Risk Owner

The risk owner is the named person accountable for a particular risk: they assess it, decide on its treatment, accept the residual risk and are answerable for monitoring it. The role needs decision and budget authority in the area concerned, which is why it sits in the business function, not in the staff unit that runs the process.

GRCLast reviewed:

Without named risk owners a risk register stays a collection of observations. Only attaching a name turns it into decisions that are taken, owned and followed up. The risk owner is therefore less a documentation field than the point at which risk management is connected to the line organisation.

What the risk owner decides

  1. Confirm the assessment: are likelihood and impact plausible from a business point of view?
  2. Choose the treatment: avoid, reduce, share or accept.
  3. Commission the controls: with a deadline, an owner and resources.
  4. Accept the residual risk, or escalate it where it exceeds their own authority.
  5. Monitor: report changes in the situation and the effectiveness of the controls.

The last point is what separates the owner from an approver. The role does not end when the treatment plan is approved.

How it differs from neighbouring roles

RoleAccountable forTypical holder
Risk ownerthe risk and the decision on its treatmentarea or process owner with a budget
Action ownerthe implementation of a single control, in time and qualitysubject-matter or project lead
Asset owneran information asset across its lifecyclethe business function the asset serves
Process ownerthe performance and metrics of a processline manager
Information security officer or risk managermethod, consolidation, reportingstaff function

The roles may coincide in one person, but not between the owner and the person responsible for the method: whoever runs the process should not also decide on accepting its results.

The basis in the standard

ISO/IEC 27001 anchors the role in the risk process: clause 6.1.2 requires a risk owner to be determined for every identified risk, and under clause 6.1.3 the risk owners' approval of the risk treatment plan and their acceptance of the residual risks have to be obtained and held as documented information. Auditors examine exactly those two pieces of evidence, often by questioning a risk owner directly about one of their risks. Anyone who does not know their own assignment makes the assignment as a whole open to challenge.

General risk management frameworks such as ISO 31000 state the same principle as the alignment of accountability and authority at one level.

Selection: who qualifies

The right person is one who can influence the cause of the risk and has the resources to commission controls. Three practical rules follow:

  • Always a person, never a committee. A committee can advise, but it cannot be personally accountable.
  • As low as possible, as high as necessary. The level has to match the size of the residual risk; above defined thresholds, executive management decides.
  • Not automatically IT. The risk that a business application fails belongs to the function that owns the process; IT is the action owner.

The assignments that do not work

  • All IT-adjacent risks are assigned to the information security officer or the head of IT, who own neither the process nor the budget.
  • The owner learns of their role only during the audit.
  • Residual risks are accepted by people whose authority to do so is not defined.
  • When people change jobs the assignment is not handed over, so risks formally belong to someone who has left the area.
Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework