Risk Taxonomy
What is Risk Taxonomy?
A classification system that categorizes risks into a hierarchical structure of risk types and sub-types for consistent identification and reporting.
Terms that appear alongside risk taxonomy
Each of these is named in at least one of the same controls as risk taxonomy. The number is how many controls name both.
- risk assessment 4 shared controls
- risk appetite 4 shared controls
- audit 4 shared controls
- technology risk 4 shared controls
- scenario analysis 3 shared controls
- operational risk 3 shared controls
- risk committee 3 shared controls
- risk management framework 3 shared controls
Frameworks that govern risk taxonomy
What the standards actually require on risk taxonomy
Requirements naming risk taxonomy across 6 standards, quoted from the control text.
HKMA TM-G-1 Governance of Technology Risk. (1) BOARD AND SENIOR MANAGEMENT OVERSIGHT OF TECHNOLOGY RISK (TM-G-1.2.1) - Board approval of IT strategy + technology risk appetite + risk tolerance; senior management accountability + governance structure;
HKMA-TMG1-Governance-Board-Framework-Roles · TM-G-1 Governance - Board + Senior Mgmt Oversight + Technology Risk Management Framework + Roles →The IRM Risk Management Process is a 5-stage continuous cycle aligned closely with ISO 31000:2018 + COSO ERM 2017. (1) Risk Identification: systematic identification of risks through workshops + interviews + SWOT/PESTLE analysis + scenario analysis + bow-tie a...
IRM-Process-Identification-Analysis-Evaluation-Treatment-Monitoring-Review-ISO31000-Aligned · IRM Risk Management Process - 5-Stage Cycle + Identification + Analysis (Inherent/Residual) + Evaluation + Treatment (4Ts Tolerate/Treat/Transfer/Terminate) + Monitoring + Review + Communication + Risk Register →Implement Technology Risk Governance + Technology Risk Management Framework + Information Asset Management per MAS TRM Chapters 2 + 3 + 5.
MAS-TRM-Governance-Chapters-2-3-Board-Senior-Management-Risk-Framework-Information-Asset-Management · MAS TRM Governance + Chapters 2-3 + Board + Senior Management + Risk Framework + Information Asset Management →Determine scope and applicability of the OCC Heightened Standards per 12 CFR Part 30 Appendix D Section I and the OCC Heightened Standards for Large Banks final rule (effective November 2014 + revisions).
OCCHS-1 · Scope, Applicability, and Definitions of Heightened Standards →Per NAIC ORSA Guidance Manual Section 2: assessment of risk exposure under normal and stressed conditions. Requires Quantitative Risk Assessment using actuarial + economic + statistical methods for material risk categories (underwriting + market + credit + liq...
ORSA-S2 · ORSA Manual Section 2: Insurer's Assessment of Risk Exposure →Describe how processes for identifying, assessing, and managing climate-related risks are integrated into the organisation's overall risk management framework, including the linkage between climate risk and enterprise risk taxonomy.
TCFD-RM-C · Integration of Climate Risks into Overall Risk Management →Questions people ask about risk taxonomy
What is Risk Taxonomy?
Why is Risk Taxonomy important for compliance?
Which compliance frameworks address Risk Taxonomy?
Where can I learn more about Risk Taxonomy?
See how Risk Taxonomy applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.