AnswerC
ExplanationThe correct answer is C. ISO 31000 clearly distinguishes between monitoring and review, even though they are closely related and often conducted together.
According to ISO 31000, monitoring is a continual activity focused on checking, supervising, observing, or critically determining the status of risks, controls, and the risk management process. Monitoring helps identify changes in risk levels, emerging risks, or deviations from expected performance in real time or near real time. Examples include tracking key risk indicators, control performance, or incident trends.
In contrast, review is a periodic or event-driven activity aimed at evaluating the suitability, adequacy, and effectiveness of the risk management framework, process, and controls in relation to objectives and context. Reviews assess whether risk management arrangements remain appropriate given changes in internal or external environments, strategy, or stakeholder expectations.
Option A is incorrect because ISO 31000 does not divide monitoring and review along regulatory versus contractual lines. Option B is incorrect because monitoring is not limited to strategic alignment, nor is review limited to daily supervision. Option D contradicts ISO 31000, which explicitly differentiates the two concepts.
From a PECB ISO 31000 Lead Risk Manager perspective, understanding this distinction is essential for effective governance. Monitoring provides early detection, while review supports learning, improvement, and strategic alignment. Therefore, the correct answer is monitoring is continual checking, while review evaluates suitability, adequacy, and effectiveness.