Understanding the CRAMM Risk Assessment Method
CRAMM (CCTA Risk Analysis and Management Method) is a version of a well-established risk … Read more
Enterprise risk management (ERM) is the discipline of identifying, assessing, and treating the full portfolio of risks that could prevent an organization from meeting its strategic objectives — financial, operational, strategic, compliance, and emerging risks alike. Unlike siloed risk functions, ERM gives boards and executives a single, integrated view of exposure so capital, controls, and management attention can be allocated where they move the needle most.
A mature ERM programme rests on three foundations. First, a governance framework — typically ISO 31000 or COSO ERM — that defines roles, escalation paths, and the three lines of defence. Second, a clear risk appetite statement that translates board tolerance into quantitative limits business units can actually manage against. Third, a repeatable risk management lifecycle covering identification, assessment, treatment, monitoring, and reporting.
Operationally, ERM depends on disciplined risk assessment — inherent vs residual scoring, control effectiveness testing, and scenario analysis — to keep the risk register honest. It also connects to sibling disciplines: business continuity management covers how the organisation survives disruption, information security management handles cyber and data risks, and governance, risk, and compliance (GRC) integrates the tooling and reporting that sits above all three.
Use this hub to explore frameworks, practitioner templates, certification guides (CRISC, FRM, PRM), and software comparisons. Whether you’re stood up a new ERM function or maturing an existing one, the resources below cover the methods, metrics, and reporting practices used by risk teams across financial services, healthcare, technology, and the public sector.
CRAMM (CCTA Risk Analysis and Management Method) is a version of a well-established risk … Read more
Conveyor belt systems are widely used in various industries, including mining, to transport materials … Read more
In 2024, the US Bureau of Labor Statistics counted 1,032 construction fatalities, the highest … Read more
On September 24, 2025, the FDA released the final Computer Software Assurance for Production … Read more
In December 2024, women in the US earned just 80.9 cents for every dollar … Read more
Between 2015 and 2022, OSHA’s Severe Injury Reports captured 77 robot-related incidents in U.S. … Read more
In April 2024, researchers published a peer-reviewed analysis of OSHA Severe Injury Reports and … Read more
In January 2025, the US Department of Health and Human Services Office for Civil … Read more
A Business Continuity Risk Assessment (XLS) is a structured spreadsheet-based framework that helps organizations … Read more
In February 2025, the Securities and Exchange Commission settled proceedings against Centaurus Financial for … Read more
At 04:09 UTC on 19 July 2024, a single 40-kilobyte content update from CrowdStrike … Read more
Figure 1. Bank compliance risk assessment template — the four FFIEC inherent risk categories … Read more