Procedure 16 ADMINISTRATIVE
Risk Assessment Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 16 · PCI DSS Req 12.3 · 0 of 4 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 16 — Risk Assessment PolicyThe rule this procedure implements
How Revique implements this today
Risk assessment is a documented management activity. What exists today in place of a formal assessment is a set of point-in-time technical reviews — the PCI DSS requirement reports and the HIPAA gap-assessment published elsewhere on this site, and this procedures section, which enumerates the estate's actual control state and its gaps. These are inputs to a risk assessment, not a substitute for one: they identify weaknesses but do not rank them by likelihood and impact, assign owners, or record management's acceptance or treatment decision.
The rule against the current state
Each row takes a statement from Policy 16 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| A formal risk assessment at least annually and on significant change | No formal risk assessment document exists. | Gap |
| Risks documented, ranked and assigned treatment actions | Gaps are documented here and in the PCI/HIPAA reports, but are not ranked by risk or assigned owners and deadlines. | Partial |
| A cryptographic and asset inventory maintained and reviewed | The KMS key list and account resource inventories exist in AWS but no maintained inventory document is kept. AWS Config, which would provide the asset inventory automatically, is not enabled. | Gap |
| Risk treatment progress tracked to closure | No risk register exists to track. | Gap |
🔍 Auditor verification — where to log in and what you will see
What technical input existsThis documentation site → the PCI DSS requirement reports, the HIPAA gap-assessment, and this Procedures section — each lists concrete, dated findings.
Cryptographic inventory sourceConsole → KMS → Customer managed keys, per account and region — 6 keys total, which is the raw material for the inventory.
Asset inventory sourceConsole → AWS Config → expect not enabled; without it, inventory must be assembled per service.
The risk assessment itselfAsk for the dated risk assessment, the risk register with rankings and owners, and management's acceptance decisions. Not stored in AWS.
Team process
The Security Officer conducts and documents the risk assessment at least annually and after significant change, drawing on the technical findings in this section. Management reviews the ranked risks and either accepts them or funds treatment; the Security Officer tracks treatment to closure.
⚠️ Where reality does not meet the policy
- No formal risk assessment has been performed or documented. This is a foundational PCI DSS 12.3 and HIPAA requirement, and its absence means every gap listed across these 21 procedures is currently unranked and unowned.
- No maintained cryptographic or asset inventory, as required by both this policy and Policy 9. Enabling AWS Config would supply the asset half of this automatically.
- There is no risk register, so there is nothing to track treatment against.
Evidence location. Risk assessment, risk register and management acceptance decisions are documents held by the Security Officer.
📘Back to the PolicyPolicy 16 — Risk Assessment Policy (PCI DSS Req 12.3)←