ISO 31000:2018
Process – ISO 31000:2018

ISO 31000:2018 6.4.4: Risk evaluation

Guidance: risk evaluation supports decisions by comparing the results of analysis with the risk criteria to determine where further action is needed. The comparison can lead to doing nothing further, considering treatment options, analysing further to understand the risk better, maintaining existing controls, or reconsidering the objectives themselves. Decisions should weigh the broader context and of the actual and perceived consequences for external and internal stakeholders. The outcome of evaluation should be documented, shared and then confirmed at the appropriate level of the organization.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 8 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 3 controls

  • 6.3.2 Audit planning
  • 7.4 Selecting appropriate auditor evaluation method
  • 7.5 Conducting auditor evaluation

ISO/IEC 23894:2023 · 3 controls

  • 23894-6.4.4 AI Risk Evaluation
  • ISO23894-6.3.3 AI Risk Evaluation
  • 6.4.4 Risk evaluation

ISO/IEC 29134:2023 · 2 controls

  • 29134-7.4 Risk evaluation
  • ISO29134-7.4 Risk Evaluation Against Criteria

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Process – ISO 31000:2018

Query this from an agent

The graph holds this control, the 8 it maps to, and the evidence behind each claim, over MCP and REST.