HLD Group
Risk management policy
Identifying, assessing, and treating organizational risks.
Last updated: 24 July 2026
Version 1.5 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy establishes how HLD Group identifies, assesses, treats, monitors, and reports risk to information, operations, and the business. A consistent, repeatable risk management process enables informed decisions about where to invest in controls and which risks to accept, transfer, or avoid.
2. Scope
This policy applies to information security, operational, compliance, and technology risks across HLD Group, and to all personnel who own, assess, or make decisions about risk.
3. Definitions
- Risk — the effect of uncertainty on objectives, expressed as the combination of likelihood and impact
- Inherent risk — risk before controls; residual risk — risk remaining after controls
- Risk appetite — the amount and type of risk the organisation is willing to pursue or retain
- Risk treatment — the options of mitigate, transfer, avoid, or accept
- Risk register — the record of identified risks, their assessment, treatment, and ownership
4. Risk management process
- Establish context — objectives, scope, and criteria for assessing risk
- Identify risks — threats, vulnerabilities, and events that could affect objectives
- Analyse and evaluate — assess likelihood and impact and compare against criteria
- Treat — select and implement treatment proportionate to the risk
- Monitor and review — track risks, controls, and treatment effectiveness over time
- Communicate and report — keep stakeholders and leadership informed
5. Risk assessment and criteria
Risks are assessed for likelihood and impact against defined criteria and plotted to support prioritisation. Assessments consider confidentiality, integrity, availability, legal and regulatory exposure, financial impact, and reputational harm. Risk assessments are performed for significant changes, new systems and vendors, and on a periodic cycle.
6. Risk treatment and acceptance
Risks exceeding appetite are treated to an acceptable level. Where a risk is accepted rather than treated, the acceptance is documented with justification, an owner, compensating controls, and a review date, and is approved at a level commensurate with the risk. Risk acceptances are recorded in the risk register and reviewed at least quarterly.
7. Risk register and reporting
- A maintained risk register records each risk, its assessment, treatment, owner, and status
- Material risks and treatment progress are reported to leadership and, where applicable, the board
- Risk trends inform security investment and policy improvement
8. Framework alignment
- ISO 31000:2018 (risk management)
- ISO/IEC 27005 (information security risk management)
- NIST SP 800-30 and SP 800-39 (risk assessment and management)
- SOC 2 Trust Services Criteria CC3.1 to CC3.4
9. Roles, exceptions, and review
Risk owners manage their risks; the CISO maintains the risk framework and register; leadership sets risk appetite. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].