Assessing the risk of noncompliance ensures that decisions are based on an understanding of the business impact and security implications. "Before reporting or remediating, it is critical to assess the risk associated with the control bypass to make informed decisions." - CISM Review Manual 15th Edition, Chapter 2: Risk Management, Section: Risk Assessment*