There are a number of standards and methodologies designed to assist company management in developing risk management systems. The most widespread and universal standards are FERMA, ISO 31000:2009 and COSO II.Despite of versatility, each of the documents is aimed at
a specific goal, which causes the difference in types of risks and risk management tools described by them. However,one can identify similarities in risk assessment processes described by standards. Analysis of risk assessmen approaches defined by COSO II, FERMA, ISO 31000
(Figure1) revealed that there are three basic tasks to be completed during risk assessment; those are risk identification, measurement and prioritization. Each task requires decision making