Enterprise Risk Management

ERM as an operating model, not a binder

COSO ERM 2017, ISO 31000, risk appetite, KRIs, and the three lines model — applied, not just cited.

🧭

Governance & Appetite

Risk appetite statements, decision rights, and board reporting that change real decisions.

📊

KRIs & Portfolio View

Leading indicators and a real aggregate view — not a quarterly refresh of a static register.

🔁

Three Lines Model

Making the revised IIA model work in a hybrid, matrixed organization.

🧭

Defining Impactful Risk Appetite Statements: Altering Decision-Making in ERM

Risk appetite statements (RAS) are strategic declarations that define an organization's risk tolerance, setting boundaries for acceptable risk levels and guiding decision-making pr…

🧭

ISO 31000 vs. COSO ERM: What the Differences Mean for Risk Owners

Enterprise risk management frameworks help organizations mitigate and manage various risks effectively. Two popular models are ISO 31000 and COSO ERM. Understanding their differenc…

🧭

COSO ERM 2017 in practice: turning the five components into an operating model

The 2017 update to COSO's Enterprise Risk Management framework — Enterprise Risk Management — Integrating with Strategy and Performance — moved the conversation past control checkl…