Skip to main content
Category: Enterprise Risk Management

Scope, Context and Criteria

Also known as: Establishing the Context, Scope, Context, and Criteria
Simply put

Scope, Context and Criteria is an early step in the risk management process where an organization decides where and how the process will be applied, understands the surrounding conditions, and sets the standards used to judge risks. Defining the scope clarifies what is included and what is excluded, while context covers the internal and external factors that shape the organization's situation. The criteria establish the reference points against which the significance of risks will be evaluated.

Formal definition

In ISO 31000 (issued by the International Organization for Standardization), Scope, Context and Criteria is the activity through which an organization tailors its risk management process to a defined application. Scope determines the boundaries of the process, identifying what will be included and excluded. Context defines the external and internal parameters relevant to the objectives under consideration. Risk criteria, referenced in the standard, express the terms of reference against which the significance of risk is assessed, and are typically aligned with the organization's objectives, external and internal context. This step precedes and informs risk assessment (risk identification, analysis, and evaluation). This entry does not cover implementation-specific methods, tooling, or particular criteria values, which vary by organization, jurisdiction, and sector.

Why it matters

Scope, Context and Criteria functions as the foundation on which the rest of the risk management process rests. Without a clearly defined scope, organizations risk applying risk assessment inconsistently, either overextending the effort into areas that add little value or omitting activities, assets, or objectives that matter. By stating explicitly what is included and excluded, this step helps ensure that later risk identification, analysis, and evaluation are directed at the right boundaries and are proportionate to the decision being supported.

Who it's relevant to

Risk Managers
Risk managers use this step to set the boundaries, contextual parameters, and criteria that direct how the risk management process is applied. Getting scope, context, and criteria right helps ensure that subsequent risk assessment is proportionate, consistent, and aligned with organizational objectives.
Governance Professionals
Those responsible for governance structures benefit from clearly defined scope and context because these clarify how risk management connects to organizational objectives and decision rights. Defined criteria support comparability of risk information reaching governance bodies.
Internal Auditors and Assurance Functions
Assurance providers can evaluate whether an organization has appropriately defined the scope, context, and criteria of its risk management process, and whether these remain aligned with objectives. This assessment is an assurance activity distinct from the management activity of establishing the criteria themselves, and independence between the two should be maintained.
Compliance Officers
Compliance specialists may find this step relevant where external legal and regulatory conditions form part of the external context, or where compliance obligations inform the criteria used to judge the significance of certain risks. The applicable regulatory context varies by jurisdiction and sector.

Inside Scope, Context and Criteria

Scope
Defines the boundaries of the risk management activity, what parts of the organization, processes, objectives, timeframes, and decisions are included and excluded. Establishing scope clarifies the focus and depth of the assessment before analysis begins.
External Context
Encompasses the environment outside the organization that may influence its ability to achieve objectives, such as legal and regulatory factors, market and economic conditions, social and cultural drivers, and the expectations of external stakeholders. In ISO 31000, understanding external context helps frame relevant sources of uncertainty.
Internal Context
Encompasses factors within the organization, including its governance structures, roles and accountabilities, objectives and strategies, culture, capabilities, and internal stakeholders. Internal context connects risk activities to how the organization is actually directed and operates.
Risk Criteria
The terms of reference against which the significance of risk is evaluated. Criteria typically reflect the organization's objectives and may draw on its risk appetite and tolerances. They commonly address how likelihood and consequence are described, how levels of risk are determined, and the basis for deciding whether risk requires treatment.
Alignment with Objectives
Scope, context, and criteria are set in relation to the objectives at stake, so that identified uncertainty is assessed against what the organization is trying to achieve rather than in the abstract.

Common questions

Answers to the questions practitioners most commonly ask about Scope, Context and Criteria.

Is establishing scope, context, and criteria the same as performing the risk assessment itself?
No. Scope, context, and criteria is the preparatory phase that frames a risk assessment; it defines the boundaries, the internal and external environment, and the reference points against which risk will be evaluated. The risk assessment, comprising risk identification, analysis, and evaluation, is a distinct subsequent activity that draws on these parameters. In ISO 31000, for example, establishing scope, context, and criteria is described as a step that precedes and informs the assessment rather than being part of it.
Do risk criteria fix a single, permanent threshold that applies across the whole organization?
Not typically. Risk criteria are the terms of reference used to judge the significance of risk, and they commonly vary by scope, objective, activity, and level of the organization. They may be revisited and revised as circumstances, objectives, or the organization's understanding of risk change. Treating criteria as a fixed universal threshold can misrepresent how they are intended to be applied and reviewed.
How is the scope of a risk assessment usually determined?
Scope is generally defined by the objectives the assessment supports and the decisions it is intended to inform. Practitioners commonly specify the activities, processes, functions, timeframes, and organizational units to be included and excluded, along with the level of detail and any dependencies on other assessments. Clarifying what is out of scope is as important as stating what is in scope.
What elements of context are commonly considered when framing a risk assessment?
Framing typically distinguishes external context, such as legal, regulatory, market, and stakeholder factors, from internal context, such as governance arrangements, objectives, capabilities, culture, and resources. In many frameworks the risk criteria are aligned with the organization's risk appetite and relevant obligations. The specific factors that matter will depend on jurisdiction, sector, and the nature of the activity being assessed.
How are risk criteria typically expressed in practice?
Risk criteria may be expressed qualitatively, quantitatively, or as a combination, and often address the nature and type of consequences considered, how likelihood is described, how the level of risk is determined, and how combinations of risks are treated. The chosen approach commonly reflects the objectives, available data, and the decisions the assessment supports; this entry does not prescribe specific scales or tooling.
How often should scope, context, and criteria be reviewed?
These parameters are generally reviewed when the objectives, environment, or organizational circumstances that shaped them change, and periodically as part of the broader risk management process. Because they underpin the comparability and relevance of assessment results, revisiting them supports consistency over time. The appropriate frequency varies by organization, sector, and the volatility of the relevant context.

Common misconceptions

Establishing scope, context, and criteria is a one-time, purely administrative step at the start of a project.
In many frameworks, including ISO 31000, context and criteria are intended to be revisited and updated as circumstances change. Objectives, external conditions, and stakeholder expectations may shift, so these parameters are typically reviewed periodically rather than fixed permanently.
Risk criteria and risk appetite are the same thing.
Risk appetite expresses the amount and type of risk an organization is willing to pursue or retain, whereas risk criteria are the specific reference points used to evaluate the significance of a given risk. Criteria may be informed by appetite and tolerance, but they operate at a more granular, operational level of evaluation.
Context is only about the external environment such as regulation and markets.
Context spans both external and internal factors. Internal context, governance arrangements, objectives, culture, and capabilities, is equally important, and treating context as purely external omits how the organization itself shapes the risks it faces.

Best practices

Define and document the scope explicitly, stating what is included and excluded, the timeframe, and the objectives the assessment relates to, so subsequent analysis is bounded and consistent.
Assess external and internal context together, capturing regulatory, market, and stakeholder factors alongside governance structures, objectives, culture, and capabilities.
Set risk criteria that trace back to the organization's objectives and, where established, its risk appetite and tolerances, and record the basis on which likelihood and consequence are described.
Involve relevant stakeholders when establishing context and criteria so that differing perspectives and expectations are reflected before evaluation begins.
Review and update scope, context, and criteria periodically or when material changes occur, rather than treating them as a fixed, one-time input.
Keep criteria transparent and consistently applied across comparable assessments so that risk evaluations remain defensible and can be understood by those relying on them.
Promotional banner for the Penetration Report Template Kit