unified
UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
The organization documents its risk framing: risk appetite and tolerance statements, assumptions, constraints, priorities, and the scope and context within which risk is managed. A standardized, structured methodology for calculating, documenting, categorizing, and prioritizing risks is defined, approved, communicated, and maintained. Risk criteria and appetite statements are reviewed periodically and after significant organizational change.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- Risk Assessment & Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-RISK-03
- title
- Define risk appetite, tolerance, and risk assessment criteria
- statement
- The organization documents its risk framing: risk appetite and tolerance statements, assumptions, constraints, priorities, and the scope and context within which risk is managed. A standardized, structured methodology for calculating, documenting, categorizing, and prioritizing risks is defined, approved, communicated, and maintained. Risk criteria and appetite statements are reviewed periodically and after significant organizational change.
- domain
- Risk Assessment & Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PM-28
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.RM-02
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.RM-06
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-P2
- coverage
- full
- relationship
- superset_of
- framework
- iso-31000
- control_id
- 31000-PR2
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Risk Appetite Definition & Board Reporting oversees UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to 31000-PR2 — Scope, context and criteria
- framework
- iso-31000
- control_id
- 31000-PR2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria mitigates Client suitability, disclosure and fiduciary breaches
- strength
- related
- rationale
- Risk Appetite & Tolerance Calibration operates UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria mitigates Inadequate or absent risk assessment process
- strength
- primary
- rationale
- Defining risk appetite, tolerance and structured assessment criteria supplies the yardsticks without which risks cannot be consistently calculated, categorised or prioritised.
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to PM-28 — Risk Framing
- framework
- nist-800-53
- control_id
- PM-28
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to GV.RM-06 — Risk Management Strategy: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
- framework
- nist-csf-2
- control_id
- GV.RM-06
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to 31000-P2 — Structured and comprehensive
- framework
- iso-31000
- control_id
- 31000-P2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2018
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Risk & Resilience Framework Governance operates UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria maps_to GV.RM-02 — Risk Management Strategy: Risk appetite and risk tolerance statements are established, communicated, and maintained
- framework
- nist-csf-2
- control_id
- GV.RM-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Enterprise Risk Assessment & Portfolio Oversight Cycle oversees UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
- UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria mitigates Product, customer or market concentration
- strength
- related
- rationale