Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.2.3. Risk Monitoring and Reporting

💡 First Principle: A risk treatment decision made once and never revisited is a snapshot of a moment that has already passed — controls degrade, business context shifts, and the risk that was accepted or mitigated last year may not be the same risk today.

Ongoing monitoring closes this gap through key risk indicators (KRIs) — measurable signals that a risk's likelihood or impact is changing (such as a rising number of failed login attempts, or an increasing count of unpatched critical systems) — reported on a defined cadence to the governance bodies established in Phase 2. Residual risk — what remains after a treatment is applied — is the specific figure that monitoring tracks over time; a control that was fully effective at deployment can quietly become less effective as the environment around it changes, and only ongoing monitoring surfaces that drift before it becomes an incident.

⚠️ Exam Trap: Risk treatment is sometimes treated as a one-time decision that closes the item permanently. The correct answer recognizes that treatment must be monitored — controls degrade and business context changes, requiring periodic re-evaluation of residual risk.

Reflection Question: A risk was mitigated eighteen months ago with a specific control, and the risk register entry hasn't been reviewed since. What could have changed in that time that would make the original treatment decision no longer adequate?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications