A Complete Guide to the Risk Assessment Process
Key Takeaways Risk assessment is a structured, repeatable cycle of identification, analysis, evaluation, treatment, … Read more
Enterprise risk management (ERM) is the discipline of identifying, assessing, and treating the full portfolio of risks that could prevent an organization from meeting its strategic objectives — financial, operational, strategic, compliance, and emerging risks alike. Unlike siloed risk functions, ERM gives boards and executives a single, integrated view of exposure so capital, controls, and management attention can be allocated where they move the needle most.
A mature ERM programme rests on three foundations. First, a governance framework — typically ISO 31000 or COSO ERM — that defines roles, escalation paths, and the three lines of defence. Second, a clear risk appetite statement that translates board tolerance into quantitative limits business units can actually manage against. Third, a repeatable risk management lifecycle covering identification, assessment, treatment, monitoring, and reporting.
Operationally, ERM depends on disciplined risk assessment — inherent vs residual scoring, control effectiveness testing, and scenario analysis — to keep the risk register honest. It also connects to sibling disciplines: business continuity management covers how the organisation survives disruption, information security management handles cyber and data risks, and governance, risk, and compliance (GRC) integrates the tooling and reporting that sits above all three.
Use this hub to explore frameworks, practitioner templates, certification guides (CRISC, FRM, PRM), and software comparisons. Whether you’re stood up a new ERM function or maturing an existing one, the resources below cover the methods, metrics, and reporting practices used by risk teams across financial services, healthcare, technology, and the public sector.
Key Takeaways Risk assessment is a structured, repeatable cycle of identification, analysis, evaluation, treatment, … Read more
What Is Risk Management? A Clear Definition Risk management is the structured process of … Read more
Key Takeaways Risk monitoring is not a milestone — it is a continuous discipline … Read more
During an annual board risk review at a mid-size healthcare provider, the Chief Risk … Read more
A cybersecurity team at a regional bank discovered a critical vulnerability in their online … Read more
On May 8, 2024, Ascension Health, one of the largest US hospital systems, took … Read more
To Calculate Risk Scores for Project Risk Analysis is a discipline many teams skip … Read more
Key Takeaways Gallagher (Arthur J. Gallagher & Co.) is the world’s fourth-largest insurance broker … Read more
A logistics warehouse manager in the South Bronx received a call at 2:00 AM … Read more
Good questions to ask about risk separate strong governance from weak governance. The right … Read more
Key Takeaways In February 2024, a mid-sized financial services firm in Nairobi walked into … Read more
In January 2025, Korn Ferry released its annual CEO and Board Survey. The headline … Read more