Without named risk owners a risk register stays a collection of observations. Only attaching a name turns it into decisions that are taken, owned and followed up. The risk owner is therefore less a documentation field than the point at which risk management is connected to the line organisation.
What the risk owner decides
- Confirm the assessment: are likelihood and impact plausible from a business point of view?
- Choose the treatment: avoid, reduce, share or accept.
- Commission the controls: with a deadline, an owner and resources.
- Accept the residual risk, or escalate it where it exceeds their own authority.
- Monitor: report changes in the situation and the effectiveness of the controls.
The last point is what separates the owner from an approver. The role does not end when the treatment plan is approved.
How it differs from neighbouring roles
| Role | Accountable for | Typical holder |
|---|---|---|
| Risk owner | the risk and the decision on its treatment | area or process owner with a budget |
| Action owner | the implementation of a single control, in time and quality | subject-matter or project lead |
| Asset owner | an information asset across its lifecycle | the business function the asset serves |
| Process owner | the performance and metrics of a process | line manager |
| Information security officer or risk manager | method, consolidation, reporting | staff function |
The roles may coincide in one person, but not between the owner and the person responsible for the method: whoever runs the process should not also decide on accepting its results.
The basis in the standard
ISO/IEC 27001 anchors the role in the risk process: clause 6.1.2 requires a risk owner to be determined for every identified risk, and under clause 6.1.3 the risk owners' approval of the risk treatment plan and their acceptance of the residual risks have to be obtained and held as documented information. Auditors examine exactly those two pieces of evidence, often by questioning a risk owner directly about one of their risks. Anyone who does not know their own assignment makes the assignment as a whole open to challenge.
General risk management frameworks such as ISO 31000 state the same principle as the alignment of accountability and authority at one level.
Selection: who qualifies
The right person is one who can influence the cause of the risk and has the resources to commission controls. Three practical rules follow:
- Always a person, never a committee. A committee can advise, but it cannot be personally accountable.
- As low as possible, as high as necessary. The level has to match the size of the residual risk; above defined thresholds, executive management decides.
- Not automatically IT. The risk that a business application fails belongs to the function that owns the process; IT is the action owner.
The assignments that do not work
- All IT-adjacent risks are assigned to the information security officer or the head of IT, who own neither the process nor the budget.
- The owner learns of their role only during the audit.
- Residual risks are accepted by people whose authority to do so is not defined.
- When people change jobs the assignment is not handed over, so risks formally belong to someone who has left the area.