ITIL Change Management Risk Assessment Template
The IT Infrastructure Library (ITIL) is a widely adopted framework in the United States, … Read more
Enterprise risk management (ERM) is the discipline of identifying, assessing, and treating the full portfolio of risks that could prevent an organization from meeting its strategic objectives — financial, operational, strategic, compliance, and emerging risks alike. Unlike siloed risk functions, ERM gives boards and executives a single, integrated view of exposure so capital, controls, and management attention can be allocated where they move the needle most.
A mature ERM programme rests on three foundations. First, a governance framework — typically ISO 31000 or COSO ERM — that defines roles, escalation paths, and the three lines of defence. Second, a clear risk appetite statement that translates board tolerance into quantitative limits business units can actually manage against. Third, a repeatable risk management lifecycle covering identification, assessment, treatment, monitoring, and reporting.
Operationally, ERM depends on disciplined risk assessment — inherent vs residual scoring, control effectiveness testing, and scenario analysis — to keep the risk register honest. It also connects to sibling disciplines: business continuity management covers how the organisation survives disruption, information security management handles cyber and data risks, and governance, risk, and compliance (GRC) integrates the tooling and reporting that sits above all three.
Use this hub to explore frameworks, practitioner templates, certification guides (CRISC, FRM, PRM), and software comparisons. Whether you’re stood up a new ERM function or maturing an existing one, the resources below cover the methods, metrics, and reporting practices used by risk teams across financial services, healthcare, technology, and the public sector.
The IT Infrastructure Library (ITIL) is a widely adopted framework in the United States, … Read more
The Information Technology Infrastructure Library (ITIL) Change Management Risk Assessment Matrix is essential in … Read more
The adoption of the ISO 27001:2022 standard, a globally acknowledged benchmark for information security … Read more
ISO 27001:2022 is an international standard for information security management systems (ISMS) that systematically … Read more
The ISO 13485:2016 Medical devices risk assessment template is an invaluable tool for organizations … Read more
Machine safety is an essential part of any industry, and the ISO 12100:2010 risk … Read more
Insider threats are a major risk to organizations, as they involve individuals who are … Read more
On July 28, 2015, OSHA cited Wilbert Plastic Services of Bellevue, Ohio, $48,900 after … Read more
In February 2021, an attacker gained remote access to a water treatment facility in … Read more
Identity theft, an increasingly prevalent issue, poses significant threats to individuals’ financial and personal … Read more
The HCR-20 Risk Assessment Template is a widely used tool in the field of … Read more
In February 2024, Boar’s Head pulled 7 million pounds of deli meat after a … Read more