Risk Ownership and Accountability
The following are some important aspects with respect to risk ownership and accountability:
- For successful risk management, each risk should have assigned ownership and accountability.
- Risk should be owned by a senior official who has the necessary authority and experience to select the appropriate risk response based on an analysis and any guidance provided by the risk practitioner.
- Risk owners should also own the associated controls and ensure the effectiveness and adequacy of those controls.
- Risk should be assigned to an individual employee rather than a group or a department. Allocating accountability to a department will circumvent ownership.
- Accountability for risk management lies with senior management and the board.
- Risk ownership is best established by mapping the risk to specific business process owners.
- Details of the risk owner should be documented in the risk register.
- The results of risk...