Institute of Risk Management (IRM) Enterprise Risk Management (ERM) Framework principally embodied in A Risk Management Standard published 2002 + co-authored by AIRMIC (Association of Insurance and Risk Managers in Industry and Commerce) + ALARM (UK Public Risk Management Association, now Alarm) + IRM (Institute of Risk Management). The Standard is freely available + best-practice + non-prescriptive + non-certifiable + intended for self-measurement. IRM was founded 1986 + is the UK independent professional body for risk management practitioners + headquartered London + awards: Certified Member of the IRM (CMIRM) qualification + International Diploma in Enterprise Risk Management + International Certificate in Enterprise Risk Management + Specialist certificates (Operational Risk + Risk in Financial Services + Digital Risk Management) + CPD continuing professional development + Special Interest Groups (SIGs) including Cyber SIG + Operational SIG + Risk Leadership SIG + ERM SIG + sector groups (Energy + Health + Public Sector + Charities). Key conceptual contributions: (1) Risk defined as the combination of the probability of an event and its consequences (ISO/IEC Guide 73 - vocabulary terms used throughout standard); (2) Risk encompasses BOTH UPSIDE (opportunities for benefit) AND DOWNSIDE (threats to success) - more comprehensive than safety-only or hazards-only models; (3) Four-quadrant risk categorisation: Strategic + Operational + Financial + Knowledge - influence from FOIL (Financial/Operational/Internal/External) typology; (4) Risk Management Process: 4 stages of Identification + Analysis + Evaluation + Treatment + supplemented by Monitoring + Review + Communication; (5) Risk Architecture + Strategy + Protocols (RASP) governance framework; (6) Risk Appetite Statement + Risk Culture as enabling elements. The 2002 Standard predates ISO 31000:2009 + 2018 + heavily influenced ISO 31000 framework which adopts similar process structure. IRM also publishes additional guidance: From the Cube to the Rainbow Double Helix (2010) + Risk Appetite and Tolerance (2011) + Risk Culture (2012) + Risk in the Boardroom (2014) + ESG Risk Management (2020) + Crisis and Resilience (2021) + AI/Machine Learning Risk (2023) + Climate Risk + Cyber Risk + numerous risk perspective papers. Public + freely available via theirm.org (some content member-gated). Coordinates with: ISO 31000:2018 Risk Management Guidelines + ISO Guide 73 Risk Management Vocabulary + COSO ERM Integrated Framework 2017 (Enterprise Risk Management - Integrating with Strategy and Performance) + COSO Internal Control - Integrated Framework 2013 + UK Corporate Governance Code 2018 + 2024 + UK Stewardship Code + FRC Financial Reporting Council Guidance on Risk Management + Internal Control + Related Financial and Business Reporting (2014) + Walker Review (2009) + Turnbull Guidance (1999/2005) + APRA CPS 230 Operational Risk Management + CPS 234 Information Security + Basel III/IV operational + credit + market + liquidity risk + Solvency II ORSA Own Risk and Solvency Assessment + OECD Principles of Corporate Governance + UN PRI Principles for Responsible Investment + UNGC + GRI Standards + TCFD Climate + ESG frameworks + GRC Governance Risk Compliance frameworks. IRM ERM Scope + ARM Standard 2002 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.