4.7 Changes to IT Risk Profile
Risk practitioners should ensure that the risk profile of the organization should be evaluated at periodic intervals to determine the changes to the risk profile.
Risk profile may change on account of following factors:
Implementation of new technologies
Changes in business processes
Changes in regulatory requirements
Changes in market demand and customer requirements
Changes in competitor’s policy
Risk profile of an organization may be affected by the cascading effects of minor changes.
With change in risk profile, objectives and goals of the risk management process should be reviewed to ensure that they continue to be aligned with the goals and objectives of the organization.
Changes in the organization’s risk profile is to be updated in the risk register. Risk registers should be able to provide status of the organization’s current risk profile.
Primary reason to determine the changes is the risk profile is to evaluate whether additional response is required to reduce the risk.
Risk profile of the organization changes over the time. Periodic monitoring of key risk indicators proactively identifies the changes in the risk profile. Once changes are identified, additional controls can be implemented to keep the risk within the appetite.
Key aspects from CRISC exam perspective