Finally the controls that you have put in place need to be reviewed and changed as necessary. This can be done by using processes already described in previous steps.
For more information on monitoring and reviewing control measures refer to Section 7 of Supplement 3 (PDF, 260 kB) of the Risk Management Code of Practice 2007.