Skip to content

Strategic Risk

What is Strategic Risk?

Risks that affect or are created by an organization's business strategy and strategic objectives, including market changes and competitive threats.

Risk Management

Each of these is named in at least one of the same controls as strategic risk. The number is how many controls name both.

What the standards actually require on strategic risk

Requirements naming strategic risk across 6 standards, quoted from the control text.

Per UK Bribery Act 2010 Section 7: failure to prevent bribery offence. Implement adequate procedures defense. Requirements include (a) Proportionate procedures + (b) Top-level commitment + (c) Risk assessment + (d) Due diligence + (e) Communication + Training...

UKBRIBE-1 · Section 7 Strategic Risk Assessment and Adequate Procedures

Determine scope and applicability of the OCC Heightened Standards per 12 CFR Part 30 Appendix D Section I and the OCC Heightened Standards for Large Banks final rule (effective November 2014 + revisions).

OCCHS-1 · Scope, Applicability, and Definitions of Heightened Standards

Conduct risk assessments at the three tiers defined in NIST SP 800-30 Rev 1 Section 2.3 and aligned with NIST SP 800-39 governance tiers.

NISTSP30-2 · Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)

Execute the Assess step per NIST SP 800-39 Chapter 3 Section 3.2 using NIST SP 800-30 (Risk Assessments) as the supporting methodology.

NISTSP39-3 · Risk Assessing: Organisation, Mission, and System Level Assessments

Per NAIC ORSA Guidance Manual Section 2: assessment of risk exposure under normal and stressed conditions. Requires Quantitative Risk Assessment using actuarial + economic + statistical methods for material risk categories (underwriting + market + credit + liq...

ORSA-S2 · ORSA Manual Section 2: Insurer's Assessment of Risk Exposure

Questions people ask about strategic risk

What is Strategic Risk?
Risks that affect or are created by an organization's business strategy and strategic objectives, including market changes and competitive threats.
Why is Strategic Risk important for compliance?
Strategic Risk is a key concept in Risk Management. Understanding strategic risk helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Strategic Risk?
Strategic Risk appears in the requirement text of UK Bribery Act 2010, OCC Heightened Standards (12 CFR Part 30, Appendix D), IRM Enterprise Risk Management Framework (Institute of Risk Management), NIST SP 800-30, NIST SP 800-39. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Strategic Risk?
Explore our compliance framework pages to see how strategic risk applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Strategic Risk applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.