IRM Enterprise Risk Management Framework (Institute of Risk Management)
IRM Reporting + KRIs + Horizon Scanning

IRM Enterprise Risk Management Framework (Institute of Risk Management) IRM-Reporting-KRIs-Performance-HorizonScanning-Dashboard-Heatmap-RiskRegister-EmergingRisk: IRM Risk Reporting + Key Risk Indicators (KRIs) + Performance Measurement + Horizon Scanning + Dashboard + Heat Map + Risk Register + Emerging Risk Identification

Risk Reporting + KRIs + Performance + Horizon Scanning translate the risk management process into actionable management information. (1) Risk Register: central repository of all identified risks with standardised attributes - Risk ID + Description + Category + Sub-Category + Owner + Date Identified + Last Reviewed + Inherent Probability + Inherent Impact + Inherent Score + Controls + Control Effectiveness + Residual Probability + Residual Impact + Residual Score + Target/Tolerable Score + Treatment + Action Plan + Action Owner + Deadline + Status + KRIs + comments. Typically maintained in GRC software (e.g. ServiceNow GRC + LogicGate + Archer + Riskonnect + Resolver + LogicManager + Galvanize) or spreadsheets. (2) Key Risk Indicators (KRIs): leading and lagging metrics that indicate the level of risk - leading KRIs (e.g. employee turnover rate predicting key person risk) + lagging KRIs (e.g. number of cyber incidents detected) + threshold-based alerts (green/amber/red) + dashboard visualisation. (3) Key Performance Indicators (KPIs) + Key Control Indicators (KCIs): operational performance metrics + control effectiveness metrics + linked to KRIs. (4) Risk Heat Map / Risk Matrix: visualisation of risks plotted on probability x impact grid with colour coding + size variation for velocity/persistence + before/after treatment view. (5) Risk Dashboard: executive + Board-level dashboards showing top risks + appetite vs actual + KRIs status + heat map + emerging risks + recent incidents + action plan status. (6) Horizon Scanning + Emerging Risk: systematic identification of emerging risks 2-10 year horizon - sources include WEF Global Risks Report + Aon Global Risk Survey + Marsh Future Risks Report + AGCS Global Risk Barometer + government strategic threat assessments + sector-specific scans + PESTLE + STEEPLE analysis + scenario planning + black swan analysis + grey rhino analysis. (7) Board Reporting: typical quarterly + annual Board + Audit Committee + Risk Committee risk reporting + including risk profile changes + KRI movements + incidents + control failures + emerging risks + appetite breaches + assurance outcomes. (8) External Reporting: annual report risk section + going concern + viability statement (UK Corporate Governance Code Section 4) + ORSA Solvency II + Pillar 3 Basel + TCFD climate risk + ESG/sustainability reporting + GRI Standards + SASB + ISSB + ESRS + CSDDD. Coordinates with COSO ERM 2017 + ISO 31000 + UK Corporate Governance Code + FRC Guidance + ORSA + TCFD/TNFD + IFRS S1/S2 + ESRS S1-S4 + Solvency II/III. IRM Reporting + KRIs + Horizon Scanning applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.