ITPEC FE Morning October 2019 Question 44
ITPEC FE Morning October 2019 — Question 44 of 80
Risk Assessment Process — identify the three sub-processes of risk assessment per ISO 31000.
Risk assessment consists of three sequential steps:
- Risk identification — find and list potential risks
- Risk analysis — estimate likelihood and impact of each risk
- Risk evaluation — compare analyzed risks against criteria to prioritize them
Everything that follows (response, acceptance, mitigation, transfer) belongs to risk treatment, not assessment.
Why not others:
- (a) Includes risk response, which is part of risk treatment, not assessment
- (b) Includes risk response and risk acceptance — both are treatment activities
- (d) Includes risk acceptance, which is a treatment decision, not an assessment step
Key rule: Risk assessment = Identify → Analyze → Evaluate. Anything beyond evaluation is risk treatment.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.