Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Enterprise Risk Management

Monitoring and Review

Also known as: Risk Monitoring, Monitoring and Evaluation, Internal Monitoring and Review
Simply put

Monitoring and review is the ongoing process of keeping track of identified risks, checking whether the measures put in place to manage them are working, and watching for new risks that may emerge. It typically involves regularly gathering and analyzing relevant data to confirm that risk management activities are helping the organization meet its objectives. Where a term or practice varies by context, the specific scope should be confirmed against the applicable framework or program.

Formal definition

In many risk management frameworks, monitoring and review refers to the continuous or periodic process of tracking identified risks, evaluating the effectiveness and continued relevance of risk treatments and controls, and detecting emerging or changed risks. It generally encompasses the regular collection and analysis of data to assess whether risk management activities are achieving their intended objectives, and is often integrated with broader monitoring and evaluation (M&E) processes to assure that the risk management process itself remains fit for purpose. The precise mechanisms, frequency, and reporting expectations vary by framework, sector, and organization, and readers should verify specific requirements against the applicable primary source or program guidance.

Why it matters

Risk management is not a one-time exercise. The risks an organization faces, and the effectiveness of the controls put in place to manage them, change over time as business conditions, regulations, and threats evolve. Monitoring and review provides the feedback loop that keeps a risk management program current: without it, an organization may continue to rely on treatments and controls that have quietly become outdated, ineffective, or misaligned with its objectives. In many frameworks it is monitoring and review that distinguishes an active, living risk process from a static register that reflects conditions as they were at a single point in time.

Monitoring and review also serves an assurance function. By regularly gathering and analyzing relevant data, organizations can test whether risk treatment controls are actually working as intended and whether the risk management process itself remains fit for purpose. This matters both for internal decision-making and for demonstrating diligence to boards, regulators, and other stakeholders. In some contexts, such as monitoring the accuracy of customer information, internal monitoring and review functions as a mechanism for detecting when previously reliable data or assumptions may no longer hold.

Because monitoring and review is frequently integrated with broader monitoring and evaluation (M&E) processes, its scope, frequency, and reporting expectations vary considerably by framework, sector, and organization. Readers should treat monitoring and review as a practice whose specific mechanics must be confirmed against the applicable program or framework rather than assumed to be uniform across contexts.

Who it's relevant to

Risk Managers
Risk managers own the ongoing tracking of identified risks and the evaluation of whether risk treatment controls remain effective and relevant. Monitoring and review is central to their role in keeping the risk register current and in detecting new or changed risks before they materialize into events.
Internal Auditors
Internal auditors draw on monitoring and review activities to assess whether the risk management process is functioning as intended and whether controls are operating effectively. The data gathered through regular monitoring can inform audit planning and support independent assurance over the program's fitness for purpose.
Compliance Officers
In areas such as internal monitoring and review of customer information, compliance functions rely on in-house controls to detect when previously accurate data may no longer be reliable. Ongoing monitoring supports adherence to applicable obligations, though specific requirements vary by jurisdiction and sector and should be confirmed against the relevant rules.
Project and Program Teams
Where risk monitoring is integrated into a project's monitoring and evaluation (M&E) process, project and program teams use it to assure that the project's risk management process continues to function throughout the project lifecycle, gathering and analyzing data on a regular basis to confirm objectives are being met.
Boards and Senior Leadership
Governance bodies rely on the outputs of monitoring and review to maintain oversight of the organization's risk profile and to confirm that risk management activities remain aligned with objectives. Reporting expectations differ by framework and organization, so leaders should clarify the scope and cadence of the monitoring information they receive.

Inside Monitoring and Review

Monitoring
The ongoing, often continuous, checking, supervising, and observation of processes, controls, and risks to track whether they perform and behave as intended. In many frameworks such as ISO 31000, monitoring is treated as a continual activity woven through the risk management process rather than a single point-in-time event.
Review
A periodic activity undertaken to determine the suitability, adequacy, and effectiveness of the subject matter, such as controls, the risk assessment, or the wider management framework, in achieving established objectives. Reviews are typically scheduled at defined intervals or triggered by significant change.
Continuous vs. periodic activity
Monitoring tends to be characterized as continuous or frequent, while review tends to be periodic or event-driven. The two are complementary: monitoring surfaces information over time, and review evaluates that information and the overall system at defined points.
Feedback and improvement loop
Findings from monitoring and review are typically fed back into other elements of the framework to correct deficiencies, update risk assessments, adjust controls, and inform decision-making, supporting a cycle of continual improvement.
Roles and accountability
Responsibility for monitoring and review is usually assigned across an organization, spanning process owners, risk and compliance functions, internal audit, and governance bodies. Clear allocation of who monitors, who reviews, and who receives results is a common expectation, though specific structures vary by organization.
Documentation and reporting
Results of monitoring and review are commonly recorded and reported to relevant stakeholders to provide a defensible record and to enable oversight. The nature and formality of documentation vary by framework, sector, and organization size.

Common questions

Answers to the questions practitioners most commonly ask about Monitoring and Review.

Is monitoring and review the same activity as internal audit?
No. Monitoring and review is typically a continuous, management-owned process embedded within the risk management framework, intended to track the performance of risks, controls, and the framework itself over time. Internal audit, by contrast, generally provides independent, periodic assurance over the design and operating effectiveness of governance, risk, and control processes. In many frameworks these are treated as distinct 'lines' with different reporting relationships and degrees of independence. While the two are complementary and their outputs may inform one another, treating routine monitoring as a substitute for independent assurance, or vice versa, can leave gaps. The specific division of responsibilities varies by organization and governance model.
Does monitoring and review only happen at the end of the risk management cycle?
Not in most framework depictions. Although diagrams sometimes place monitoring and review at the end of a sequence of steps, many frameworks describe it as an ongoing activity that runs in parallel with, and feeds back into, the other elements of the process. In this view it is not a final checkpoint but a continuous function that can prompt reassessment of context, risk identification, analysis, evaluation, and treatment at any point. Some frameworks also distinguish continuous monitoring from periodic review, with the two operating on different cadences. Treating it purely as a closing step may cause emerging changes to go unnoticed between cycles.
How often should monitoring and review be performed?
There is no single prescribed frequency, and appropriate cadence typically depends on factors such as the volatility of the risk, the significance of the objectives affected, regulatory expectations, and available resources. Many organizations combine continuous or near-real-time monitoring of certain indicators with periodic reviews conducted at defined intervals or triggered by events such as significant changes in context, incidents, or organizational change. Frequency and triggers are often documented within the risk management framework or policy. Because expectations vary by jurisdiction and sector, specific requirements should be verified against applicable regulations and internal governance documents.
What kinds of information or indicators are commonly used to support monitoring and review?
Organizations often draw on a range of inputs, which may include key risk indicators, control performance data, incident and loss records, results of testing or assurance activities, audit findings, and changes in the internal or external environment. Some frameworks emphasize capturing both leading indicators, which may signal emerging risk before it materializes, and lagging indicators, which reflect outcomes that have already occurred. The selection of indicators is typically tailored to the organization's objectives, risk profile, and appetite. This entry does not prescribe specific metrics, as suitability is context-dependent.
Who is typically responsible for monitoring and review?
Responsibilities are commonly distributed rather than assigned to a single party. In many governance models, operational management owns and performs day-to-day monitoring of risks and controls within their areas; risk and compliance functions may oversee, aggregate, and challenge that information; and governing bodies or committees typically review summarized results and provide direction. Independent assurance providers, where present, generally review the effectiveness of these arrangements rather than perform them. The precise allocation depends on the organization's structure, size, and chosen framework, and should be defined in governance documentation.
How can the results of monitoring and review be used effectively?
Outputs are typically most useful when they feed back into decision-making and drive action, rather than being recorded for their own sake. This can include updating risk assessments, adjusting or strengthening controls, revisiting risk treatment decisions, reassessing whether residual risk remains within tolerance, and informing reporting to management and governing bodies. Many frameworks also treat monitoring and review as a means of evaluating and improving the risk management framework itself over time. Documenting findings, decisions, and follow-up actions can support accountability and provide evidence of the process, though the appropriate level of documentation depends on organizational and, where relevant, regulatory expectations.

Common misconceptions

Monitoring and review are the same activity used interchangeably.
Although related, they are distinct. Monitoring is typically ongoing observation to track performance and behavior, while review is a periodic or triggered evaluation of suitability, adequacy, and effectiveness. Treating them as identical can leave gaps in either continuous oversight or periodic evaluation.
Monitoring and review confirm that controls are working and therefore eliminate risk.
Monitoring and review assess whether controls and processes are operating as intended, but they do not eliminate risk. Controls modify risk rather than remove it, and residual risk typically remains even where monitoring indicates controls are effective.
Monitoring and review are a compliance-only obligation performed to satisfy auditors.
While monitoring and review support compliance, they span governance and risk management as well, informing decision-making and continual improvement. Framing them solely as an audit exercise understates their role in the broader management framework.

Best practices

Distinguish clearly in your framework which activities are continuous monitoring and which are periodic or triggered reviews, and define the frequency and triggers for each.
Assign explicit accountability for monitoring, for review, and for acting on the results, so that responsibilities across process owners, risk and compliance functions, and oversight bodies are unambiguous.
Establish a feedback loop so that findings are routed back into risk assessments, control adjustments, and decision-making rather than being recorded and set aside.
Document monitoring and review activities and their outcomes in a way that provides a defensible record and supports oversight, scaling formality to the organization's size and context.
Report results to the relevant stakeholders on a timely basis so that governance bodies and management can respond to emerging issues and changing conditions.
Review the suitability and effectiveness of the monitoring and review arrangements themselves at defined intervals, and update them when significant change occurs in objectives, risks, or the operating environment.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps