Not Every Risk Deserves a Meeting.

A risk register that treats a printer outage like a data breach wastes attention. Rank risks against defined criteria, monitor the lower-priority items, and bring the material decisions to people.

Sorena AI TeamRisk and Governance4 min read

When everything is urgent, nothing is

Logging a risk is only the first step. If the program flags and escalates every entry at the same level, the team still has to sort the register by hand.

A stalled vendor invoice and a critical vulnerability may both be open, but they should not wait in the same queue with the same priority. Rank them against agreed criteria so reviewers can spend more time on material risks.

Impact and likelihood are the starting point

Impact and likelihood are common starting points for risk assessment. ISO 31000:2018 describes a process for identifying, analysing, evaluating, treating, monitoring, and communicating risk. NIST SP 800-30 uses threats, vulnerabilities, impact, and likelihood to help decision makers choose responses.

A risk that could stop revenue for a week should not carry the same weight as a typo in a policy draft. Score the relevant factors, then compare the result with risk criteria, tolerance, and the confidence behind the assessment.

You need a line, not a longer list

Scoring sets the order. Risk appetite sets the threshold for action. COSO's 2017 Enterprise Risk Management framework, Integrating with Strategy and Performance, ties risk management to strategy and defines risk appetite as the types and amount of risk an organization is willing to accept in pursuit of value. IRM uses a similar definition: the amount and type of risk an organisation is willing to take to meet strategic objectives. Without that threshold, every item on a ranked list still looks actionable.

Risk appetite lets you accept a low-severity risk deliberately instead of ignoring it when time runs out. The acceptance should have a rationale and an owner.

Most of the register may fall below the line and need monitoring rather than a committee. The handful above it get attention, owners, and sometimes a meeting. The risk management process should defend a threshold the board can understand.

Score before and after treatment

Compare the score before and after treatment. Capture inherent impact and likelihood, then record the treatment, residual impact, residual likelihood, confidence, and appetite threshold. A high inherent risk below appetite after mitigation may need monitoring, not a meeting. A medium risk with low confidence may need escalation.

The score should explain why the risk is on the agenda, why it is below the line, or why the team is still not sure enough to decide. For security programs, an ISO/IEC 27005 residual-risk approval workflow is the cleaner pattern: show the original scenario, treatment choice, residual risk, approval owner, and review trigger in one defensible record.

Alert fatigue is a prioritization failure

When every alert is critical, people stop reading alerts. This is a predictable response to a system that assigns the same urgency to every entry. People tune it out and respond more slowly when a genuinely urgent signal arrives.

No human can act on a thousand equal alerts. The most important one looks like the other nine hundred and ninety-nine.

Send fewer, ranked alerts. An alert that fires only when a risk crosses a defined threshold is more likely to get a response.

Systems score. Humans decide.

Software can apply predefined scoring rules across a large register. It can calculate the same formula for every entry and show the inputs behind each ranking. People still need to validate those inputs, account for uncertainty, and correct bad classifications.

Treatment and acceptance remain governance decisions. Business context, changing conditions, and risk appetite determine whether a high-scoring risk is acceptable and who can approve it.

One ranked view beats forty open threads

Use one short, ranked view. Show what crossed the appetite threshold, who owns it, and why it ranked where it did. Keep everything else visible but quiet so it can be monitored without demanding a meeting.

This replaces forty open email threads with a rule the team agreed to in advance. The useful argument is whether the threshold is set correctly, not which inbox sounds most urgent today.

A grounded, traceable ranking also holds up later. When someone asks why a risk was accepted, show the score, appetite threshold, owner, and recorded rationale.

Rank it, then decide who cares

Rank risks before setting the agenda. Define the criteria and appetite, record treatment and residual risk, and monitor lower-priority items for change. Bring material risks and uncertain assessments to the people accountable for the decision.

Frequently asked questions

Doesn't ignoring low-priority risks just mean they blow up later?+

Keep low-ranked risks monitored and on the record without giving each one the same meeting time as a material risk. Record the acceptance rationale, owner, appetite decision, and review trigger so a change can move the risk back up the list.

How do you decide where the line goes?+

Use risk appetite and risk criteria. COSO ties appetite to the amount and type of risk an organization is willing to accept in pursuit of value. Set thresholds through governance, then use the score, uncertainty, existing controls, and business context to choose a response.

If a system scores the risks, what is left for people to do?+

People validate the inputs, challenge the ranking, and decide on treatment or acceptance. Software can apply predefined scoring rules consistently across a large register, but it cannot supply missing context or own the decision.

Sources

Share

See Sorena do the work

Book a demo and watch one real compliance workflow go from question to audit-ready output.