من أنا
المقالات
الوظائف
التواصل معي

The risk management cycle

Risk management is not an annual meeting nor a file prepared for the auditor. It is a repeating cycle with known steps, turning for as long as the business runs.

Chapter 1 · Lesson 2 of 59 min readBeginner level

The recognised professional frameworks — whatever terminology they use — agree on one path: understand the context, identify the risks, analyse them, evaluate them, treat them, then monitor, review and report.

1 The steps of the cycle

1
Context

Objectives, environment and the boundaries of the activity

2
Identification

What might happen and have an effect?

3
Analysis

Impact, likelihood and existing controls

4
Evaluation

Is the risk acceptable, or does it need treating?

5
Treatment

Avoid, reduce, transfer or accept

6
Monitoring

Indicators and periodic follow-up

7
Communication

Reporting to management, the committee and the board

A continuous cycle: the outputs of monitoring become inputs to identification all over again

2 Step zero: establishing the context

Before hunting for risks, you must know what you are protecting. Risks are measured by their effect on specific objectives, and with no clear objective the exercise becomes a list of worries. The context covers:

  • The objectives of the organisation, department or project being assessed.
  • The external environment: the market, competition, regulation, the economy.
  • The internal environment: structure, IT systems, capabilities, culture.
  • The assessment criteria: the impact and likelihood scales, and the acceptance thresholds.

3 Analysis and evaluation: what is the difference?

AnalysisEvaluation
The questionHow large is the risk?Do we accept it or not?
The outputA risk score (impact × likelihood)A decision: acceptable / needs treatment / unacceptable
The reference pointData, experience and existing controlsRisk appetite and approved tolerance limits

Who decides to accept?

Not the analyst nor the risk officer, but the risk owner within their authority: that may be a department head, the CEO, or the board if the risk exceeds the approved tolerance limits.

4 Monitoring and review

Risk is a moving thing: it rises and falls as the market, the technology and the team change. So the cycle needs:

  • Periodic review of the risk register — usually quarterly — and immediately after a major event.
  • Key risk indicators (KRIs) that warn before the event, such as a rise in overdue receivables.
  • Follow-up on treatment plans: were they delivered on time? And did they actually reduce the risk?
  • Lessons learned from events that occurred inside the organisation and outside it.
The full cycle applied to a single risk

Context: finance’s objective is to close the accounts within 10 days of month end.

Identification: because the close depends on one employee who knows the system, it may be delayed when they are away.

Analysis: impact is medium (delayed reports and management decisions), likelihood is high (leave and travel).

Evaluation: the score is above finance’s approved acceptance threshold → it needs treatment.

Treatment: train a second employee, document the close steps, and set up backup rights in the system.

Monitoring: a “days to close” indicator monthly, and a quarterly review of the risk.

A common mistake

Assessing risks once when the framework is built and then forgetting it. A register that has not changed in a year means either the organisation has stopped, or nobody is reading it.

Lesson summary

  • The cycle: context → identification → analysis → evaluation → treatment → monitoring → communication.
  • Without defined objectives, risk assessment becomes a list of worries.
  • Analysis measures the size; evaluation decides acceptance against approved thresholds.
  • The decision to accept a risk belongs to the risk owner within their authority, not to the risk team.
  • Monitoring with indicators and periodic review keeps the framework alive.

5 Test your understanding

Three quick questions

Pick the answer you believe is correct and you will see the result immediately.

1. Which step comes before identifying risks?

2. Who holds the decision to accept a risk that exceeds the tolerance limits?

3. What is the purpose of a key risk indicator (KRI)?

Sources and review: the steps of the risk management cycle as settled in the internationally recognised professional frameworks for enterprise risk management. Last reviewed: September 2026. Educational content, written to build understanding.