An IT control gap has been identified in a key process. Who is the MOST appropriate owner of the risk associated with this gap?
The business process owner is accountable for the process and has the authority to ensure that risks arising from control gaps are assessed and appropriately treated. Control, security, and operational-risk roles may support oversight and remediation, but they do not ordinarily own the underlying business-process risk.
Community Discussion