Risk Toolkit βΊ Frameworks & Governance
Risk Toolkit Β· Governance
Frameworks & Governance
The scaffolding above the individual risk tools: enterprise risk management, a board-set risk appetite cascaded into limits, and the frameworks that keep it all accountable.
01Overview
Enterprise risk management ties individual risk disciplines together under a governance structure, a stated risk appetite and regulatory frameworks such as Basel. This hub covers the frameworks and model-risk governance that sit above day-to-day risk management.
How it works
Enterprise risk management (ERM) binds the separate disciplines β market, credit, liquidity and operational risk β into one governed system rather than a set of silos. At its centre is a risk appetite: a board-approved statement of how much and what kinds of risk the firm will accept, cascaded into limits that desks trade within. ISO 31000 frames risk itself as βthe effect of uncertainty on objectives,β making risk management a decision-support discipline embedded in strategy, not a compliance afterthought. Governance also covers model risk β the risk that the very models used to measure risk are wrong or misused.
The risk-appetite cascade β from board statement to desk limit
In practice
Two reference frameworks dominate. COSOβs ERM β Integrating with Strategy and Performance (2017) embeds risk in strategy-setting and performance rather than treating it as a separate control layer. ISO 31000:2018 provides principles, a framework and a process usable by any organisation regardless of size or sector. Around these sit sector regulation (Basel for banks), formal risk-appetite statements, model-risk governance and the three-lines-of-defence operating model β the scaffolding that keeps the individual risk tools in this Toolkit coherent and accountable.
02Key methods
A board-approved statement of how much and what kinds of risk the firm will accept, cascaded into desk limits.
Integrates risk with strategy-setting and performance, not as a separate control layer.
Principles, framework and process usable by any organisation β risk as the effect of uncertainty on objectives.
Controls over the risk that the models used to measure risk are themselves wrong or misused.
COSOβs ERM β Integrating with Strategy and Performance (2017) embeds risk in strategy and performance, while ISO 31000:2018 gives principles, a framework and a process for any organisation. Around them sit sector regulation (Basel), risk-appetite statements and the three-lines operating model.
Sources & credits
Standard-setting and primary sources. Links open the original publication.
- Enterprise Risk Management β Integrating with Strategy and Performance Standard-setter: The leading ERM framework Β· coso.org
- ISO 31000:2018 β Risk management β Guidelines Standard-setter: The international risk-management standard Β· iso.org
- The new ISO 31000 keeps risk management simple Authoritative: Official overview of ISO 31000 Β· iso.org
Explore the disciplines
These frameworks bind the market, credit, liquidity and operational tools across the Risk Toolkit.
