IRM Enterprise Risk Management Framework (Institute of Risk Management)
The Institute of Risk Management (IRM) provides professional risk management standards and qualifications. The IRM Enterprise Risk Management framework guides organisations in developing and implementing ERM. Key publications: IRM Risk Management Standard (2002, with ISO 31000 alignment), IRM Horizon Scanning guidance, IRM Cyber Risk Resources, and IRM Risk Culture guidance. IRM is the world's leading professional body for risk management, with members in 143 countries. IRM qualifications (International Certificate/Diploma/Advanced Diploma in Risk Management) are recognised globally by employers and regulators.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
Architecture
| Code | Title |
|---|---|
| IRM.1 | Risk Architecture |
Assurance
| Code | Title |
|---|---|
| IRM.18 | Assurance Mapping |
Capability
| Code | Title |
|---|---|
| IRM.19 | Training and Competence |
Controls
| Code | Title |
|---|---|
| IRM.10 | Control Effectiveness |
Culture
| Code | Title |
|---|---|
| IRM.5 | Risk Culture |
Financial Risk
| Code | Title |
|---|---|
| IRM-FR-1 | Market Risk |
| IRM-FR-2 | Credit and Liquidity Risk |
| IRM-FR-3 | Financial Controls |
Horizon Scanning
| Code | Title |
|---|---|
| IRM.14 | Emerging Risk |
Improvement
| Code | Title |
|---|---|
| IRM.20 | Continual Improvement |
Integration
| Code | Title |
|---|---|
| IRM.21 | Integration with Strategy and Decisions |
Knowledge Management Risk
| Code | Title |
|---|---|
| IRM-KR-1 | Knowledge Resources |
| IRM-KR-2 | Information and Data Risk |
Monitoring
| Code | Title |
|---|---|
| IRM.12 | Key Risk Indicators |
Operational Risk
| Code | Title |
|---|---|
| IRM-OR-1 | Process and Systems Risk |
| IRM-OR-2 | People and HR Risk |
| IRM-OR-3 | Supply Chain and Technology Risk |
Performance
| Code | Title |
|---|---|
| IRM.13 | Performance Measurement |
Process
| Code | Title |
|---|---|
| IRM.15 | Project and Programme Risk |
| IRM.16 | Third Party and Supply Chain Risk |
| IRM.6 | Risk Identification |
| IRM.7 | Risk Analysis |
| IRM.8 | Risk Evaluation |
| IRM.9 | Risk Treatment |
Protocols
| Code | Title |
|---|---|
| IRM.3 | Risk Protocols |
Reporting
| Code | Title |
|---|---|
| IRM.11 | Risk Reporting |
Resilience
| Code | Title |
|---|---|
| IRM.17 | Crisis Management Linkage |
Risk Management Process
| Code | Title |
|---|---|
| IRM-RP-1 | Risk Identification |
| IRM-RP-2 | Risk Analysis and Evaluation |
| IRM-RP-3 | Risk Treatment and Reporting |
| IRM-RP-4 | Monitoring and Review |
Strategic Risk
| Code | Title |
|---|---|
| IRM-SR-1 | Strategic Risk Assessment |
| IRM-SR-2 | Reputation Risk |
| IRM-SR-3 | Environmental and Regulatory Change |
Strategy
| Code | Title |
|---|---|
| IRM.2 | Risk Strategy |
| IRM.4 | Risk Appetite Statement |
Your Compliance Coverage
If you comply with IRM Enterprise Risk Management Framework (Institute of Risk Management), you already cover:
Critical Infrastructure Risk Management Program (CIRMP) Rules 2023
25%
9 controls mapped
Compare →Notifiable Data Breaches Scheme (Australia)
25%
9 controls mapped
Compare →EU Digital Markets Act
25%
9 controls mapped
Compare →+ 473 more: FTC Health Breach Notification Rule (25%), UK Product Security and Telecommunications Infrastructure Act (PSTI) (25%)
See all 476 mapped frameworks ↓Maps to 476 other frameworks
Frequently Asked Questions
What is IRM Enterprise Risk Management Framework (Institute of Risk Management)?
IRM Enterprise Risk Management Framework (Institute of Risk Management) is a compliance framework from International (IRM) with 20 domains and 36 controls. The Institute of Risk Management (IRM) provides professional risk management standards and qualifications. The IRM Enterprise Risk Management framework guides organisations in developing and implementing ERM. Key publications: IRM Risk Management Standard (2002, with ISO 31000 alignment), IRM Horizon Scanning guidance, IRM Cyber Risk Resources, and IRM Risk Culture guidance. IRM is the world's leading professional body for risk management, with members in 143 countries. IRM qualifications (International Certificate/Diploma/Advanced Diploma in Risk Management) are recognised globally by employers and regulators. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does IRM Enterprise Risk Management Framework (Institute of Risk Management) have?
IRM Enterprise Risk Management Framework (Institute of Risk Management) has 36 controls organised across 20 domains. The largest domains are Process (6 controls), Risk Management Process (4 controls), Financial Risk (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does IRM Enterprise Risk Management Framework (Institute of Risk Management) map to?
IRM Enterprise Risk Management Framework (Institute of Risk Management) maps to 476 other compliance frameworks. The top mapping partners are Critical Infrastructure Risk Management Program (CIRMP) Rules 2023 (25% coverage), Notifiable Data Breaches Scheme (Australia) (25% coverage), EU Digital Markets Act (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with IRM Enterprise Risk Management Framework (Institute of Risk Management) compliance?
Start your IRM Enterprise Risk Management Framework (Institute of Risk Management) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IRM Enterprise Risk Management Framework (Institute of Risk Management) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 36 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 706 frameworks.
Get Started Free →Free forever — no credit card required