02 — Capability · BC-130
Enterprise Risk
Know what could stop the enterprise from meeting its objectives, decide how much of that uncertainty it is willing to carry, and make sure the biggest exposures have an owner, a response and a number that leadership sees.
- Enterprise Risk Management
- ERM
- Risk Management Framework
- Integrated Risk
In scope
- The risk framework, taxonomy and appetite the board signs off on
- Identification and assessment of strategic, operational, financial and reputational risk
- Risk responses, the controls that reduce exposure, and insurance for what remains
- Risk monitoring, key risk indicators and reporting to leadership and the board
Out of scope
- Testing whether controls actually work (see BC-160)
- Cyber threat and vulnerability management (see BC-760)
- Continuity and crisis response when a risk materializes (see BC-830)
Realized by · 1
- ServiceNow · Governance, Risk and Compliancepartial via BC-130.30
Used in · 0
- Not yet placed on a value stream.
Build it · 0
- Nothing in the library points here yet.
Decomposes into · 5
- BC-130.10Risk Framework & AppetiteDefine what the enterprise means by risk, how it is categorized and scored, and how much of each kind the board is prepared to accept, so every assessment uses the same yardstick.
- BC-130.20Risk Identification & AssessmentFind the risks that matter before they find the enterprise, and rate their likelihood and impact consistently enough that the top of the list is actually the top.
- BC-130.30Risk Response & ControlsDecide for each significant risk whether to avoid, reduce, transfer or accept it, and design the controls that make the chosen response real.
- BC-130.40Risk Monitoring & ReportingWatch the indicators that show a risk is moving, and tell leadership and the board what has changed in a form they can act on.
- BC-130.50Insurance & Risk TransferTransfer the risks the enterprise should not carry alone through an insurance program sized to its exposures, and recover what it is owed when a loss occurs.