Policy and Procedures
Training
Risk Assessment
Risk Disclosure
Risk Mitigation
Risk Monitoring
Response
Notification
Data Management
Communications
Each of these KPAs are rated on a scale of 1 to 5, with 1 being “Reactive” (lowest) and 5 being
“Optimized” (highest). Then, the overall TRM program is scored as the lowest KPA score –a
program is only strong as its weakest link -- with a “Plus” value indicating the number of KPAs
rated higher than the lowest KPA. For example, a program might be rated a Level 2 Plus 6.
Once the risk assessment has been completed, it should be clear what additional solutions are
required to address any potential risk or situation.