Three layers, and most organisations only have the third
Nearly every institution we assess runs a risk process of some kind. Far fewer have a framework governing it, and fewer still can show the principles are actually satisfied. The gap is almost always upward.
Six risk domains, one register
Enterprise risk management fails when each domain keeps its own list. Identification runs across all six, into a single register the board can read in one sitting.
Strategic
Objectives, market position, business model and the decisions that change the direction of the institution.
Operational
Processes, people, systems, third parties and the day-to-day failures that accumulate into events.
Financial
Credit, liquidity, market and capital exposures, and their interaction with the rest of the register.
Compliance
Regulatory obligations, supervisory expectations, contractual duties and the cost of falling short.
Information security
Confidentiality, integrity and availability of the data and systems the business depends on.
Business continuity
Disruption scenarios, recovery capability and the tolerance the board has actually agreed.
Somebody has to own each risk, and it cannot be “the business”
A large part of the engagement is establishing an accountability structure: who oversees, who decides, who escalates and at what threshold. Without it the register is a list of observations.
What exists at the end that did not exist before
Work that connects to it
Risk assessment
The operational cycle underneath the framework, run once or on a standing cadence.
ISO 27001
Information security risk treated as one domain within enterprise risk rather than a parallel programme.
Central Bank regulations
For supervised institutions, the framework is the vehicle for demonstrating risk governance.
