Risk owners and control owners
In the previous chapters, we learned about various methods for performing a risk assessment and the importance of having a risk register to catalog all organizational risks in one place. An extremely important part of the risk catalog is having an owner for each of the identified risks to ensure the accountability of these risks is considered and a dedicated individual can be reached to approve the risk response strategy.
In the absence of a risk owner, the organization will have a difficult time finding the accountable individual responsible for risk treatment and the risks may go unnoticed. The risk owner should be a manager or a member of the executive committee that is relevant to the identified risks so that they can provide the budget and mandate the risk response based on the risk practitioner’s guidance.
Similarly, each risk should have a single risk owner who can speak with authority on the risk response and attest true accountability...