In practice, it risk assessment is a phrase that gets searched by two people: the one who wants a definition for a memo and the one who has to sign an attestation about it next quarter. This page is written for the second. For a business holding its systems to a control framework, it risk assessment comes down to a record and a set of figures: the record is the controls, the tests, the vulnerabilities, the incidents and the access reviews, kept with an owner, a date and a status; the figures are the evidence load that record puts on its reviewers, the days an audit of it takes, the gaps an audit will find and what they cost, the incidents and cases it produces, and the training it requires. The sections below explain it risk assessment in those terms, say what it is not, and show where the free sheets on this site work each figure from the programme's own numbers with no account.
What it risk assessment means in practice
For a business holding its systems to a control framework, it means being able to show, for each obligation, which control satisfies it, what evidence proves the control operated, who reviewed the evidence and who attested to the result. The record is the controls, the tests, the vulnerabilities, the incidents and the access reviews. The regulator's own material, linked below, says what the obligations are; this site publishes none of that and no legal advice. What it publishes is the arithmetic: the obligations register sheet turns the count of obligations, controls and evidence items into reviewer hours and the months to a full attestation.
The searches this page answers, in the words people use
Measured in the United States, the phrasings that lead here are it risk assessment (800/mo), sox it general controls (200/mo), nonprofit policies and procedures manual template (80/mo). They are one question asked 3 ways: a business holding its systems to a control framework wants to know what the record must hold and what it costs to keep, and the IT control-testing sheet on this site works the figure that answers it. The wording differs; the register behind it does not, and neither does the arithmetic.
The figures behind it risk assessment
Evidence items and reviewer hours; audit samples, days and coverage; expected gaps, remediation hours and cost; incident hours; case backlog months; training seats outstanding. Each is a free sheet on this site and each computes from the programme's own inputs. For IT compliance the sheet to start with is the IT control-testing sheet, which works the figure a business holding its systems to a control framework is examined on first. A programme that knows those numbers has stopped estimating its own compliance.
What it risk assessment is not
It is not a certificate, a piece of software or a consultant's memo, although all three are sold under the name. It is a record and the figures that follow from it, kept by the business that owes the obligations. The guide this page supports covers the questions for a regulatory compliance consultant, the help a small business buys around that record. Attestvio Pro keeps the record at one flat price; the sheets are free with no account.
Why the search is it risk assessment
The words in it risk assessment are the words a business holding its systems to a control framework uses when the obligation has a name and the programme does not yet have a number. The name is the regulator's, linked below; the number is the programme's own, and it is the count of obligations, controls and evidence items behind IT compliance turned into reviewer hours on the obligations register sheet and into audit days on the audit scope sheet. A programme that searches it risk assessment and comes away with those two figures has done the first day of the work, and the paid plan on this site keeps what follows: the record, with owners, dates and the attestation that closes each period.
Questions people ask about it risk assessment
What is it risk assessment?
For a business holding its systems to a control framework: keeping the controls, the tests, the vulnerabilities, the incidents and the access reviews as a record with an owner, a date and a status, and being able to show for each obligation the control, the evidence and the attestation. The regulator's own material, linked below, defines the obligations; the free sheets on this site work the arithmetic.
Who is responsible for it risk assessment in a small business?
The compliance officer, or the owner wearing that hat, who signs the attestation. The sheets on this site are written for that person and need no account.
Does Attestvio make a business compliant with IT compliance?
No. The business meets the obligations; Attestvio keeps the record and works the figures, and publishes no rule and no advice. Counsel and the regulator's own material say what the obligations are.