Evaluate, Categorize, and Prioritize Risks
Evaluate and categorize each identified risk using the defined risk categories and parameters, and determine its relative priority.

The evaluation of risks is needed to assign relative importance to each identified risk, and is used in determining when appropriate management attention is required. Often it is useful to aggregate risks based on their interrelationships, and develop options at an aggregate level. When an aggregate risk is formed by a roll up of lower level risks, care must be taken to ensure that important lower level risks are not ignored.

Collectively, the activities of risk evaluation, categorization, and prioritization are sometimes called “risk assessment” or “risk analysis.”