Home / Insights / Glossary / Risk categories

Glossary

Risk categories

The groupings an organisation uses to sort risk — strategic, operational, financial, compliance, technology and others.

What it means

Most frameworks sort risk into categories so that related items can be owned, compared and reported together. Common groupings include strategic, operational, financial, compliance and legal, technology and cyber, people, and third-party or supply-chain risk. Some sectors add their own: clinical and care quality in health, safety and environmental in industrial operations.

Categories are a reporting convenience rather than a truth about the world. The risks that cause the most trouble usually cross several at once — a supplier failure is simultaneously operational, financial, compliance and reputational — so a category structure that forces a single home can hide the connection.

Where MyRISK fits

What we do about it

MyRISK works across all risk rather than cyber alone, which is why every sector page carries at least one example that is not cyber, privacy or AI. Categories matter less to us than whether a risk has an owner, a consequence somebody can name, and an action that moves.

See the four routes

Is this the thing you are actually trying to fix?

A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.