Skip to content

Risk Taxonomy

What is Risk Taxonomy?

A classification system that categorizes risks into a hierarchical structure of risk types and sub-types for consistent identification and reporting.

Risk Management

Each of these is named in at least one of the same controls as risk taxonomy. The number is how many controls name both.

What the standards actually require on risk taxonomy

Requirements naming risk taxonomy across 6 standards, quoted from the control text.

HKMA TM-G-12 controls

HKMA TM-G-1 Governance of Technology Risk. (1) BOARD AND SENIOR MANAGEMENT OVERSIGHT OF TECHNOLOGY RISK (TM-G-1.2.1) - Board approval of IT strategy + technology risk appetite + risk tolerance; senior management accountability + governance structure;

HKMA-TMG1-Governance-Board-Framework-Roles · TM-G-1 Governance - Board + Senior Mgmt Oversight + Technology Risk Management Framework + Roles

The IRM Risk Management Process is a 5-stage continuous cycle aligned closely with ISO 31000:2018 + COSO ERM 2017. (1) Risk Identification: systematic identification of risks through workshops + interviews + SWOT/PESTLE analysis + scenario analysis + bow-tie a...

IRM-Process-Identification-Analysis-Evaluation-Treatment-Monitoring-Review-ISO31000-Aligned · IRM Risk Management Process - 5-Stage Cycle + Identification + Analysis (Inherent/Residual) + Evaluation + Treatment (4Ts Tolerate/Treat/Transfer/Terminate) + Monitoring + Review + Communication + Risk Register

Determine scope and applicability of the OCC Heightened Standards per 12 CFR Part 30 Appendix D Section I and the OCC Heightened Standards for Large Banks final rule (effective November 2014 + revisions).

OCCHS-1 · Scope, Applicability, and Definitions of Heightened Standards

Per NAIC ORSA Guidance Manual Section 2: assessment of risk exposure under normal and stressed conditions. Requires Quantitative Risk Assessment using actuarial + economic + statistical methods for material risk categories (underwriting + market + credit + liq...

ORSA-S2 · ORSA Manual Section 2: Insurer's Assessment of Risk Exposure

Describe how processes for identifying, assessing, and managing climate-related risks are integrated into the organisation's overall risk management framework, including the linkage between climate risk and enterprise risk taxonomy.

TCFD-RM-C · Integration of Climate Risks into Overall Risk Management

Questions people ask about risk taxonomy

What is Risk Taxonomy?
A classification system that categorizes risks into a hierarchical structure of risk types and sub-types for consistent identification and reporting.
Why is Risk Taxonomy important for compliance?
Risk Taxonomy is a key concept in Risk Management. Understanding risk taxonomy helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk Taxonomy?
Risk Taxonomy appears in the requirement text of HKMA TM-G-1, IRM Enterprise Risk Management Framework (Institute of Risk Management), Monetary Authority of Singapore Technology Risk Management Guidelines, OCC Heightened Standards (12 CFR Part 30, Appendix D), Own Risk and Solvency Assessment (ORSA) - NAIC Model Act. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Taxonomy?
Explore our compliance framework pages to see how risk taxonomy applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Taxonomy applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.