Employee Key Performance Indicators: 26 KPI Examples with Formulas and Benchmarks
Gallup’s 2025 State of the Global Workplace report delivered a number that should alarm … Read more
Enterprise risk management (ERM) is the discipline of identifying, assessing, and treating the full portfolio of risks that could prevent an organization from meeting its strategic objectives — financial, operational, strategic, compliance, and emerging risks alike. Unlike siloed risk functions, ERM gives boards and executives a single, integrated view of exposure so capital, controls, and management attention can be allocated where they move the needle most.
A mature ERM programme rests on three foundations. First, a governance framework — typically ISO 31000 or COSO ERM — that defines roles, escalation paths, and the three lines of defence. Second, a clear risk appetite statement that translates board tolerance into quantitative limits business units can actually manage against. Third, a repeatable risk management lifecycle covering identification, assessment, treatment, monitoring, and reporting.
Operationally, ERM depends on disciplined risk assessment — inherent vs residual scoring, control effectiveness testing, and scenario analysis — to keep the risk register honest. It also connects to sibling disciplines: business continuity management covers how the organisation survives disruption, information security management handles cyber and data risks, and governance, risk, and compliance (GRC) integrates the tooling and reporting that sits above all three.
Use this hub to explore frameworks, practitioner templates, certification guides (CRISC, FRM, PRM), and software comparisons. Whether you’re stood up a new ERM function or maturing an existing one, the resources below cover the methods, metrics, and reporting practices used by risk teams across financial services, healthcare, technology, and the public sector.
Gallup’s 2025 State of the Global Workplace report delivered a number that should alarm … Read more
In 2024, a mid-cap asset manager lost $47 million in a single quarter—not because … Read more
In the late 1950s, a sedative marketed as safe for pregnant women left a … Read more
In 2023, a mid-sized healthcare system in the U.S. Southeast discovered that a single … Read more
Key Takeaways Business Risk Management: A Practitioner’s Guide to Protecting Value and Driving Growth … Read more
In September 2023, a mid-tier Australian financial services firm reported a $1.2 billion loss … Read more
On February 21, 2024, ALPHV/BlackCat ransomware operators encrypted Change Healthcare’s systems and shut down … Read more
Risk Control Self-Assessments (RCSA) are critical in operational risk management. RCSAs allow organizations to … Read more
On 10 October 2024, TD Bank pleaded guilty to wilfully violating the Bank Secrecy … Read more
There are several important reasons why regulatory compliance is crucial in banking: Adhering to … Read more
Navigating the intricate landscape of the banking sector, characterized by frequently evolving regulations and … Read more
Risk Control Self Assessment (RCSA) is essential because it is a process that helps … Read more