See below – wording from a poll posted on the Linkedin ISO 31000 Risk Management Standard group – perhaps the poll and the sample answer options provided are tongue-in-cheek, perhaps not, but how does your organization (and its directors) determine that risks and uncertainties are successfully identified, evaluated and managed on an ongoing basis?
How do you know that an organization successfully manages its risks?
-
It is compliant to a standard
-
There has been no major disaster
-
Processes and controls are in place
-
People are competent and accountable
-
You just can’t know
Dave Tate, Esq.