Risk management strategies help organizations bring unacceptable risks within policy thresholds through avoidance, reduction, transference, or acceptance. Understanding the distinction between risk exceptions and exemptions is essential for proper governance and compliance.
Risk Mitigation Strategies
There are going to be certain risks that we're not going to want to take on, certain risks that might fall outside of our comfort zone from a risk perspective, that extend beyond our risk appetite, or there could be other reasons as well. There are some management strategies to deal with those types of risks, to get them below that threshold or get them to an acceptable point.
One thing we could do with risk is avoid it altogether. There are certain scenarios where we could not do something, or do something, to just avoid whatever risk that we had.
Or we could reduce the impact. If that risk is actualized, if it takes place, then the risk has a lower impact, and so we can reduce that impact.
Or we could transfer the risk — maybe transfer it to some other entity, like take out insurance on some sort of risk.
Or we can accept the risk and just realize that it's a risk with whatever we're doing.
To illustrate these, let's come up with a scenario. Let's say our policy says that no risk can be greater than $100,000. So now here is our risk tolerance right here, or our risk threshold, or our risk appetite, whichever term you want to use for it.
Let's say we're rolling out a new product that we're going to charge end users for through an e-commerce site. We're going to be accepting credit cards. Now, during this accepting of credit cards, what's going to happen is we're taking on risk — for instance, that credit card information could get stolen by some other entity and we could be liable for it. Because of that, we've determined that this risk is at $250,000, which is significantly more than the threshold we have in our policy. Somehow we need to reduce the risk that credit cards bring on.
Number one, we could avoid it altogether. Maybe we just don't do any credit card processing, maybe we're going to give the product away for free. It might not be a great solution, but in this case we would be avoiding that risk.
The next thing we could do is reduce the impact. Maybe we take the credit card information, we process it, but then we delete it right away. That might work in a lot of cases, where we don't really need to hold on to that credit card information. But maybe we want to charge them on a monthly basis — now we're probably going to have to hold on to that card in order to process that information on a monthly basis, so that might not be a great solution either.
We could transfer it. There are ways that we can use third-party processors: we send them to the third-party processor to process the credit card information, and then on a monthly basis we can just charge that card, and that card never gets stored on our systems. So what we've done is we've transferred that to whatever service that we're using.
The other one was that we could just accept it — that it is much above and beyond what we have as far as our policy is concerned, but it's worth the risk, because we're going to be getting a lot of money through the extra services that we're going to be selling.
When it comes to acceptance, we have two different types of acceptance. There's an exemption, or there's an exception.
The terms exception and exemption can be a little confusing, and rightfully so, because the result is the same. In this case we have a $250,000 risk, but we're not going to follow the $100,000 limit that's been imposed upon us. The result is the same, but it is because of two different circumstances.
If you have an exception, you're receiving a special circumstance where you are being excluded from the policy, from the rule. In this case you've gone to maybe the CEO, or maybe the board of directors, or possibly all of the upper management, and you've said this is the circumstance, and they've given you permission to have an exception to the rule and said go ahead and proceed — we want to be able to make this money and we have to do this.
The other scenario is that the rule doesn't apply. Maybe we go in there and say, this could come up again, so what we're going to do is actually change the rule. We're going to add to it, and say that these are the exemptions from it, that it doesn't apply in these scenarios.
So in our circumstances, we already mentioned that exemption just means that you're getting approval to proceed with this credit card. But with the exemption we have this added to the policy: that unless a particular risk can't be avoided — so what they're doing is they're asking you to avoid the risk first — and it's associated with an action that is mission critical. Well, taking credit card information is mission critical, because we want to make money and the business needs to be profitable. So it is mission critical, and therefore what has happened is we've created an exemption, that this rule doesn't exactly apply in this scenario because it's mission critical.
So those are various strategies that we can take.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →