Analysing preventative and directive controls is particularly important in risk and control self-assessments as they tend to reduce the likelihood of a risk occurring, whereas detective and corrective controls tend to reduce the impact that the firm suffers. Most risk managers aim to have a balance, where possible, of controls which mitigate a risk before the event and its effects after the event. As illustrated in the paragraph above, this is not always possible.
When a variety of types of controls have been identified, their effects can be assessed on the inherent likelihood and inherent impact scores. This provides validation and confirmation of residual likelihood and residual impact scores if the ...
Get Mastering Risk Management now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.