Home/Insights/Enterprise Risk Assessment
Enterprise Risk

Enterprise Risk Assessment

How a company-wide risk assessment is actually built — from risk identification through appetite, treatment and the key risk indicators that tell the board something has moved before it becomes a loss.

Typical duration
6–10 weeks
Standard
COSO ERM · ISO 31000
Governance
Board risk committee
Output
Register, appetite, KRI set
0Phases in the assessment cycle
0Risk categories in a standard taxonomy
0Treatment options for every risk

The assessment cycle

Risk assessment is a cycle, not a project. The output of monitoring feeds directly back into identification in the next round.

01

Establish context

Agree the risk taxonomy, the scoring scales for likelihood and impact, and which entities and processes are in scope.

Risk taxonomy & scales
02

Identify risks

Workshops with process owners, loss data review, and scanning of regulatory and external developments.

Draft risk register
03

Assess inherent risk

Score likelihood and impact before controls. Document the rationale so the score can be challenged and reproduced.

Scored inherent risks
04

Evaluate controls

Map controls to risks, then test both design and operating effectiveness. An untested control cannot reduce a score.

Control library & test results
05

Determine residual & treat

Compare residual risk to appetite. Where it exceeds appetite, choose to treat, transfer, terminate or tolerate with documented rationale.

Treatment plans with owners
06

Monitor via KRIs

Set thresholds on indicators that move before losses do, and escalate automatically when a threshold is breached.

KRI dashboard

Plotting inherent against residual

The value of the matrix is the movement between inherent and residual. A risk that does not move once controls are applied is telling you the controls do not work.

5
10
15
20
25
4
8
12
16
20
3
6
9
12
15
2
4
6
8
10
1
2
3
4
5
Low impactHigh impact

Vertical axis: likelihood. Horizontal axis: impact.

The eight risk categories

A standard taxonomy for a regulated Egyptian institution.

Credit risk

Counterparty default and concentration exposure.

Market risk

Rate, currency and price movement exposure.

Liquidity risk

Settlement buffers and funding concentration.

Operational risk

Process failure, human error, reconciliation breaks.

Compliance & regulatory

Breach of law, circular or licence condition.

Financial crime

AML, sanctions, fraud and bribery exposure.

Technology & cyber

Unpatched vulnerabilities, outage, data loss.

Reputational

Conduct failure and stakeholder trust erosion.

Need this assessed for your organisation?

Every engagement is led by a senior practitioner and closes with documented, regulator-ready evidence of what was built.

Talk to an Expert All Insights
PreviousKYC & Customer Onboarding NextCompany Due Diligence Readiness