Monitoring and Review
Monitoring and review is the ongoing process of keeping track of identified risks, checking whether the measures put in place to manage them are working, and watching for new risks that may emerge. It typically involves regularly gathering and analyzing relevant data to confirm that risk management activities are helping the organization meet its objectives. Where a term or practice varies by context, the specific scope should be confirmed against the applicable framework or program.
In many risk management frameworks, monitoring and review refers to the continuous or periodic process of tracking identified risks, evaluating the effectiveness and continued relevance of risk treatments and controls, and detecting emerging or changed risks. It generally encompasses the regular collection and analysis of data to assess whether risk management activities are achieving their intended objectives, and is often integrated with broader monitoring and evaluation (M&E) processes to assure that the risk management process itself remains fit for purpose. The precise mechanisms, frequency, and reporting expectations vary by framework, sector, and organization, and readers should verify specific requirements against the applicable primary source or program guidance.
Why it matters
Risk management is not a one-time exercise. The risks an organization faces, and the effectiveness of the controls put in place to manage them, change over time as business conditions, regulations, and threats evolve. Monitoring and review provides the feedback loop that keeps a risk management program current: without it, an organization may continue to rely on treatments and controls that have quietly become outdated, ineffective, or misaligned with its objectives. In many frameworks it is monitoring and review that distinguishes an active, living risk process from a static register that reflects conditions as they were at a single point in time.
Monitoring and review also serves an assurance function. By regularly gathering and analyzing relevant data, organizations can test whether risk treatment controls are actually working as intended and whether the risk management process itself remains fit for purpose. This matters both for internal decision-making and for demonstrating diligence to boards, regulators, and other stakeholders. In some contexts, such as monitoring the accuracy of customer information, internal monitoring and review functions as a mechanism for detecting when previously reliable data or assumptions may no longer hold.
Because monitoring and review is frequently integrated with broader monitoring and evaluation (M&E) processes, its scope, frequency, and reporting expectations vary considerably by framework, sector, and organization. Readers should treat monitoring and review as a practice whose specific mechanics must be confirmed against the applicable program or framework rather than assumed to be uniform across contexts.
Who it's relevant to
Inside Monitoring and Review
Common questions
Answers to the questions practitioners most commonly ask about Monitoring and Review.

