Which of the following is MOST important when defining an organization’s risk scope?
An organization’s risk scope must be grounded in an understanding of how its risk environment affects the organization. That understanding identifies the relevant internal and external sources of risk and their potential impact; management approach and reporting requirements are subsequent governance considerations.
Community Discussion