Risk Treatment Mode
To specify risk treatment choices:

In the properties page of a risk, select the
Treatment tab.
Treatment Modes
Various solutions that enable facing the risk are proposed.
• Acceptance
This is the strategy of risk management that consists of accepting the risk having considered its consequences. As long as no desire to treat the risk is expressed, this strategy will not protect the organization against the risk.
• Reduction
Risk frequency can be reduced by installing additional controls, or the impact of its consequences can be reduced if the risk occurs.
• Transfer (sub-contractor)
The risk can also be shared with other partners, in particular when they have greater skills in controlling the risk. For example, you can sub-contract a dangerous activity to a partner specialized in the particular field. In such cases, it should be noted that it is often necessary to carry out a new risk study, since the introduction of a new partner can bring additional risks.
• Insurance
Complementing all previous approaches, it is often necessary to seek assurance, in particular for risks of low frequency but with high impact. In this case, the assurer generally requests that risk prevention and reduction measures are also installed.
The different scenarios possible are analyzed to weigh up their positive and negative aspects, with a view to selecting a scenario compatible with the risk control level in question.
Depending on the solution adopted, we consider the effect of different solutions in terms of frequency and impact as well as costs and benefits.
Risk levels
The choice of remediation should be the solution that reduces Residual Risk to within the tolerable limit required by management.
In the Target Risk field, you can indicate the level of risk accepted by the organization.
Specifying Controls to be Implemented
Management draws up a set of actions matching risk levels with risk tolerance level and risk appetite for the organization.
For each risk, the selected scenario is described in detail, with the various risk factors and the controls implemented to counter them highlighted. Also specified are controls installed to warn of risks, as well as the corrective procedures to be implemented if the risks occur.
Implementation of prevention controls to reduce risk frequency and impact can be a solution for risk reduction.
To indicate the controls and action plans enabling risk prevention:

In the
Treatment page of the risk properties page, expand the
Controls and Action Plans section.
• The Action Plans tab contains the list of action plans installed: for example for creation or improvement of a control, management of a crisis linked to occurrence of an incident, or revision of a process with a view to its improvement.
• The Controls tab lists controls planned for risk reduction.

A control is a set of rules and means enabling the assurance that a legal, regulatory, internal or strategic requirement is met.