Skip to main content
Category: Enterprise Risk Management

Identify

Also known as: Identification, Identifying
Simply put

To identify means to recognize or determine who someone is or what something is, and to be able to state or demonstrate that conclusion. In a governance, risk, or compliance setting, it generally refers to the act of pinpointing or naming a relevant item, such as a risk, control, obligation, or stakeholder, so it can be assessed and managed. Failing to identify something typically means overlooking or missing it entirely.

Formal definition

In its general sense, to identify is to perceive, recognize, or establish the identity of a person or thing and to state or prove that identity. Within governance, risk, and compliance practice, identification is typically the initial step in a broader process, in which a practitioner determines and names the relevant subject matter (for example, risks, controls, applicable requirements, or affected parties) before subsequent stages such as assessment, evaluation, treatment, or monitoring. The precise scope and rigor of an identification activity generally depend on the applicable framework, methodology, and the practitioner's own judgment; this entry addresses the term in its plain-language sense rather than as a defined term under any specific statute or framework.

Why it matters

Identification is typically the foundational step in any governance, risk, or compliance process. If a risk, obligation, control, or affected party is never identified, it generally cannot be assessed, prioritized, treated, or monitored; the item simply remains outside the scope of management attention. As the plain-language sense makes clear, the opposite of identifying something is to overlook or miss it entirely, and in a GRC context that gap can propagate through every subsequent stage of a program because later activities operate only on what was named at the outset.

Because so much downstream work depends on it, the quality and completeness of identification tends to shape the effectiveness of the whole process. A risk assessment can be methodologically sound yet still leave an organization exposed if the underlying risk population was incomplete; a compliance program can be well-resourced yet still fall short if an applicable obligation was never recognized. This is why identification is usually treated as a distinct, deliberate activity rather than an afterthought, and why frameworks and methodologies commonly position it explicitly as an early phase before assessment or evaluation.

The rigor expected of identification generally varies with the applicable framework, methodology, and the practitioner's own judgment. This entry addresses "identify" in its plain-language sense; it is not a defined term under any specific statute or framework, and what counts as adequate identification in a given program will depend on the facts, the sector, and the entity involved. Entries here are educational and not legal, audit, or compliance advice.

Who it's relevant to

Risk professionals
Risk identification is generally the first phase of a risk process, in which relevant risks are recognized and named before they can be assessed, prioritized, or treated. A risk that is never identified typically cannot be managed, so completeness at this stage tends to shape the reliability of everything that follows.
Compliance officers
Identifying applicable obligations, requirements, and affected parties is generally a prerequisite to monitoring and demonstrating compliance. An obligation that is overlooked at the identification stage will typically fall outside the scope of the program built around it.
Internal auditors and assurance functions
Identification is often relevant when determining the population of controls, processes, or subject matter within an engagement's scope. What is not identified generally is not examined, so the boundaries set at this step can affect the coverage of assurance work.
Boards and management
Because identification is foundational to risk and compliance activity, those responsible for oversight and for operating programs both have an interest in whether relevant items are being recognized and named in the first place. The specific accountability for a given identification activity depends on which function owns it under the organization's arrangements.

Inside Identify

Risk Identification
The process of recognizing and describing risks that could affect the achievement of objectives. Under frameworks such as ISO 31000 and COSO ERM, identification is generally the foundational step that precedes analysis, evaluation, and treatment, and it aims to be as comprehensive as reasonably practicable rather than exhaustive.
Sources and Drivers of Risk
The internal and external factors from which risks arise, including strategic, operational, financial, compliance, and reputational sources. Identifying the source helps distinguish the underlying cause from the risk event and its potential consequences.
Risk Events and Consequences
The potential occurrences that could happen and the outcomes that could follow. Identification typically captures both the event and its plausible impacts, which are later assessed in terms of likelihood and impact during the analysis phase, not during identification itself.
Scope and Context
The boundaries within which identification is performed, such as an entity, process, project, or objective. Under certain frameworks, establishing context is a prerequisite so that identification is aligned to defined objectives and relevant to the entity type, sector, and jurisdiction.
Risk Register or Inventory
A structured record used to capture identified risks and their attributes. It is generally a management tool that documents outputs of the identification process; it is typically owned and maintained by management (first and second lines) rather than by the board.
Ownership and Accountability
The assignment of each identified risk to a responsible owner. Accountability for identifying and managing risks generally sits with management, while the board and its committees typically retain oversight of whether an adequate identification process exists.

Common questions

Answers to the questions practitioners most commonly ask about Identify.

Is 'Identify' the same as the risk assessment step, so once we have a risk register we've completed it?
Not quite. Identification is broader than producing a risk register. In many frameworks, an identify function encompasses building foundational understanding of the organization's assets, business environment, governance context, and the risks that flow from them, rather than a single point-in-time cataloguing exercise. Producing a register is typically one output, but it does not by itself establish the underlying context, ownership, and prioritization that the function is meant to support. Treating a register as the finish line risks leaving gaps in how risks are understood and maintained over time. The specifics depend on the framework you are applying and your own judgment about scope.
Does the board 'do' identification, or is this really management's job?
These are distinct roles that should not be conflated. Identifying risks operationally, cataloguing assets, assessing the business environment, and surfacing exposures, is generally an activity owned by management and, where applicable, supported by assurance functions. The board's role is typically oversight: satisfying itself that a credible identification process exists, that it captures material risks, and that results inform strategy and risk appetite. Attributing the hands-on identification work to the board, or the oversight duty to management, misstates where accountability sits. The precise allocation varies by entity type, jurisdiction, and the organization's governance structure. This entry is educational and not legal, audit, or compliance advice.
Who should own the identification activity within an organization?
Ownership generally sits with management, often distributed across business units and process owners who are closest to the relevant assets and exposures (commonly associated with the first line of defense). A risk or compliance function may coordinate, provide methodology, and challenge results (often associated with the second line), while internal audit may provide independent assurance over the process (the third line). Where a given identification task belongs depends on your operating model and how you have defined the three lines. Clarifying accountability for each activity, rather than assuming a single owner, is typically important. Jurisdiction, sector, and entity type all affect the appropriate structure.
How often should identification be performed?
There is generally no single mandated frequency; the appropriate cadence depends on the framework you follow, the volatility of your environment, and regulatory expectations that vary by jurisdiction and sector. Many organizations treat identification as an ongoing activity supplemented by periodic formal refreshes, and re-run it when triggered by significant changes such as new products, entering new markets, reorganizations, or shifts in the external environment. Rather than fixing a universal interval, it is typically more useful to define triggers and a baseline review rhythm suited to your risk profile. This depends on facts and professional judgment.
How do we know our identification effort is complete enough?
Completeness is generally a matter of reasonable coverage and judgment rather than certainty, since no process can guarantee every exposure is captured. In practice, organizations often test coverage by drawing on multiple sources, process walkthroughs, workshops, prior incidents and near-misses, external intelligence, and independent challenge from assurance functions, to reduce blind spots. Documenting the scope considered, and explicitly noting what was treated as out of scope, helps make the boundaries of the exercise transparent. Whether coverage is sufficient depends on your risk appetite, the framework applied, and applicable requirements, and remains a professional judgment.
How should the output of identification connect to the rest of the risk process?
Identification typically feeds subsequent steps such as analysis, evaluation, and treatment, so its output should be structured to support them. That generally means capturing enough context, affected assets, potential sources, and ownership, so that later stages can assess likelihood and impact and distinguish inherent from residual risk. Importantly, identification itself does not usually rate or score risk; conflating it with analysis or evaluation blurs distinct steps. Linking identified items to a clear owner and to the mechanisms used for prioritization helps maintain traceability. The exact linkages depend on the framework you apply and your own operating model.

Common misconceptions

Identifying a risk is the same as assessing or rating it.
Identification is generally a distinct, earlier step focused on recognizing and describing what could go wrong. Assessing likelihood and impact, and distinguishing inherent from residual risk, occurs in the subsequent analysis and evaluation phases under frameworks such as ISO 31000 and COSO ERM.
Risk identification is the board's job.
In many governance models built on the three lines concept, management (the first and second lines) typically owns the operational activity of identifying risks, while the board and its committees exercise oversight of the adequacy of that process. Attributing the operational identification duty to the board conflates oversight with execution.
A completed risk register means all material risks have been identified.
Identification aims to be comprehensive but is rarely exhaustive; emerging, novel, or low-visibility risks may be missed. A register is a point-in-time record that generally requires periodic refresh, and its completeness depends on facts, judgment, and the quality of the underlying process.

Best practices

Establish the scope and context before identifying risks, tying the exercise to specific objectives and to the relevant entity type, sector, and jurisdiction so that identification remains focused and relevant.
Draw on multiple inputs and perspectives, including first-line process owners and second-line risk and compliance functions, to reduce blind spots and avoid over-reliance on a single source.
Describe each risk clearly by separating its source or cause, the potential event, and the plausible consequences, so later analysis of likelihood and impact rests on a sound foundation.
Assign a documented owner to each identified risk to reinforce accountability at the management level, while preserving the board's oversight role over the adequacy of the identification process.
Treat identification as an ongoing activity by refreshing the risk register periodically and after significant changes, recognizing that no inventory captures all emerging risks.
Document the basis and limitations of the identification exercise, noting where conclusions depend on judgment or facts, and treat outputs as inputs to further assessment rather than final risk decisions.