Skip to content

Governance

Risk Management

How we identify, assess, and treat risks to the commitments we make to our customers and stakeholders.

Last reviewed: July 2026

Systematic risk assessment helps us identify, prioritize, and track the treatment of risks to the commitments we make to our customers and other stakeholders. This page describes our approach to risk management.

Our approach

We periodically perform an operational risk assessment to identify risks that could affect our commitments. The results are compiled into a report that management reviews. Identified security risks are risk-rated, assigned to a risk owner, and tracked through to treatment or acceptance.

Where risk can come from

We consider internal and external security risk factors, including:

  • the possibility of fraud affecting our ability to meet our business objectives;
  • changes to the regulatory, economic, and physical environment in which we operate; and
  • risks associated with third-party vendors, which we assess under our Vendor and Subprocessor Management Policy.

How we think about risk

  • Threat: a possible situation or activity, whether deliberate, accidental, or caused by nature, that could degrade our operations. This may include service outages, data theft, physical harm, or financial loss.
  • Impact: the extent of damage that would result from a threat event, such as unauthorized access, unauthorized changes to or deletion of data, or partial or complete loss of system availability.
  • Likelihood: the probability that a threat will occur and cause damage.
  • Risk: we measure the net risk of a threat by combining its impact and likelihood (Risk = Impact x Likelihood).
  • Risk assessment: listing the threats to the organization, computing the risk for each, and benchmarking those against a predetermined acceptable level, so that threats above that level are addressed with mitigation measures.
  • Risk management: the program that carries out risk assessment and mitigation, including recognizing threats, analyzing their likelihood and impact, treating the outcomes, and monitoring the measures.

How we assess risk

Our risk assessments are a shared responsibility across our leadership, our security function, and the teams responsible for the area being assessed. We use qualified internal staff or experienced external parties, and each assessment produces a report with a risk-reduction action plan. Our process typically follows these steps:

  • Management defines the scope and assembles the assessment team with an owner to lead it.
  • The team lists the potential risks and threats to the system in scope.
  • For each threat, we quantify the impact of damage on a scale of 0 to 10, where 0 is negligible and 10 is the maximum.
  • For each threat, we estimate the likelihood of occurrence as a value between 0 and 1.
  • We compute the net risk from these two measures, giving a value between 0 and 10, and propose controls to reduce the impact and likelihood.
  • We produce a risk assessment report, share it with management, and communicate mitigation measures to the affected teams.
  • We take mitigation actions and monitor their effectiveness.

We carry out risk assessment at least annually. We use the learnings from previous assessments to understand how threats are changing and to build proactive threat intelligence for future work, and we update our process and methodology as needed in response to audits and incidents.

How we treat risk

  • When the net risk is less than 3, there are reasonable grounds to consider it acceptable.
  • For higher values, a risk may still be accepted if the cost of mitigation exceeds the net financial impact the risk could cause.
  • If a risk cannot be mitigated and the net risk exceeds 8, we consider additional treatment measures, including risk transfer options, and escalate to the CEO for a decision.
  • We rank threats in descending order of net risk to set the order in which we address them, design controls for the risks selected for mitigation, and plan their implementation in that order.

After controls and mitigation strategies are fully implemented, we compute the residual risk and decide whether to accept the risk, transfer it, add more controls, or take other action as needed. When an assessment is complete, we communicate the results to the affected teams.

Questions

If you have any questions about this policy, contact us at [email protected].

← Back to Trust Center

Questions about this policy? [email protected]