This article is dedicated to enterprise risk management, specifically the problem of subjectivity of decisions made on different phases of
risk management process, risk assessment in particular. Quality of decisions strongly affects the effectiveness of risk management process
as a whole; at the same time, standards regulating risk management do not provide any instruments to support the decision-making process.
The main objective of this study is to decrease the subjectivity of decisions made during the risk management process by integrating
decision theory tools into the risk assessment phase. As a result, an approach to risk assessment using Analytical Hierarchy Process is
introduced; the approach is then implemented to IT Service Management processes.