من أنا
المقالات
الوظائف
التواصل معي

Treatment, controls and monitoring

We have identified the risk and measured it. The practical question remains: what do we do about it? There are four options and no fifth — and the tools for delivering them are controls.

Chapter 1 · Lesson 5 of 59 min readBeginner level

Acceptance is a decision, not neglect. Accepting a risk knowing its size and monitoring it is one thing; leaving it because you never noticed it is something else entirely.

1 The four treatment options

1
Avoid

Stop the activity that creates the risk

2
Reduce

Controls that lower the likelihood or the impact

3
Transfer

Insurance, outsourcing or a contractual clause

4
Accept

Documented approval, with monitoring

Choosing between the four balances the cost of treatment against the size of the risk

OptionWhen is it used?Example
AvoidThe risk is severe and the return does not justify itDeclining to operate in a market that is high-risk from a regulatory standpoint
ReduceThe most common option, where the cause can be controlledDual authorisation on bank transfers
TransferThe impact is large and the likelihood lowFire insurance, or outsourcing operations to a specialist
AcceptThe risk is within appetite and treatment costs more than its impactAccepting slight price volatility in a non-material input

The cost-benefit rule

A control should never cost more than the expected loss from the risk. A control costing a million riyals to protect against a risk with an impact of a hundred thousand is bad management, not prudence.

2 Types of control

TypeIts functionExamples
PreventiveStops the risk before it occursSegregation of duties · system access rights · training · dual authorisation
DetectiveCatches it quickly after it occursBank reconciliations · surprise stock counts · exception reports
CorrectiveRemedies the effect and prevents recurrenceA continuity plan · backups · amending the procedure
DirectiveGuides the required behaviourPolicies · regulations · written instructions

A healthy mix combines them: preventive alone can be circumvented, and detective alone comes too late.

3 The three lines of defence

1
First line

Operating departments: own the risk and apply the controls

2
Second line

Risk and compliance: set the framework and monitor

3
Third line

Internal audit: independent assurance to the board

Three lines that do not overlap: whoever executes is not whoever monitors, and neither is whoever assures

A common confusion

Asking internal audit to write the risk register and implement the controls. Once it does, it loses its independence and ends up auditing its own work.

4 The treatment plan

Every treatment needs a written plan answering five questions: what will we do? Who is responsible? By when? With what resources? And how will we know it worked? Without a date and an owner, a plan is a wish.

From a risk to a plan

The risk: because there is no second authorisation on transfers, a fraudulent transfer may be executed, causing a direct cash loss.

ActionTypeOwnerDate
Enable dual authorisation for every transfer above 50,000PreventiveCFOWithin a month
A daily report of large transfers for reviewDetectiveSenior accountantImmediately
Train the team on common fraud techniquesDirectiveHRWithin a quarter
A recovery procedure and bank contact on suspicionCorrectiveCFOAlways ready

Success indicator: zero transfers executed on a single authorisation, and any exception detected in under 24 hours.

5 Monitoring with indicators

A key risk indicator (KRI) is a number tracked periodically to reveal a risk drawing closer before it materialises, with an agreed alert threshold:

RiskIndicatorAlert threshold
Collection failuresShare of receivables over 90 days10%
Operational outageNumber of system failures per month3 failures
Loss of key peopleEmployee turnover rate15% a year
Regulatory breachNumber of requirements past their deadlineZero tolerance

Chapter 1 summary

  • There are four treatment options: avoid, reduce, transfer, accept — and acceptance is a documented decision, not neglect.
  • Controls come in types: preventive, detective, corrective and directive, and they are combined.
  • The cost of a control must not exceed the expected loss from the risk.
  • The three lines of defence separate execution, monitoring and independent assurance.
  • A treatment plan with no owner, date and success indicator is not a plan.

6 Test your understanding

Three quick questions

Pick the answer you believe is correct and you will see the result immediately.

1. Buying a fire insurance policy represents which option?

2. The monthly bank reconciliation is which type of control?

3. In the three lines of defence, who owns the risk and applies the controls day to day?

Sources and review: the treatment options, the classification of controls, the three lines of defence model and key risk indicators per the recognised professional frameworks for risk management and internal control. The examples and figures are illustrative. Last reviewed: September 2026.