Risk treatment
At its simplest, risk treatment involves a process to modify a risk by changing the consequences that could occur or their likelihood. This process requires creative consideration of options and detailed design, both inputs being necessary to find and select the best risk treatment.
Once implemented, risk treatments will either create new controls or amend existing controls.
Risk treatment takes place in two distinctive contexts:
In the proactive context, where an organisation has successfully integrated risk management into a system of management, risk treatment is integral to and effectively indistinguishable from decision-making. Therefore, at the time a decision is finalised the risk created by the decision will be within the organisation’s risk criteria.
In a reactive context, the organisation is looking retrospectively at the risk created by decisions taken and implemented previously, and so any risk treatments found necessary will be remedial in nature.
In both contexts, those risks that the organisation judges are unacceptable should be treated.