The enterprise risk management process is a continuous cycle of six steps: identify the risks to your objectives, analyse and prioritise them, plan how to treat them, implement those treatments, review and track progress, and improve the whole system each cycle. It follows the risk management process in ISO 31000:2018 and the Performance and Review components of the COSO ERM framework, and it is how boards and executives turn risk management from a register into better decisions.
This guide from Security Solution Consultants (SSC) explains each step of the ERM process in practical terms: what happens, who is involved, which techniques work, and what you should have at the end. Select a step to jump straight to it.

Step 6 feeds back into step 1: the ERM process is a continuous cycle, not a one-off project.
Enterprise risk management is the coordinated way an organisation manages every material risk to its objectives: strategic, operational, financial, compliance, cyber, people, third-party and reputational. The framework sets the governance, policy, roles and appetite. The process is the set of activities that runs inside that framework, cycle after cycle.
ISO 31000:2018 describes the process in clause 6 as communication and consultation; scope, context and criteria; risk assessment (identification, analysis and evaluation); risk treatment; monitoring and review; and recording and reporting. COSO’s 2017 framework, Enterprise Risk Management: Integrating with Strategy and Performance, covers the same ground in five components and 20 principles. Our six steps map to both:
| SSC ERM step | ISO 31000:2018 | COSO ERM 2017 |
|---|---|---|
| 1. Risk identification | 6.4.2 Risk identification | Performance: identifies risk (principle 10) |
| 2. Risk analysis | 6.4.3 Risk analysis and 6.4.4 Risk evaluation | Performance: assesses severity and prioritises risks (principles 11 and 12) |
| 3. Risk mitigation planning | 6.5 Risk treatment: selecting options and preparing plans | Performance: implements risk responses (principle 13) |
| 4. Risk management implementation | 6.5.3 Implementing treatment plans, and 5.5 Implementation of the framework | Performance (principles 13 and 14) and Governance and Culture |
| 5. Review and tracking | 6.6 Monitoring and review, and 6.7 Recording and reporting | Review and Revision (principles 15 and 16), and Information, Communication and Reporting (principles 18 to 20) |
| 6. Continuous improvement | 5.7 Improvement, and the principle of continual improvement | Review and Revision: pursues improvement in ERM (principle 17) |
Communication and consultation is not a separate step: it runs through all six. Risk owners, subject matter experts and decision makers should be involved at every stage, otherwise the register describes the risk team’s view rather than the organisation’s.
The ERM process only produces consistent results when everyone uses the same rules. Before the first workshop, agree:

Risk identification finds, recognises and describes the risks that could help or stop you achieving your objectives. The aim is a complete picture, not a long list: twenty well-described enterprise risks are more useful than two hundred vague ones.
A useful risk statement names the cause, the event and the consequence. For example: “Because payroll depends on a single software vendor (cause), a prolonged vendor outage (event) could delay staff pay by more than two days (consequence), breaching enterprise agreements and damaging trust.” Compare that with “IT risk”, which nobody can own, measure or treat.
Output of step 1: a draft risk register with clear risk statements, categories, owners and the existing controls for each risk.

Risk analysis builds an understanding of each risk: what drives it, how likely it is, how severe the consequences could be, and how well existing controls work. Risk evaluation then compares the result with your risk criteria and appetite to decide which risks need action first.
Inherent risk is the level of risk before considering controls. Residual risk is the level that remains with current controls operating. The gap between the two shows how much you rely on those controls, which tells internal audit and the second line where testing matters most.
Most organisations use a five by five matrix. The descriptions below are illustrative and should be calibrated to your size, appetite and obligations:
| Combined rating | Typical meaning | Expected response |
|---|---|---|
| Extreme | Almost certain or likely, with major or severe consequences | Immediate executive action and board visibility; outside appetite |
| High | Likely with moderate consequences, or possible with major consequences | Treatment plan within an agreed short timeframe, executive oversight |
| Medium | Possible with moderate consequences | Managed within the business unit, monitored through KRIs |
| Low | Unlikely or rare with minor consequences | Accepted and monitored through routine processes |
For the small number of risks with the largest potential impact, such as a major cyber incident, loss of a critical supplier or a prolonged outage of a core system, qualitative ratings can be complemented by scenario analysis and quantitative estimates. Techniques such as bow-tie analysis, which links causes, controls and consequences on one diagram, and Monte Carlo simulation for financial exposure, help the board weigh the cost of treatment against the exposure it removes.
Output of step 2: inherent and residual ratings, control effectiveness assessments, and a prioritised list of risks that sit outside appetite.

Risk mitigation planning, called risk treatment in ISO 31000, decides what to do about each priority risk. ISO 31000:2018 lists the options as:
Output of step 3: approved treatment plans for every risk outside appetite, and documented acceptance for risks the organisation chooses to retain.
A plan only reduces risk once it changes how work is done. Implementation turns treatment plans into controls that operate every day, and embeds risk thinking into the decisions that create risk in the first place.
| Role | Responsibility in the ERM process |
|---|---|
| Board and risk committee | Approves the framework and risk appetite, oversees the risk profile and challenges management |
| Executive team | Sets the tone, owns enterprise risks, allocates resources to treatment and makes risk decisions |
| First line: risk owners and management | Identify and manage risks in their area, operate controls and deliver treatment actions |
| Second line: risk and compliance functions | Maintain the framework, facilitate assessments, challenge ratings and report the risk profile |
| Third line: internal audit | Provides independent assurance to the board that the framework and key controls work |
The Institute of Internal Auditors’ Three Lines Model (2020) is the most widely used way to describe these roles. Clear roles avoid the two most common failures: a risk team that owns every risk on behalf of the business, and a business that treats risk management as someone else’s paperwork.
Output of step 4: treatment actions delivered, controls operating with evidence, and risk assessment built into key decisions.

Risks change. Review and tracking, covering monitoring and review and recording and reporting in ISO 31000, keeps the risk profile current and makes sure the right people see the right information at the right time.
| Audience | What they receive | Typical frequency |
|---|---|---|
| Risk owners | Their risks, KRIs and overdue actions | Monthly |
| Executive risk committee | Enterprise risk profile, risks outside appetite, emerging risks | Monthly or quarterly |
| Board audit and risk committee | Risk profile against appetite, trends, key assurance results | Quarterly |
| Board | Annual review of the framework and risk appetite | Annually, and after major change |
Board reports work best when they are short, trend-based and written for directors rather than specialists. Our guide to board cyber risk KRIs and quarterly reporting shows the indicators we typically recommend for cyber.
Output of step 5: an up-to-date register, KRI dashboards, action tracking and a regular reporting pack.

Continual improvement is one of the eight principles of ISO 31000, and improvement closes the loop of its framework. The final step asks two questions: are our risks better managed than last cycle, and is our risk management itself getting better?
Output of step 6: lessons learned, an updated framework and a maturity roadmap that shapes the next cycle.
A risk process stays alive when the register, controls, actions, evidence and indicators live in one system. GRCLens, the governance, risk and compliance platform built by SSC, supports the full cycle:
| ERM step | How GRCLens helps |
|---|---|
| Risk identification | A central risk register with categories, owners, causes, consequences and linked controls |
| Risk analysis | Configurable likelihood and consequence scales, inherent and residual ratings, and risk heat maps |
| Risk mitigation planning | Treatment actions with owners, due dates and target ratings, linked to each risk |
| Implementation | A control library mapped to frameworks such as ISO 27001, with an evidence repository |
| Review and tracking | Key risk indicators, dashboards, version history and scheduled board-ready reports |
| Continuous improvement | Point-in-time assessment history so you can see maturity and risk trends over time |
We also work with your existing GRC tool if you have one; the process matters more than the software.
In Australia, ISO 31000:2018 is adopted as AS ISO 31000:2018 and is the usual reference for public and private sector risk frameworks. Several obligations build on the same process: APRA CPS 220 requires regulated institutions to maintain a board-approved risk management framework, CPS 230 adds operational risk and critical operations, and the SOCI Act requires responsible entities for critical infrastructure assets to maintain a Critical Infrastructure Risk Management Program. In New Zealand, directors are expected to oversee material risks, and public sector agencies apply risk management through the Protective Security Requirements. Running one enterprise process that feeds each of these avoids duplicated registers and conflicting ratings. For more detail, see our guide to the enterprise risk management framework for Australian organisations.
We design, run and uplift the enterprise risk management process for organisations across Australia and New Zealand, from a first enterprise risk register to a mature, board-reported program. Typical engagements include facilitating risk identification workshops, building rating criteria and appetite statements, designing KRIs and board reporting, and reviewing an existing framework against ISO 31000.
To talk about your risk process, contact our team.
The ERM process has six steps: risk identification, risk analysis and evaluation, risk mitigation planning, risk management implementation, review and tracking, and continuous improvement. Communication and consultation with stakeholders runs through every step, and the last step feeds back into the first, so the process is a continuous cycle.
The framework is the set of arrangements that supports risk management: leadership and commitment, policy, roles, risk appetite and reporting structures. The process is the cycle of activities that runs inside it: identifying, analysing, treating, monitoring and improving. ISO 31000:2018 describes the framework in clause 5 and the process in clause 6.
Inherent risk is the level of risk before considering controls. Residual risk is the level that remains with existing controls operating. Comparing the two shows how much the organisation relies on its controls, and where control testing matters most.
ISO 31000:2018 lists avoiding the risk, taking or increasing it to pursue an opportunity, removing the risk source, changing the likelihood, changing the consequences, sharing the risk through contracts or insurance, and retaining it by informed decision. These are often summarised as avoid, reduce, transfer and accept.
Risk owners typically review their risks and actions monthly, executives review the enterprise profile monthly or quarterly, and the board or its risk committee reviews it quarterly, with an annual review of the framework and risk appetite. Significant events such as a major incident, acquisition or new regulation should trigger an immediate review.
Either can work, and many organisations use both. ISO 31000:2018 gives concise, principle-based guidelines and is widely used in Australia and New Zealand; it is not certifiable. COSO ERM 2017 places strong emphasis on linking risk to strategy and performance. The six-step process on this page is consistent with both.
A key risk indicator is a measurable signal that a risk is increasing or decreasing, such as overdue critical patches or unplanned downtime of a critical service. Each KRI has thresholds linked to risk appetite, so crossing a threshold triggers a defined escalation.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.