A PRACTICAL APPROACH TO QUALITATIVE RISK APPETITE LIMITS

A practical method of setting and managing qualitative risk appetite, as will be seen in Chapter 6, Risk management and risk and control self-assessments, is to use risk assessment scores which are linked with the quality of the mitigating controls and displayed graphically, as in Figure 4.6.

Figure 4.6 Qualitative risk appetite, using risk and control self-assessment scores

This graphical representation of risk and control self-assessment scores is constructed through multiplying the gross likelihood and gross impact scores for a risk and multiplying the relevant control design and control ...

Get Mastering Risk Management now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.