Nature-Related Risk Assessment: TNFD Framework Guide
Key Takeaways The TNFD framework, published in September 2023, provides 14 disclosure recommendations across … Read more
Enterprise risk management (ERM) is the discipline of identifying, assessing, and treating the full portfolio of risks that could prevent an organization from meeting its strategic objectives — financial, operational, strategic, compliance, and emerging risks alike. Unlike siloed risk functions, ERM gives boards and executives a single, integrated view of exposure so capital, controls, and management attention can be allocated where they move the needle most.
A mature ERM programme rests on three foundations. First, a governance framework — typically ISO 31000 or COSO ERM — that defines roles, escalation paths, and the three lines of defence. Second, a clear risk appetite statement that translates board tolerance into quantitative limits business units can actually manage against. Third, a repeatable risk management lifecycle covering identification, assessment, treatment, monitoring, and reporting.
Operationally, ERM depends on disciplined risk assessment — inherent vs residual scoring, control effectiveness testing, and scenario analysis — to keep the risk register honest. It also connects to sibling disciplines: business continuity management covers how the organisation survives disruption, information security management handles cyber and data risks, and governance, risk, and compliance (GRC) integrates the tooling and reporting that sits above all three.
Use this hub to explore frameworks, practitioner templates, certification guides (CRISC, FRM, PRM), and software comparisons. Whether you’re stood up a new ERM function or maturing an existing one, the resources below cover the methods, metrics, and reporting practices used by risk teams across financial services, healthcare, technology, and the public sector.
Key Takeaways The TNFD framework, published in September 2023, provides 14 disclosure recommendations across … Read more
Key Takeaways Scope 3 financed emissions (GHG Protocol Category 15) represent over 99% of … Read more
Key Takeaways Key Takeaways Board members spend an average of 4.5 hours per month … Read more
Key Takeaways Key Takeaways The ISO 31000 certification from PECB validates your ability to … Read more
Key Takeaways A well-structured RCSA template transforms risk identification from a vague brainstorming exercise … Read more
Key Takeaways # Takeaway 1 An ERM dashboard translates the risk register, KRI data, … Read more
Key Takeaways # Takeaway 1 A risk appetite statement is the board-approved document that … Read more
Key Takeaways # Takeaway 1 A risk register is the central, living repository of … Read more
Key Takeaways # Takeaway 1 NIST CSF 2.0 is a voluntary, flexible cybersecurity framework … Read more
Key Takeaways ✓ Third-party breaches doubled from 15% to 30% of all incidents in … Read more
Key Takeaways ✓ A responsible AI framework is a structured governance system that translates … Read more
Key Takeaways If you only read one section, read this. What Is AI Bias … Read more