SOC Risk Assessment: The SOC 2 Requirements Auditors Test
On February 12, 2024, attackers logged into a Change Healthcare remote-access portal that had … Read more
Enterprise risk management (ERM) is the discipline of identifying, assessing, and treating the full portfolio of risks that could prevent an organization from meeting its strategic objectives — financial, operational, strategic, compliance, and emerging risks alike. Unlike siloed risk functions, ERM gives boards and executives a single, integrated view of exposure so capital, controls, and management attention can be allocated where they move the needle most.
A mature ERM programme rests on three foundations. First, a governance framework — typically ISO 31000 or COSO ERM — that defines roles, escalation paths, and the three lines of defence. Second, a clear risk appetite statement that translates board tolerance into quantitative limits business units can actually manage against. Third, a repeatable risk management lifecycle covering identification, assessment, treatment, monitoring, and reporting.
Operationally, ERM depends on disciplined risk assessment — inherent vs residual scoring, control effectiveness testing, and scenario analysis — to keep the risk register honest. It also connects to sibling disciplines: business continuity management covers how the organisation survives disruption, information security management handles cyber and data risks, and governance, risk, and compliance (GRC) integrates the tooling and reporting that sits above all three.
Use this hub to explore frameworks, practitioner templates, certification guides (CRISC, FRM, PRM), and software comparisons. Whether you’re stood up a new ERM function or maturing an existing one, the resources below cover the methods, metrics, and reporting practices used by risk teams across financial services, healthcare, technology, and the public sector.
On February 12, 2024, attackers logged into a Change Healthcare remote-access portal that had … Read more
Machine guarding failures drew 1,239 OSHA citations in fiscal 2025, the standard’s 20th-plus consecutive … Read more
On February 4, 2026, the Federal Reserve finalized a scenario in which commercial real … Read more
On June 18, 2016, 20-year-old Regina Elsea entered a robotic station at the Ajin … Read more
In June 2025, OFAC penalized GVA Capital, a San Francisco venture firm, $215,988,868 for … Read more
Associated Builders and Contractors put a number on the humble toolbox talk in May … Read more
The Bureau of Labor Statistics put the median wage for US financial risk specialists … Read more
Sedgwick’s US Recall Index counted 858 million defective units recalled in 2025, a 26% … Read more
A mental health risk assessment template became measurable business infrastructure on September 28, 2022, … Read more
When Secureframe’s 2026 risk management study reported that 58% of organizations had been hit … Read more
On July 7, 2025, the European Commission opened consultation on a rewritten Annex 11, … Read more
This article provides an overview of Risk and Control Self-Assessment (RCSA) in a PDF … Read more