Englishالعربية Soon
Under attack?
ISO 31000:2018 · Enterprise risk management

Risk management belongs inside decision-making, not beside it.

We review, enhance and align your enterprise risk management framework with ISO 31000:2018, its principles, its framework and its process, so risk informs strategy rather than documenting it after the fact.

Built for regulated institutions
Domestic systemically important banks
Insurers and microfinance institutions
Government and public bodies
Organisations under central bank oversight
Groups integrating risk across subsidiaries

ISO 31000 is a guidance standard, not a certifiable one. What we deliver is a framework that withstands supervisory scrutiny and an organisation that can demonstrate it operates, which is what a regulator actually asks for.

The standard

Three layers, and most organisations only have the third

Nearly every institution we assess runs a risk process of some kind. Far fewer have a framework governing it, and fewer still can show the principles are actually satisfied. The gap is almost always upward.

Layer 1

Principles

Eight elements

What the framework has to satisfy

Integrated into all organisational activities
Structured and comprehensive in approach
Customised to context and objectives
Inclusive of stakeholders and their views
Dynamic, anticipating and responding to change
Built on the best available information
Accounting for human and cultural factors
Continually improved through learning
Layer 2

Framework

Five elements

How risk management is governed and sustained

Leadership and commitment from the top
Integration into governance and structure
Design against context, appetite and roles
Implementation with a plan, resources and authority
Evaluation and continual improvement of the framework itself
Layer 3

Process

Six elements

What is done, repeatedly, in practice

Scope, context and criteria established
Risk identification across all domains
Risk analysis of likelihood and consequence
Risk evaluation against agreed criteria
Risk treatment with owners and follow-up
Monitoring, review, recording and reporting
Methodology

Seven phases, aligned to ISO 31000 and supported by ISO 31010

Structured and phased, but customised to your operations, objectives and supervisory context. A methodology applied identically to a bank and a manufacturer is a methodology applied to neither.

01
Initiation & planning
Existing policies, frameworks, governance structures and previous assessments reviewed. Stakeholders identified, responsibilities assigned, secure data-sharing established under NDA, and integration with your strategic objectives and supervisory expectations confirmed.
02
Pre-assessment & current state
A pre-audit against the principles, framework and process. Gaps identified across integration, structure, inclusiveness and adaptability; design, implementation, evaluation and improvement; identification through to review. Governance arrangements assessed, including appetite, culture and oversight. Output is a documented gap analysis with prioritised recommendations.
03
Risk identification
Recognised techniques applied: structured brainstorming, interviews, document review, capturing risk across strategic, operational, financial, compliance, information security and business continuity domains, covering internal and external factors alike.
04
Analysis & evaluation
ISO 31010 techniques applied to assess likelihood, consequence and overall level. Risks prioritised against an agreed scoring model and your stated appetite, then mapped to strategic objectives and regulatory obligations.
05
Treatment planning
Treatment actions developed for high-priority risks in line with appetite and mitigation capacity, each with a named owner, follow-up requirements, and built-in monitoring so the plan does not decay.
06
Framework documentation
The risk management framework updated and documented against ISO 31000 principles and your governance structure, then validated and finalised with management rather than delivered over a wall.
07
Capacity building
Targeted workshops and awareness sessions for the risk team, senior management and key stakeholders, with feedback loops and periodic review mechanisms that embed continual improvement rather than announce it.
Coverage

Six risk domains, one register

Enterprise risk management fails when each domain keeps its own list. Identification runs across all six, into a single register the board can read in one sitting.

Strategic

Objectives, market position, business model and the decisions that change the direction of the institution.

Operational

Processes, people, systems, third parties and the day-to-day failures that accumulate into events.

Financial

Credit, liquidity, market and capital exposures, and their interaction with the rest of the register.

Compliance

Regulatory obligations, supervisory expectations, contractual duties and the cost of falling short.

Information security

Confidentiality, integrity and availability of the data and systems the business depends on.

Business continuity

Disruption scenarios, recovery capability and the tolerance the board has actually agreed.

Governance

Somebody has to own each risk, and it cannot be “the business”

A large part of the engagement is establishing an accountability structure: who oversees, who decides, who escalates and at what threshold. Without it the register is a list of observations.

Board and risk committee
Sets appetite, approves the framework, receives reporting and challenges it.
Executive management
Owns integration into strategy and decision-making, and resources the treatment plan.
Risk function
Maintains the framework and register, facilitates assessment, and reports independently.
Risk owners
Named individuals accountable for specific risks and their treatment actions.
Internal audit
Provides independent assurance that the framework operates as documented.
Deliverables

What exists at the end that did not exist before

Gap analysis report against principles, framework and process
Documented scope, context and risk criteria
Risk management framework document, validated with management
Risk management policy aligned to appetite and strategy
Enterprise risk register spanning all six domains
Agreed scoring model your team can apply without us
Risk treatment plans with named owners and follow-up
Governance and accountability matrix
Roles, responsibilities and escalation thresholds
Workshop and awareness material for each audience
Monitoring, review and reporting mechanisms
Continual improvement process with defined cadence
Related

Work that connects to it

Risk assessment

The operational cycle underneath the framework, run once or on a standing cadence.

ISO 27001

Information security risk treated as one domain within enterprise risk rather than a parallel programme.

Central Bank regulations

For supervised institutions, the framework is the vehicle for demonstrating risk governance.

Start with the pre-assessment.

A pre-audit against the three layers tells you which of them you actually have, and what the rest would take.