Summary
At the beginning of this chapter, we learned about the importance of risk response and monitoring. We then learned about the roles of risk owners and control owners. It is important for the risk manager to be aware of this ownership of risks and controls to take action on them and define the relevant response strategy. The next section then covered the risk response strategies – mitigation, acceptance, transfer/share, and avoid – that a risk manager can use to respond to a risk. We also noted that the goal of risk response is not to remove the risk altogether but to optimize it and use it as an opportunity instead. We then learned about the factors that the risk manager and the management team must consider before proceeding with a risk response that includes a cost-benefit analysis and thorough diligence on return on investment.
In the next chapter, we will learn about third-party risk management.