According to the CRISC Review Manual (Digital Version), the next course of action when an organization has determined a risk scenario is outside the defined risk tolerance level is to identify risk responses, which are the actions or measures taken to address the risk. Identifying risk responses helps to: Reduce the likelihood and/or impact of the risk to an acceptable level Align the risk response with the organization's risk appetite and risk tolerance Optimize the value and benefits of the risk response Balance the costs and efforts of the risk response with the potential losses or damages caused by the risk Coordinate and communicate the risk response with the relevant stakeholders References = CRISC Review Manual (Digital Version), Chapter 3: IT Risk Response, Section 3.2: Risk Response Process, pp. 161-1621