| Identifying and managing risks and vulnerabilities |
Lack of a methodological approach to managing risks and opportunities |
| Avoiding preventable risks |
Limiting to identifying risks without taking action |
| Addressing risks in the right order, reducing them to the maximum sustainable level |
Absence of warning thresholds |
| Avoiding excessive caution that limits the ability to seize opportunities |
Tendency to manage risks only when they arise |
| Ensuring compliance with laws, regulations, norms, and good management practices |
Neglecting the analysis of operational continuity |
| Monitoring risks and setting alert thresholds |
Unawareness of risky processes (absence of process risk assessment) |
| Verifying proper application through internal audits |
|