The IRM Risk Management Process is a 5-stage continuous cycle aligned closely with ISO 31000:2018 + COSO ERM 2017. (1) Risk Identification: systematic identification of risks through workshops + interviews + SWOT/PESTLE analysis + scenario analysis + bow-tie analysis + cause-and-effect analysis + risk taxonomy review + horizon scanning + external benchmarking + emerging risk identification + categorised by source (internal/external/strategic/operational/financial/knowledge) + recorded in Risk Register with unique ID + description + owner + date identified. (2) Risk Analysis: assess each risk in terms of: (a) Probability/Likelihood (rare + unlikely + possible + likely + almost certain - typically 1-5 scale or quantitative 0-100% with sub-categories); (b) Impact/Consequence (insignificant + minor + moderate + major + severe across multiple dimensions: financial + reputational + operational + regulatory + safety + environmental + customer); (c) Inherent Risk score (probability x impact before controls); (d) Control effectiveness assessment (none + weak + moderate + strong + very strong); (e) Residual Risk score (inherent risk after controls); (f) Velocity (how quickly risk could materialise) + Persistence (how long impact lasts). (3) Risk Evaluation: compare residual risk against Risk Appetite + Risk Tolerance to determine acceptability + prioritise + escalate + treatment decisions + use of risk heat map / risk matrix / risk register. (4) Risk Treatment (Four Ts): (a) Tolerate (accept) - no action where residual risk within appetite + cost of treatment exceeds benefit; (b) Treat (mitigate) - implement preventive controls + detective controls + corrective controls + recovery controls; (c) Transfer (share) - insurance + outsourcing + contractual + financial instruments; (d) Terminate (avoid) - exit activity + cease product line + close site + divest. Plus enhancing/Exploit/Augment for upside risks. (5) Monitoring + Review: ongoing risk monitoring + Key Risk Indicators (KRIs) + Key Performance Indicators (KPIs) + KCIs Key Control Indicators + post-incident reviews + reviewing process for effectiveness + annual independent assurance + quarterly Board reporting + emerging risk scanning + back-testing predictions. (6) Risk Communication: stakeholder engagement throughout the cycle + risk register accessible to relevant parties + reporting to Board/Risk Committee/Audit Committee/Executive Team + external disclosure (annual report + sustainability report + ORSA Solvency II + Pillar 3 Basel). Coordinates with ISO 31000:2018 Process Steps + ISO 31010 Risk Assessment Techniques + COSO ERM 2017 + Bow-Tie XP + risk software (RiskonnEct + LogicGate + ServiceNow + Riskwatch + Archer + Resolver) + FRC reporting guidance. IRM Risk Management Process applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.