On 17 April 2026 the OCC, the Federal Reserve and the FDIC replaced model risk guidance that had stood since 2011, rescinding four separate issuances in a single bulletin. Any integrated risk management program at a bank above $30 billion in assets now works from a rulebook rewritten for the first time in fifteen years.
One line in that guidance deserves more attention than it has received. Generative and agentic AI models are novel and rapidly evolving, the agencies wrote, and are therefore not within scope, which leaves the fastest-moving exposure on the books without a supervisory home.
| Integrated Risk Management Program: Key Takeaways |
| An integrated risk management program puts strategic, operational, financial, technology and compliance risk on one taxonomy, one register and one reporting cycle, so the board ranks a single list instead of reconciling five departmental ones. |
| Gartner retired integrated risk management as a market category in 2020, saying there is no single buying center with a consolidated view of risk and a consolidated budget. Treat it as an operating model to build, never a product to purchase. |
| Only 32 percent of organizations describe their risk oversight as mature, and 47 percent run a systematic process with regular board reporting, according to the 2024 Global State of Risk Oversight. |
| Five of the ten near-term risks boards named for 2026 to 2028 are operational, led by cyber threats and third-party risk, which is precisely the territory a siloed program handles worst. |
| On 17 April 2026 the OCC, Federal Reserve and FDIC put generative and agentic AI outside the scope of their new model risk guidance, leaving that exposure to the integrated risk management program to own. |
| COSO ERM 2017 supplies the governance spine, ISO 31000:2018 the process, the IIA Three Lines Model the accountability, and NIST CSF 2.0 plus the AI RMF the technology layer. A serious program maps to all four. |
That gap is the argument for integration in a sentence. When a regulator declines a risk, it does not disappear, it simply lands on whichever function can see across the whole organization. An integrated risk management program is the function built to catch it.
What an Integrated Risk Management Program Actually Is
Strip away the vendor language and the definition is narrow. An integrated risk management program is the operating model that puts every material risk on one taxonomy, one register and one reporting cycle, so exposures are scored the same way regardless of which department found them.
The word doing the work in integrated risk management program is the first one. Plenty of firms run credit risk, cyber risk and compliance risk competently in parallel, yet still cannot say what their three largest exposures are, because nobody scores them on a comparable scale.
Integrated Risk Management Program Compared With ERM and GRC
The three labels overlap enough to cause real confusion in budget meetings, and integrated risk management program is the one most often misused. What separates them is scope and output rather than ambition, and knowing which a stakeholder means saves hours of circular argument.
| Label | What it names | Typical owner | What it produces |
| Integrated risk management program | The operating model that joins risk domains onto shared scoring and reporting | Chief risk officer, with accountable owners per domain | One ranked risk view, a shared taxonomy, and an assurance plan built from it |
| Enterprise risk management | The discipline of managing risk in support of strategy and objectives | Chief risk officer or finance | Risk register, appetite statement, board risk reporting |
| Governance, risk and compliance | The coordination of policy, control testing and regulatory obligation | Compliance, legal, internal audit | Control library, obligations register, audit and testing evidence |
| Integrated risk management software | Tooling that stores and workflows the above | Technology, procured by risk or compliance | Workflow, dashboards, evidence storage, no judgment |
Our position is that the distinction matters least at the top and most in procurement. A board wants one ranked list, so it hardly cares what the function is called, while a buyer who confuses the program with the platform ends up automating fragmentation. See our guide to GRC frameworks for where the compliance layer fits.
The Five Domains an Integrated Risk Management Program Joins
Most organizations already run all five of these domains. The integration work is not creating them, it is forcing them onto one scoring scale and one calendar so that a technology exposure and a credit exposure can sit on the same page without translation.

Figure 1. The integration is not a new department, it is a shared taxonomy, register and appetite.
Getting the taxonomy right is the unglamorous part that decides everything downstream. A well-built risk register with consistent register fields lets a cyber finding and a supplier finding be compared, and without that comparison the ranked list is just an opinion.
Why the Integrated Risk Management Program Stopped Being a Product Category
Here is the fact that reframes most of what is written about this topic. Gartner, the firm that popularized the term, retired integrated risk management as a market category in 2020, having concluded that buyers treat it as a strategy to pursue rather than a product class to shop for.
The stated reason is worth quoting on its merits. There is no single buying center for these solutions with a consolidated view of risk and a consolidated budget, which is exactly the organizational problem the program is meant to solve, showing up in the procurement data.
The category survives as a Gartner Peer Insights review market and in the earlier market guide for integrated risk management solutions. Buying from either without first fixing taxonomy and ownership produces a tidier version of the same fragmentation, at a considerably higher annual cost.
The survey evidence points the same way. Only 32 percent of organizations describe their risk oversight as mature and 47 percent run a systematic process with regular board reporting, per the 2024 Global State of Risk Oversight from AICPA & CIMA and the NC State ERM Initiative.

Figure 2. Two thirds sense risk rising, while a third call their oversight mature.
Read those two numbers together and the maturity problem is not awareness. Executives can see the risk curve steepening, yet the AICPA and NC State research still finds 17 percent reporting that leadership considers the cost of the program higher than its benefit.
What the 2026 Risk Register Demands of an Integrated Risk Management Program
Maturity is only half the story, because the shape of the risk list itself now argues for an integrated risk management program. Boards and C-suites named their near-term concerns for 2026 to 2028, and the composition of that list tells you where a fragmented program fails first.
| Rank | Near-term risk named for 2026 to 2028 | Category |
| 1 | Cyber threats | Operational |
| 2 | Third-party dependency and vendor risk | Operational |
| 3 | Adoption of emerging technologies and workforce upskilling | Strategic |
| 4 | Legacy IT infrastructure and performance gaps | Operational |
| 5 | Economic conditions including inflation | Macroeconomic |
| 6 | AI implementation risk | Operational |
| 7 | Talent acquisition and retention | Operational |
| 8 | Regulatory uncertainty and fragmentation | Strategic |
| 9 | Labor availability | Macroeconomic |
| 10 | Global market and trade policy change | Macroeconomic |

Figure 3. Half the list is operational, which is where departmental silos overlap most.
The 14th edition of the Protiviti and NC State top risks survey drew 1,540 board members and C-suite executives and was published on 11 December 2025. Cyber and third-party risk taking the top two slots is the clearest possible case for a shared register.
Optimism sits alongside that anxiety, which changes how the program should be sold internally. Roughly 70 percent of those executives expect meaningful revenue growth over two to three years, so a program framed only as loss prevention will lose the argument for funding.
Third-party exposure deserves particular attention because it crosses every domain at once. Pair a third-party risk management framework with a view of concentration risk across vendor relationships, or the register will show ten suppliers where one dependency actually exists.
Standards That Give an Integrated Risk Management Program Its Spine
Nothing here needs inventing, which is the good news for anyone staring at a blank integrated risk management program charter. Four published frameworks already cover governance, process, accountability and technology, and a defensible program maps its own documentation to each of them explicitly.
COSO and ISO Inside an Integrated Risk Management Program
The two anchors do different jobs inside an integrated risk management program and are not substitutes for one another. COSO Enterprise Risk Management, Integrating with Strategy and Performance supplies five components and twenty principles tying risk to strategy, while ISO 31000:2018 supplies principles, framework and a repeatable process.
Choosing between them is a false problem that consumes real months. Firms with a US listing and an audit committee usually anchor on COSO, others on ISO, and our comparison of ISO 31000 and COSO ERM sets out where each is stronger.
Accountability is the third leg and the one most often left implicit. The IIA Three Lines Model, updated in July 2020, replaced the older defensive framing with coordinated roles, and our walkthrough of the three lines covers how it reads in practice.
Where NIST Fits an Integrated Risk Management Program
Technology risk arrives with its own vocabulary, and the integration job is translation. NIST Cybersecurity Framework 2.0, published on 26 February 2024, added a Govern function whose explicit purpose is folding cyber risk into enterprise risk management rather than running it separately.
Artificial intelligence now needs the same treatment inside an integrated risk management program, and two documents carry it. The NIST AI Risk Management Framework of January 2023 gives four functions to work with, and ISO/IEC 42001:2023 turns AI governance into a certifiable management system.
| Framework | What it contributes | Where it lands in the program |
| COSO ERM 2017 | Governance, strategy alignment, five components and twenty principles | Charter, appetite statement, board reporting structure |
| ISO 31000:2018 | Principles, framework and a repeatable risk management process | Assessment methodology, scoring scale, review cadence |
| IIA Three Lines Model 2020 | Role clarity between management, oversight functions and internal audit | RACI for risk ownership and the assurance map |
| NIST CSF 2.0 Govern function | Language for folding cyber risk into enterprise decisions | Technology risk domain feeding the shared register |
| NIST AI RMF and ISO/IEC 42001 | Govern, map, measure and manage for AI systems, plus a certifiable AI management system | The AI risk domain the model risk guidance left out of scope |
| Basel Principles for Operational Resilience | Tolerance for disruption on critical operations, mapped interconnections | Operational risk domain in regulated firms |
Regulated firms carry a fifth layer on top of those four. The Basel Committee principles for operational resilience and the EU Digital Operational Resilience Act both push toward the same shared register, and the same is true of business resilience programs more broadly.
How to Build an Integrated Risk Management Program in Seven Steps
Sequence matters more than speed, because each step consumes the previous one. Programs that jump to tooling before taxonomy end up with expensive software that stores incomparable data, which is the most common failure we are called in to unpick.
| Step | What you do | What proves it is finished |
| 1. Mandate | Get a written charter naming the program owner, the committee it reports to, and the decisions it informs | Board-approved charter with a named executive owner and a standing agenda slot |
| 2. Taxonomy | Agree one risk taxonomy and one scoring scale across all five domains, including definitions of likelihood and impact | A single taxonomy document that credit, cyber and compliance have all signed |
| 3. Appetite | Convert strategy into stated appetite and tolerance per risk category, expressed in numbers | Appetite statement with quantified tolerances the board has approved |
| 4. Register | Consolidate departmental registers into one, rescoring every entry on the shared scale | One register with no orphan entries and no duplicate risks under different names |
| 5. Ownership | Assign a single accountable owner per material risk, with the three lines mapped around them | RACI and assurance map showing who manages, who oversees and who audits |
| 6. Reporting | Set one cadence and one board pack format drawing on indicators, not activity counts | Quarterly report with trend, appetite breaches and named owners |
| 7. Assurance | Direct audit and testing effort at the highest-ranked risks rather than at a rotation | Risk-based audit plan traceable to the top of the ranked register |
Step two is where most programs quietly lose. Two departments scoring likelihood on different scales cannot be merged later without rescoring every entry from scratch, so settle the scale before anybody populates a template or buys a risk assessment matrix.
Step three fails for a different reason, which is nerve rather than method. Appetite has to be a number somebody will defend, and our worked risk appetite statement examples and the distinction between appetite, tolerance and capacity give you the language for that conversation.
Self-assessment supplies the raw material for steps four and five of an integrated risk management program. A disciplined risk and control self-assessment produces owner-level data, and regulated firms can start from an RCSA template built for banks rather than a generic grid.
Governance and Metrics for an Integrated Risk Management Program
Reporting is where integration either proves itself or is exposed. A board pack that lists activity, such as workshops held or registers refreshed, tells nobody whether exposure moved, and it is the surest sign the program has not integrated anything.
| Metric | What it measures | Why it belongs in the board pack |
| Coverage of the taxonomy | Share of material risks scored on the shared scale rather than a local one | Direct measure of whether integration is real or aspirational |
| Appetite breach count and duration | Risks sitting outside stated tolerance, and how long they have been there | Turns the appetite statement from a document into a control |
| Top risk movement | Quarter-on-quarter change in the ranked top ten | Shows whether mitigation is shifting exposure or just consuming budget |
| Key risk indicator coverage | Share of top risks with a leading indicator and a defined trigger | Distinguishes forward-looking programs from retrospective ones |
| Single-owner ratio | Material risks with exactly one accountable owner named | Shared ownership is the quiet cause of unmanaged risk |
| Assurance alignment | Share of audit effort directed at top-quartile risks | Tests whether the register actually drives anything |
Indicators are the part practitioners most often get wrong by choosing what is easy to count. Our library of key risk indicator examples and a set of board-ready ERM dashboards show the difference between a metric that predicts and one that merely records.

Figure 4. US organizations sit mid-table on self-reported maturity, behind Europe.
The regional spread is a useful corrective for anyone benchmarking an integrated risk management program against peers. At 30 percent for US organizations, the bar for above-average maturity is low enough that clearing it should never be mistaken for a finished program.
Where Integrated Risk Management Programs Break Down
A pharmaceutical client of ours once presented two registers to the same audit committee in one meeting, one from quality and one from IT, with the same supplier scored high in the first and low in the second. Nobody had defined what high meant.
| Breakdown | Root cause | Correction |
| Two registers, two answers | No shared taxonomy or scoring scale across departments | Rescore every entry on one scale before merging anything |
| Software bought before the model | Tooling treated as the program rather than its plumbing | Fix taxonomy, ownership and cadence first, then shortlist platforms |
| Appetite written in adjectives | Nobody wanted to defend a number to the board | Force a quantified tolerance per category and let breaches correct it |
| Risks with three owners | Committee ownership used to avoid difficult conversations | One accountable name per material risk, recorded in the register |
| AI risk sitting nowhere | Model risk guidance excludes generative and agentic systems | Create an explicit AI risk domain mapped to the NIST AI RMF |
| Reporting that counts activity | Metrics chosen for availability rather than decision value | Report exposure movement, appetite breaches and indicator trends |
| Audit plan on a rotation | Assurance planned by cycle rather than by risk rank | Rebuild the audit plan from the top of the ranked register |
The pattern underneath all seven breakdowns is the same, and it is organizational rather than technical. Integration asks departments to give up their private scoring, and that negotiation is the actual project, whatever the implementation plan and its milestones happen to claim.
Certification and extra headcount rarely fix it either, though both get tried first. Firms sometimes hire against GRC certifications hoping that credentials will settle a taxonomy argument which only an executive decision can settle, and the register stays split either way.
Integrated Risk Management Program FAQs: Expert Answers to Critical Questions
What is an integrated risk management program in simple terms?
An integrated risk management program is a way of running risk so that every material exposure, whether cyber, financial, operational, strategic or compliance, is scored on the same scale and reported on the same cycle. The output is one ranked list a board can act on.
How does an integrated risk management program differ from ERM?
Enterprise risk management names the discipline, while an integrated risk management program names the operating model that makes it work across domains. In practice many firms use the terms interchangeably, and the useful test is whether cyber and credit risk appear on one comparable register.
Do I need software to run an integrated risk management program?
No, and buying it first usually makes matters worse rather than better. Software helps an integrated risk management program once taxonomy, ownership and cadence are settled, whereas a platform layered over inconsistent scoring simply produces fragmented data faster and at greater expense.
Which standards should an integrated risk management program follow?
Map an integrated risk management program to COSO ERM 2017 for governance, ISO 31000:2018 for process, the IIA Three Lines Model for accountability, and NIST CSF 2.0 with the AI RMF for technology. Regulated firms add their own supervisory rules on top of that base.
Who should own the integrated risk management program?
A chief risk officer or equivalent owns the integrated risk management program, with a named accountable executive for each material risk underneath them. Committee ownership sounds inclusive and reliably produces risks that nobody manages between meetings. The register should carry one name per risk, never the name of a forum.
How long does an integrated risk management program take to build?
Expect six to twelve months to reach a credible first ranked register in a mid-sized organization, with taxonomy and appetite consuming the first quarter. Programs that report faster progress have usually skipped the rescoring work and will pay for it later.
How do you measure whether an integrated risk management program is working?
Track taxonomy coverage, appetite breaches and their duration, movement in the ranked top ten, and the share of audit effort aimed at top-quartile risks. Activity counts such as workshops delivered measure effort rather than exposure, and boards see through them quickly.
The Next Wave for Integrated Risk Management Programs
Start with the gap the regulators just left open. With generative and agentic AI outside the scope of the April 2026 model risk guidance, the practical burden falls on the integrated risk management program to define an AI domain, and firms that wait for a rule will be building it during an examination.
Regulatory fragmentation is itself now a named risk, sitting eighth on the 2026 list. The World Economic Forum Global Risks Report 2026 puts geoeconomic confrontation at the top of its two-year outlook, which turns trade and sanctions exposure into a live input for geopolitical risk assessment.
Expect disclosure pressure to keep pulling risk data toward one place. The SEC cybersecurity disclosure rule already forces a materiality judgment within four business days, and that judgment is close to impossible without an integrated register that ranks cyber against everything else.
Build the AI risk domain before the mandate arrives rather than after. Our AI governance framework guide sets out the control set, and pairing it with ISO 31000 principles keeps AI scored on the same scale as everything else in the register.
Pressure-Test Your Integrated Risk Management Program
Ask your risk team for one ranked list of the organization’s ten largest exposures, scored on a single scale, by Friday. If what comes back is five departmental spreadsheets, the integration work has not happened yet, and that is the diagnosis we are usually hired to confirm.
We rebuild taxonomies, quantify appetite and rescore consolidated registers so that a board can rank the list rather than reconcile it. Look through our advisory services and get in touch naming the one risk domain you currently trust least, because that is where we will start.
Teams building alone should start with the risk management process, set governance against an enterprise risk management framework, and check the technology domain with our NIST CSF and ISO comparison before anyone opens a vendor demo or signs a pilot agreement.
Tooling comes last and only after the model holds. When that point arrives, compare ERM software platforms, the wider enterprise risk management software field, plus compliance management tools and internal audit platforms against the taxonomy you already sett

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.