Requirements of risk assessment
Risk assessment is an important tool in the arsenal of risk practitioners. Risk assessments help organizations determine the level of risk and mitigate it according to the risk appetite of the organizations. Risk assessments also help organizations to be more proactive in implementing controls for unforeseen risks instead of being reactive to adverse risk scenarios.
The following table details some of the legal and regulatory compliance requirements for conducting a risk assessment:
Regulation/Law |
Risk assessment requirements section |
Canada – The Personal Information Protection and Electronic Documents Act (PIPEDA) |
Principles 1,3, and 7 |
EU Directive 2016/679 – General Data Protection Regulation (GDPR) |
Article 36. 1, 7(c), 7(d), and 11 |