Skip to main content
Category: Enterprise Risk Management

Risk Monitoring and Review

Also known as: Risk Monitoring, Risk Monitoring and Reviewing
Simply put

Risk monitoring and review is the ongoing process of keeping track of risks an organization has already identified, checking that the controls put in place to manage them are still working, and watching for new risks as circumstances change. The goal is to confirm that risks stay at a level the organization considers acceptable over time. Because conditions evolve, this is a continuous activity rather than a one-time exercise.

Formal definition

Risk monitoring and review is a continuous component of the risk management process focused on tracking previously identified risks, evaluating whether risk treatment controls remain effective, and detecting emerging or changing risks over time. It typically involves ongoing surveillance of risk treatment plans to confirm they are executed as intended and that residual risk remains within accepted parameters, while providing assurance to relevant stakeholders. The cadence and depth of monitoring generally depend on the entity, sector, and applicable framework; under many risk management frameworks it is treated as an integral, recurring phase rather than a discrete endpoint. This entry is educational and not legal, audit, or compliance advice; specific practices vary by jurisdiction, framework, and professional judgment.

Why it matters

Risk profiles are not static. Controls that were effective when designed can degrade as processes change, personnel turn over, technology is adopted, or the external environment shifts. Without ongoing monitoring and review, an organization may continue to assume that a previously assessed risk remains within acceptable parameters when, in fact, residual risk has drifted higher or a new risk has emerged unnoticed. Continuous surveillance helps confirm that risk treatment plans are actually executed as intended and that they continue to keep exposures at a level the organization considers acceptable.

Monitoring and review also serve an assurance function. Boards and their committees carry an oversight responsibility for risk, but they generally rely on management and assurance functions to surface timely, reliable information about how risks and controls are performing. A well-functioning monitoring process provides the evidence that allows management to demonstrate, and the board to gain comfort, that the risk framework is operating rather than merely documented. It also creates the feedback loop through which changing circumstances are fed back into risk identification, assessment, and treatment.

The cadence and depth of monitoring generally depend on the entity, sector, and applicable framework, and no single approach is universally mandated. Under many risk management frameworks it is treated as an integral, recurring phase rather than a discrete endpoint, and in some contexts it is embedded within broader monitoring and evaluation processes. This entry is educational and not legal, audit, or compliance advice; specific practices vary by jurisdiction, framework, and professional judgment.

Who it's relevant to

Boards and risk committees
Directors and committee members exercising risk oversight generally depend on the outputs of monitoring and review to gain assurance that identified risks remain within accepted parameters and that treatment plans are working. Their role is typically oversight rather than day-to-day execution; they set expectations for what is monitored and how it is reported, and they challenge the information they receive.
Management and risk owners
Management and the individuals accountable for specific risks own the operational task of tracking those risks, confirming that controls remain effective, and watching for emerging exposures. They are typically responsible for ensuring risk treatment plans are executed as intended and for escalating when residual risk moves outside accepted levels.
Assurance and internal audit functions
Functions providing independent or objective assurance rely on and contribute to monitoring activity, helping to evaluate whether controls are operating effectively over time. Their perspective helps distinguish between controls that are well designed and those that are actually operating as intended, and supports the assurance provided to stakeholders.
Project and program teams
In project-based contexts, risk monitoring is often integrated into broader monitoring and evaluation processes and conducted on a recurring basis. Teams delivering projects use it to keep identified risks under review and to detect new risks as the project environment changes.

Inside Risk Monitoring and Review

Ongoing Monitoring
The continuous activities embedded in normal operations through which management tracks whether identified risks, their likelihood and impact, and the controls addressing them remain valid over time. Ownership of this activity typically sits with management and risk owners in the first and second lines, not with the board.
Periodic Review
Scheduled, point-in-time reassessments of the risk profile, risk register, and control environment, generally conducted at defined intervals or triggered by significant change. Frequency and formality vary by entity type, sector, and the frameworks an organization has adopted.
Key Risk Indicators (KRIs)
Metrics used to signal changes in risk exposure or emerging threats before they materialize. KRIs support monitoring but are only as useful as the thresholds and escalation paths defined around them; they are a management tool rather than a legal requirement.
Change Triggers
Internal or external developments, such as new regulation, strategic shifts, incidents, or changes in the operating environment, that prompt reassessment outside the normal review cycle. Identifying triggers helps keep the risk picture current between scheduled reviews.
Reassessment of Inherent and Residual Risk
Reviewing whether the level of risk before controls (inherent) and after controls (residual) has shifted, and whether residual risk remains within the organization's stated risk appetite and tolerance. These are distinct concepts and should not be treated as interchangeable during review.
Control Effectiveness Evaluation
Assessing whether controls are both suitably designed and operating effectively in practice. Monitoring may distinguish between design assessment and evidence of operating effectiveness over a period, and the two should not be conflated.
Escalation and Reporting
Defined routes for surfacing changes in risk to management, relevant committees, and the board. Reporting supports the board's oversight role, while the underlying monitoring and response typically remain management responsibilities.
Assurance Inputs
Independent perspectives, such as those from internal audit, that inform the reliability of monitoring and review activities. Under a three-lines model, assurance functions evaluate the process but generally do not own the risks or the controls they assess.

Common questions

Answers to the questions practitioners most commonly ask about Risk Monitoring and Review.

Is risk monitoring the same as the annual risk assessment we already perform?
No. A periodic risk assessment is typically a point-in-time exercise that identifies and evaluates risks, whereas monitoring and review is an ongoing, continuous activity that tracks whether identified risks, their likelihood or impact, and the controls addressing them have changed over time. Under frameworks such as ISO 31000 and COSO ERM, monitoring and review is generally described as a distinct, continuing component rather than a repeat of the assessment. Treating the two as interchangeable can leave gaps between assessment cycles during which emerging or shifting risks go undetected. The appropriate cadence and design depend on the entity's facts, sector, and risk profile, and this entry is educational rather than prescriptive.
Does monitoring risk mean the board is responsible for carrying out the monitoring activities?
Generally no. Accountability for oversight of the risk management framework typically sits with the board or a designated committee, but the operational activity of monitoring risks and testing controls is usually owned by management and the relevant lines of defense. In many governance models, first-line operational management owns day-to-day monitoring, second-line risk and compliance functions provide oversight and challenge, and internal audit provides independent assurance. The board's role is generally to review the outputs, question the assurance received, and satisfy itself that the framework operates effectively, not to perform the monitoring itself. The precise allocation of responsibilities varies by jurisdiction, entity type, and the entity's own governance arrangements.
How often should risk monitoring take place?
There is no single mandated frequency across jurisdictions or frameworks. Cadence is typically calibrated to the nature and volatility of the risk: high-velocity or high-impact risks may warrant near-continuous or frequent monitoring, while more stable risks may be reviewed less often. Many organizations blend continuous monitoring of key indicators with periodic formal reviews reported to management and, where relevant, to the board or a committee. The right approach depends on the entity's risk appetite, resources, and regulatory context, and remains a matter of professional judgment rather than a fixed rule.
What kinds of indicators or triggers are commonly used to detect changes in risk?
Organizations commonly use key risk indicators, control performance metrics, incident and loss data, near-miss reporting, and external signals such as regulatory developments or market changes. Distinguishing likelihood indicators from impact indicators can help clarify what a given metric actually measures. Event-based triggers, such as a significant incident, a change in strategy, an acquisition, or a new regulatory requirement, may prompt an off-cycle review outside the normal cadence. The selection and thresholds for such indicators are entity-specific and should reflect the organization's risk appetite and tolerance; this entry does not prescribe particular metrics.
How does monitoring distinguish between whether a control is well designed and whether it actually works?
Monitoring and review generally addresses both control design and operating effectiveness, but these are separate questions. Design effectiveness concerns whether a control, if operated as intended, would adequately address the risk; operating effectiveness concerns whether the control is in fact operating consistently over time. Monitoring activities may confirm a control remains well designed yet still identify that it is not being operated reliably, or vice versa. Conflating the two can produce false assurance. The evidence and testing needed to reach a view depend on the control, the risk, and the assurance function's methodology.
How should the results of risk monitoring feed back into the wider governance and risk framework?
Monitoring outputs are typically reported through defined channels so that management can act on emerging issues and so that the board or its committee receives sufficient information for its oversight role. Results generally inform updates to the risk register, reassessment of residual risk against risk appetite and tolerance, decisions to strengthen or redesign controls, and escalation where thresholds are breached. Effective feedback loops help ensure monitoring is not a standalone exercise but connects to assessment, treatment, and reporting. The specific reporting lines, escalation thresholds, and documentation expectations depend on the entity's structure, applicable requirements, and professional judgment, and this entry is not legal, audit, or compliance advice.

Common misconceptions

Risk monitoring and review is an activity the board performs directly.
In many governance models, ongoing monitoring and periodic review are management responsibilities carried out in the first and second lines, while the board or its risk or audit committee exercises oversight of the process. Attributing the operational monitoring duty to the board, or the oversight duty to management, misstates where accountability typically sits.
Once a risk assessment is completed, monitoring simply confirms the original conclusions.
Monitoring and review exist precisely because risk exposure, likelihood, impact, and control effectiveness can change over time. Reassessment may reveal that inherent or residual risk has shifted, that controls no longer operate as designed, or that residual risk has moved outside the organization's risk appetite or tolerance.
Frameworks such as COSO or ISO 31000 impose a single mandatory monitoring and review process on all organizations.
These are voluntary frameworks that describe monitoring and review as a component of a broader risk management process; they are not universally mandatory. The specific requirements, frequency, and formality of monitoring depend on jurisdiction, sector, entity type, applicable law, and a professional's own judgment.

Best practices

Define clear ownership for monitoring and review, distinguishing the risk owners and management functions that perform it from the committees and board that oversee it, consistent with a three-lines approach.
Establish both ongoing monitoring embedded in operations and scheduled periodic reviews, and specify the change triggers that prompt reassessment between cycles.
Evaluate control design and operating effectiveness separately, and reassess whether residual risk remains within the organization's stated risk appetite and tolerance.
Use key risk indicators with defined thresholds and escalation paths so that emerging changes in exposure are surfaced to the appropriate level in a timely way.
Document reassessment outcomes and report changes in the risk profile through defined escalation routes to management and relevant committees to support informed oversight.
Calibrate the frequency and formality of review to the entity's size, sector, regulatory context, and any adopted frameworks, recognizing that appropriate practice varies and depends on professional judgment rather than a single mandatory standard.