framework pages to see how risk review applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Review applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.