Risk Avoidance
Pronunciation: RISK uh-VOY-duns
Definition
Risk avoidance removes exposure by not starting, discontinuing, or materially redesigning the activity that creates a particular risk. Decision-makers use Risk Avoidance to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified. A score for Risk Avoidance is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions.
Overview
Risk avoidance is a treatment choice used when exposure exceeds appetite, cannot be controlled adequately, or offers insufficient benefit. Examples include declining a market, disabling a feature, ending a vendor relationship, or prohibiting a transaction type.
Avoidance differs from mitigation, which reduces likelihood or impact while continuing the activity. It may also shift risk elsewhere through customer migration, operational workarounds, lost revenue, concentration, or dependence on alternative providers.
Decision-makers should define the scenario being avoided, verify that exposure is actually removed, assess secondary effects, communicate ownership, and monitor for unauthorized re-entry. Exit plans must address contracts, data, funds, customers, records, and continuing obligations. Management should confirm that revenue incentives do not recreate prohibited activity indirectly.
For Risk Avoidance, repeated renewal is a signal that the underlying design needs correction.
Risk avoidance removes exposure by not starting, discontinuing, or materially redesigning the activity that creates a particular risk. Risk avoidance ends the risk-creating activity, but it must be verified because workarounds, migration, and exit obligations can create new exposure.
For Risk Avoidance, the assessment should evaluate Risk avoidance removes exposure by not starting, discontinuing, or materially redesigning the activity that creates a particular risk. The assessment record should separate observed evidence supporting Risk avoidance removes exposure by not starting, discontinuing, or materially redesigning the activity that creates a particular risk from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in Risk avoidance removes exposure by not starting, discontinuing, or materially redesigning the activity that creates a particular risk have changed enough to require a new rating, treatment, or approval.
Key Takeaway
Risk avoidance ends the risk-creating activity, but it must be verified because workarounds, migration, and exit obligations can create new exposure.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)