Risk Assessment Matrix Template (Excel), Color-Coded Scoring
In 2012, JPMorgan Chase turned a $2 billion trading loss in its London Chief … Read more
Enterprise risk management (ERM) is the discipline of identifying, assessing, and treating the full portfolio of risks that could prevent an organization from meeting its strategic objectives — financial, operational, strategic, compliance, and emerging risks alike. Unlike siloed risk functions, ERM gives boards and executives a single, integrated view of exposure so capital, controls, and management attention can be allocated where they move the needle most.
A mature ERM programme rests on three foundations. First, a governance framework — typically ISO 31000 or COSO ERM — that defines roles, escalation paths, and the three lines of defence. Second, a clear risk appetite statement that translates board tolerance into quantitative limits business units can actually manage against. Third, a repeatable risk management lifecycle covering identification, assessment, treatment, monitoring, and reporting.
Operationally, ERM depends on disciplined risk assessment — inherent vs residual scoring, control effectiveness testing, and scenario analysis — to keep the risk register honest. It also connects to sibling disciplines: business continuity management covers how the organisation survives disruption, information security management handles cyber and data risks, and governance, risk, and compliance (GRC) integrates the tooling and reporting that sits above all three.
Use this hub to explore frameworks, practitioner templates, certification guides (CRISC, FRM, PRM), and software comparisons. Whether you’re stood up a new ERM function or maturing an existing one, the resources below cover the methods, metrics, and reporting practices used by risk teams across financial services, healthcare, technology, and the public sector.
In 2012, JPMorgan Chase turned a $2 billion trading loss in its London Chief … Read more
In 2024, JPMorgan Chase received roughly 493,000 applications for about 4,000 summer analyst and … Read more
On May 10, 2012, JPMorgan Chase announced an initial $2 billion trading loss on … Read more
On November 15, 2013, attackers broke into Target Corporation’s network using credentials stolen from … Read more
On March 10, 2023, Silicon Valley Bank failed after $42 billion in deposit withdrawals … Read more
On March 7, 2017, the Apache Software Foundation published CVE-2017-5638, a critical remote-code-execution flaw … Read more
On 14 August 2025, NYDFS announced that Healthplex, Inc., a New York licensed insurance … Read more
On May 1, 2025, Capital One posted 87 GRC Analyst openings and 142 Risk … Read more
On April 17, 2024, JPMorgan Chase posted 314 open entry-level risk analyst roles across … Read more
In April 2025, JPMorgan’s 2025 proxy statement disclosed total compensation for Ashley Bacon, the … Read more
The 5×5 Risk Matrix vs 4×4 Risk Matrix debate comes down to one practical … Read more
Scope 1 vs Scope 2 vs Scope 3 Emissions is the GHG Protocol framework … Read more