Risk Review
What is Risk Review?
A periodic assessment of the risk landscape, control effectiveness, and risk management processes to ensure they remain current and effective.
Terms that appear alongside risk review
Each of these is named in at least one of the same controls as risk review. The number is how many controls name both.
- privacy risk 4 shared controls
- audit 4 shared controls
- tone at the top 3 shared controls
- due diligence 3 shared controls
- risk tolerance 3 shared controls
- joint controllers 3 shared controls
- risk appetite 3 shared controls
- risk appetite statement 3 shared controls
Frameworks that govern risk review
What the standards actually require on risk review
Requirements naming risk review across 6 standards, quoted from the control text.
Identify and address concentration risk and systemic risk where multiple suppliers share common dependencies.
ISO22318-9.1 · Concentration and Systemic Risk Review →Review privacy risks periodically and on trigger events such as new processing, breaches, or regulatory updates.
ISO27557-9.2 · Privacy Risk Review →Sets out the broader list of critical raw materials (high economic importance and high supply risk), reviewed at least every three years, which triggers monitoring, circularity and reporting obligations across the Regulation.
CRMA-Art.4 · List of critical raw materials →Aviation supply chain cybersecurity covers: (a) Executive Order 14028 'Improving the Nation's Cybersecurity' SBOM + secure software development practices + NIST SSDF (SP 800-218) alignment;
FAA-CSA-SupplyChain · Supply Chain Cybersecurity (CISA + NIST SSDF + Executive Orders alignment) →GAMP 5 SUPPLIER ASSESSMENT + OPERATIONAL PHASE + CHANGE CONTROL + PERIODIC REVIEW. SUPPLIER ASSESSMENT: pre-engagement qualification + risk-based depth (lighter for Cat 1/3 + deeper for Cat 4/5);
GAMP5-Supplier-Operations-Change-Periodic · Supplier Assessment, Operational Phase, Change Control and Periodic Review →Section 1.6 introduces two key Pharmaceutical Quality System (PQS) Enablers - Knowledge Management and Quality Risk Management. Section 4.1 Knowledge Management: systematic approach to acquiring + analysing + storing + disseminating information related to prod...
ICH-Q10-Section1-Enablers-KnowledgeMgmt-QRM-FoundationICH-Q8-Q9 · ICH Q10 Section 1 - PQS Enablers + Knowledge Management + Quality Risk Management (ICH Q9 Foundation) →Questions people ask about risk review
What is Risk Review?
Why is Risk Review important for compliance?
Which compliance frameworks address Risk Review?
Where can I learn more about Risk Review?
See how Risk Review applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.