Skip to main content
Category: Enterprise Risk Management

Establishing the Context

Also known as: Context Establishment, Establish the Context, Context Setting
Simply put

Establishing the context is typically the first step in a risk management process, where an organization sets out the background, scope, and boundaries within which risks will be identified and assessed. It involves clarifying objectives, identifying stakeholders, and deciding how risks will be evaluated before any specific risks are examined. This step provides the foundation that makes later risk assessment meaningful and consistent.

Formal definition

Under risk management frameworks such as ISO 31000, establishing the context is generally the initial step of the risk management process that defines the scope and boundaries of the process and sets the criteria against which risks will subsequently be assessed. It typically encompasses planning the process, mapping the scope and objectives, identifying stakeholders and their interests, and defining the risk criteria used to evaluate likelihood and impact. As described in the evidence, this step is presented as a foundational activity that enables an organization to build a coherent risk strategy; its precise application varies by framework, jurisdiction, sector, and entity type, and this entry is educational rather than legal, audit, or compliance advice.

Why it matters

Establishing the context matters because it determines whether everything that follows in a risk management process is coherent and defensible. Without a clearly defined scope, set of objectives, and agreed criteria for evaluating risk, an organization risks assessing the wrong things, applying inconsistent standards across business units, or producing risk registers that cannot be meaningfully compared or aggregated. As the evidence describes, this step defines the scope for the risk management process and sets the criteria against which risks will subsequently be assessed, meaning the quality of every later judgment about likelihood and impact depends on the groundwork laid here.

This foundational step also shapes accountability and communication. By identifying stakeholders and their interests at the outset, an organization can align its risk process with the concerns of those who have a legitimate stake in the outcome, and by fixing the boundaries of the exercise it clarifies what is in and out of scope. Frameworks such as ISO 31000 treat this as the first step precisely because ambiguity about scope or criteria tends to surface later as disputes over whether a risk was missed, mis-rated, or simply outside the remit of the assessment.

It is worth emphasizing that establishing the context is generally a planning and framing activity rather than the point at which specific risks are identified or controls are tested. Its precise application varies by framework, jurisdiction, sector, and entity type, and getting it right does not guarantee a sound risk process, it simply makes the subsequent steps meaningful. This entry is educational and not legal, audit, or compliance advice.

Who it's relevant to

Chief Risk Officers and risk management functions
Those who own the design and operation of the risk management process rely on the context step to set the scope, boundaries, and risk criteria that give the rest of the process consistency. It is generally their responsibility to plan the process and ensure the criteria are appropriate to the organization's objectives, though the specifics depend on the framework and entity type.
Boards and risk committees
In their oversight capacity, board members and risk committee members have an interest in how the context is framed, because the scope and criteria established here shape what risks management will surface for the board's attention. The board typically does not perform this step operationally but may review whether the context adequately reflects the organization's objectives and stakeholders.
Internal audit and assurance providers
Assurance functions may examine whether the context was properly established as part of evaluating the design of the risk management process. A poorly defined scope or set of criteria can undermine the reliability of downstream risk assessments, making this an area of interest for those providing independent assurance.
Managers and process owners across the business
Because establishing the context involves identifying stakeholders and their objectives, managers whose activities fall within scope have a stake in how the boundaries are drawn. They are often the source of information about objectives and stakeholder interests that inform the context, and they operate within the criteria it defines.

Inside Establishing the Context

External Context
The factors outside the organization that shape its risk environment, typically including the legal and regulatory landscape, market and economic conditions, competitive dynamics, technological developments, and the expectations of external stakeholders such as regulators, investors, and customers. Under frameworks such as ISO 31000, establishing the external context helps ensure the risk assessment reflects the environment in which the entity actually operates.
Internal Context
The internal characteristics that influence how risk is identified and managed, generally including governance structures, roles and accountabilities, organizational culture, strategic objectives, capabilities and resources, information systems, and existing policies and controls. This element aligns the risk process with the organization's own objectives and decision-making arrangements.
Scope and Boundaries
A clear definition of what the risk management activity will and will not cover, including the objectives in scope, the organizational units or processes involved, the time horizon, and any exclusions. Defining boundaries helps prevent gaps and overlaps and clarifies where accountability for a given activity sits.
Risk Criteria
The reference points against which the significance of risk is evaluated, typically informed by the organization's risk appetite and expressed through measures of likelihood and impact and the thresholds used to rate or prioritize risks. Establishing criteria before assessment supports consistent and comparable evaluation. Note that risk appetite, risk tolerance, and risk capacity are distinct concepts and should be defined separately when setting criteria.
Stakeholders and Their Objectives
Identification of the internal and external parties with an interest in the risk management outcomes, and understanding of their relevant objectives and expectations. This helps ensure that the context reflects the perspectives that matter to how risks are prioritized and communicated.

Common questions

Answers to the questions practitioners most commonly ask about Establishing the Context.

Is establishing the context the same as identifying risks?
No. Establishing the context is a preparatory step that precedes risk identification. It involves defining the internal and external parameters, objectives, scope, and criteria against which risk will be assessed. Under frameworks such as ISO 31000, this step sets the boundaries and reference points so that subsequent risk identification, analysis, and evaluation are meaningful and consistent. Treating the two as interchangeable can lead to risks being assessed without a clear frame of reference, though the precise relationship depends on the framework and methodology an organization adopts.
Does establishing the context only concern external factors like regulation and markets?
No. The context generally has both external and internal dimensions. The external context typically includes regulatory, legal, market, social, and stakeholder factors, while the internal context typically includes governance arrangements, organizational objectives, culture, capabilities, and resources. Focusing only on external factors can leave internal drivers of risk unaddressed. The relative weight given to each dimension depends on the entity, sector, and the framework in use, and this entry is educational rather than prescriptive.
Who is typically responsible for establishing the context in a risk management process?
Responsibility generally sits with management, which owns the operation of the risk management process, including defining objectives, scope, and criteria. The board or a relevant committee typically exercises oversight, for example by approving risk appetite statements or criteria that inform the context, rather than performing the operational work itself. Assurance functions may review whether the context has been appropriately established. The exact allocation depends on an organization's governance structure and applicable frameworks.
How does establishing the context connect to risk appetite and risk criteria?
Establishing the context generally includes defining the criteria used to evaluate the significance of risk, which are often informed by the organization's risk appetite. Risk appetite typically describes the amount and type of risk an organization is willing to pursue or retain, while risk criteria translate that into reference points for assessment. Keeping these distinct matters: appetite is a strategic statement, while criteria are the practical benchmarks applied during evaluation. How they are documented and linked varies by framework and entity.
What practical inputs help define the context at the start of a risk assessment?
Common inputs include the objectives the assessment supports, the scope and boundaries of the activity, applicable legal and regulatory obligations, stakeholder expectations, relevant governance and organizational structures, and available resources. Practitioners often also confirm the criteria for likelihood and impact and the terminology to be used, so assessments remain consistent. The appropriate inputs depend on the purpose of the assessment, and professionals should apply their own judgment to their specific circumstances.
How often should the context be reviewed or refreshed?
The context is generally not a one-time exercise. Because internal and external factors change, many frameworks treat establishing the context as something to revisit periodically and when significant events occur, such as regulatory change, strategic shifts, or major organizational restructuring. The appropriate cadence depends on the entity's circumstances, the volatility of its environment, and its own governance and review arrangements. This entry is educational and not a substitute for professional advice on any specific process.

Common misconceptions

Establishing the context is a one-off, box-ticking exercise done at the start of a risk assessment.
Context generally needs to be revisited as the internal and external environment changes, since shifts in regulation, strategy, market conditions, or organizational structure can alter which risks are relevant and how they should be evaluated. Many frameworks treat it as an iterative rather than static step.
Establishing the context sets the organization's risk appetite.
The context step draws on risk appetite to define risk criteria, but setting appetite is typically a distinct governance activity. In many organizations the board or a board committee owns the setting of risk appetite, while management applies it when establishing context for a specific assessment. The two should not be conflated.
Establishing the context is a prescriptive requirement mandated identically across all organizations.
Establishing the context is a step described in risk management frameworks such as ISO 31000, which are voluntary standards rather than universally binding law. How, and whether, it is formally documented depends on the framework adopted, the jurisdiction, the sector, and the entity type, and on the organization's own judgment.

Best practices

Distinguish and separately document the external and internal context so that both the regulatory and market environment and the organization's own governance, culture, and objectives are captured.
Define the scope, boundaries, time horizon, and any exclusions explicitly at the outset to avoid gaps or overlaps and to clarify where accountability for each activity sits.
Establish risk criteria before conducting the assessment, keeping likelihood and impact as separate dimensions and grounding thresholds in the organization's articulated risk appetite.
Keep risk appetite, risk tolerance, and risk capacity distinct when translating them into criteria, and confirm that the appetite being applied reflects what the board or relevant committee has set.
Identify relevant stakeholders and their objectives early so that risk prioritization and communication reflect the perspectives that matter to the organization.
Revisit the context periodically and when significant internal or external changes occur, rather than treating it as a single fixed step, so the risk process remains aligned with current conditions.