IRM Enterprise Risk Management Framework (Institute of Risk Management)
IRM Risk Management Process

IRM Enterprise Risk Management Framework (Institute of Risk Management) IRM-Process-Identification-Analysis-Evaluation-Treatment-Monitoring-Review-ISO31000-Aligned: IRM Risk Management Process - 5-Stage Cycle + Identification + Analysis (Inherent/Residual) + Evaluation + Treatment (4Ts Tolerate/Treat/Transfer/Terminate) + Monitoring + Review + Communication + Risk Register

The IRM Risk Management Process is a 5-stage continuous cycle aligned closely with ISO 31000:2018 + COSO ERM 2017. (1) Risk Identification: systematic identification of risks through workshops + interviews + SWOT/PESTLE analysis + scenario analysis + bow-tie analysis + cause-and-effect analysis + risk taxonomy review + horizon scanning + external benchmarking + emerging risk identification + categorised by source (internal/external/strategic/operational/financial/knowledge) + recorded in Risk Register with unique ID + description + owner + date identified. (2) Risk Analysis: assess each risk in terms of: (a) Probability/Likelihood (rare + unlikely + possible + likely + almost certain - typically 1-5 scale or quantitative 0-100% with sub-categories); (b) Impact/Consequence (insignificant + minor + moderate + major + severe across multiple dimensions: financial + reputational + operational + regulatory + safety + environmental + customer); (c) Inherent Risk score (probability x impact before controls); (d) Control effectiveness assessment (none + weak + moderate + strong + very strong); (e) Residual Risk score (inherent risk after controls); (f) Velocity (how quickly risk could materialise) + Persistence (how long impact lasts). (3) Risk Evaluation: compare residual risk against Risk Appetite + Risk Tolerance to determine acceptability + prioritise + escalate + treatment decisions + use of risk heat map / risk matrix / risk register. (4) Risk Treatment (Four Ts): (a) Tolerate (accept) - no action where residual risk within appetite + cost of treatment exceeds benefit; (b) Treat (mitigate) - implement preventive controls + detective controls + corrective controls + recovery controls; (c) Transfer (share) - insurance + outsourcing + contractual + financial instruments; (d) Terminate (avoid) - exit activity + cease product line + close site + divest. Plus enhancing/Exploit/Augment for upside risks. (5) Monitoring + Review: ongoing risk monitoring + Key Risk Indicators (KRIs) + Key Performance Indicators (KPIs) + KCIs Key Control Indicators + post-incident reviews + reviewing process for effectiveness + annual independent assurance + quarterly Board reporting + emerging risk scanning + back-testing predictions. (6) Risk Communication: stakeholder engagement throughout the cycle + risk register accessible to relevant parties + reporting to Board/Risk Committee/Audit Committee/Executive Team + external disclosure (annual report + sustainability report + ORSA Solvency II + Pillar 3 Basel). Coordinates with ISO 31000:2018 Process Steps + ISO 31010 Risk Assessment Techniques + COSO ERM 2017 + Bow-Tie XP + risk software (RiskonnEct + LogicGate + ServiceNow + Riskwatch + Archer + Resolver) + FRC reporting guidance. IRM Risk Management Process applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.