IRM Enterprise Risk Management Framework (Institute of Risk Management)
IRM Risk Architecture + Strategy + Protocols + Culture

IRM Enterprise Risk Management Framework (Institute of Risk Management) IRM-Architecture-Strategy-Protocols-Appetite-Culture-Board-Audit-Committee-CRO-Three-Lines: IRM RASP - Risk Architecture + Strategy + Protocols + Risk Appetite Statement + Risk Culture + Board + Audit Committee + Chief Risk Officer + Three Lines of Defence + Tone at the Top

The IRM Risk Architecture + Strategy + Protocols (RASP) framework defines the governance + structural + behavioural enabling elements of effective enterprise risk management. (1) Risk Architecture: the formal structure of accountabilities + responsibilities + reporting lines + committees + risk owners + including Board level (Risk Committee or equivalent + Audit Committee), Executive level (Chief Executive + Chief Risk Officer + Risk Steering Group), Operational level (risk owners + business unit risk officers), Third Line (Internal Audit) - aligned with Three Lines of Defence model (1st Line: Operational Management owning risk + 2nd Line: Risk Management and Compliance function setting policy + 3rd Line: Internal Audit providing assurance) - updated to Three Lines Model per IIA 2020. (2) Risk Strategy: written enterprise risk strategy linked to business strategy + setting out objectives + scope + ambition + key principles + maturity targets + risk culture aspirations + reviewed annually by Board. (3) Risk Protocols: detailed operational procedures + standards + templates + guidance covering Risk Register format + Risk Assessment Methodology + Risk Scoring + Risk Treatment Approach + Risk Reporting + KRIs + RACI matrix + Issue Escalation Procedure + Project Risk + Third Party Risk + Operational Resilience. (4) Risk Appetite Statement: board-approved statement defining the amount of risk the organisation is willing to accept + take + or tolerate in pursuit of its strategic objectives - typically expressed across risk categories with tolerance ranges + cascaded to business units + reviewed annually + linked to capacity (maximum risk organisation can absorb without insolvency or critical impairment) + tolerance (acceptable variation around appetite) - per FRC/Walker/APRA guidance. (5) Risk Culture: the values + beliefs + knowledge + attitudes + understanding about risk shared by a group of people with a common purpose + including Tone at the Top + leadership behaviour modelling + middle management cascade + employee engagement + incentive structures + whistleblower mechanisms + cultural surveys (e.g. KPMG Risk Culture Survey + EY Risk Culture Maturity Model + IRM Risk Culture Aspects Model 2012 - PEAT Personal/Employee/Application/Top). Three Lines of Defence operational integration: clear delineation of risk ownership vs risk management vs assurance + avoidance of risk function being both player and umpire. Board oversight + Audit Committee scrutiny + Risk Committee deep dives + reporting cadence. Coordinates with FRC Guidance on Risk Management + Internal Control + Related Financial and Business Reporting (2014) + UK Corporate Governance Code + Walker Review + Turnbull Guidance + APRA CPS 230 Operational Risk + Basel Committee Principles for Operational Risk + COSO ERM 2017 + IIA Three Lines Model 2020 + Edelman Trust Barometer + Hofstede cultural dimensions. IRM RASP + Architecture + Strategy + Protocols + Appetite + Culture applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.