Loading markets…

Risk Toolkit Frameworks & Governance

🏛️

Risk Toolkit · Governance

Frameworks & Governance

The scaffolding above the individual risk tools: enterprise risk management, a board-set risk appetite cascaded into limits, and the frameworks that keep it all accountable.

01Enterprise risk management02Risk appetite03COSO & ISO 3100004Model risk

01Overview

Enterprise risk management ties individual risk disciplines together under a governance structure, a stated risk appetite and regulatory frameworks such as Basel. This hub covers the frameworks and model-risk governance that sit above day-to-day risk management.

How it works

Enterprise risk management (ERM) binds the separate disciplines — market, credit, liquidity and operational risk — into one governed system rather than a set of silos. At its centre is a risk appetite: a board-approved statement of how much and what kinds of risk the firm will accept, cascaded into limits that desks trade within. ISO 31000 frames risk itself as “the effect of uncertainty on objectives,” making risk management a decision-support discipline embedded in strategy, not a compliance afterthought. Governance also covers model risk — the risk that the very models used to measure risk are wrong or misused.

The risk-appetite cascade — from board statement to desk limit

Board risk appetite Risk limits Desk mandates & controls more granular, more specific, closer to the trade → ERM BINDS Market Credit Liquidity Operational — one governed system
Schematic. A single board-level appetite is translated into ever-more-specific limits and mandates the closer you get to the trade — while ERM keeps the separate risk disciplines coherent and accountable.

In practice

Two reference frameworks dominate. COSO’s ERM — Integrating with Strategy and Performance (2017) embeds risk in strategy-setting and performance rather than treating it as a separate control layer. ISO 31000:2018 provides principles, a framework and a process usable by any organisation regardless of size or sector. Around these sit sector regulation (Basel for banks), formal risk-appetite statements, model-risk governance and the three-lines-of-defence operating model — the scaffolding that keeps the individual risk tools in this Toolkit coherent and accountable.

02Key methods

Risk appetite

A board-approved statement of how much and what kinds of risk the firm will accept, cascaded into desk limits.

COSO ERM (2017)

Integrates risk with strategy-setting and performance, not as a separate control layer.

ISO 31000:2018

Principles, framework and process usable by any organisation — risk as the effect of uncertainty on objectives.

Model-risk governance

Controls over the risk that the models used to measure risk are themselves wrong or misused.

§
The two reference frameworks

COSO’s ERM — Integrating with Strategy and Performance (2017) embeds risk in strategy and performance, while ISO 31000:2018 gives principles, a framework and a process for any organisation. Around them sit sector regulation (Basel), risk-appetite statements and the three-lines operating model.

Sources & credits

Standard-setting and primary sources. Links open the original publication.

  1. Enterprise Risk Management — Integrating with Strategy and Performance Standard-setter: The leading ERM framework · coso.org
  2. ISO 31000:2018 — Risk management — Guidelines Standard-setter: The international risk-management standard · iso.org
  3. The new ISO 31000 keeps risk management simple Authoritative: Official overview of ISO 31000 · iso.org
Editorial Sourced from standard-setters & primary texts Reviewed: 8 Jul 2026

Explore the disciplines

These frameworks bind the market, credit, liquidity and operational tools across the Risk Toolkit.