The Enterprise Risk Management Process: 6 Steps

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

The enterprise risk management process is a continuous cycle of six steps: identify the risks to your objectives, analyse and prioritise them, plan how to treat them, implement those treatments, review and track progress, and improve the whole system each cycle. It follows the risk management process in ISO 31000:2018 and the Performance and Review components of the COSO ERM framework, and it is how boards and executives turn risk management from a register into better decisions.

This guide from Security Solution Consultants (SSC) explains each step of the ERM process in practical terms: what happens, who is involved, which techniques work, and what you should have at the end. Select a step to jump straight to it.

Leadership team in a boardroom reviewing sticky notes arranged in a circular six-stage loop, representing the enterprise risk management process
Enterprise risk management works best as a regular cycle that the leadership team owns.

Step 6 feeds back into step 1: the ERM process is a continuous cycle, not a one-off project.

What is the enterprise risk management process?

Enterprise risk management is the coordinated way an organisation manages every material risk to its objectives: strategic, operational, financial, compliance, cyber, people, third-party and reputational. The framework sets the governance, policy, roles and appetite. The process is the set of activities that runs inside that framework, cycle after cycle.

ISO 31000:2018 describes the process in clause 6 as communication and consultation; scope, context and criteria; risk assessment (identification, analysis and evaluation); risk treatment; monitoring and review; and recording and reporting. COSO’s 2017 framework, Enterprise Risk Management: Integrating with Strategy and Performance, covers the same ground in five components and 20 principles. Our six steps map to both:

SSC ERM stepISO 31000:2018COSO ERM 2017
1. Risk identification6.4.2 Risk identificationPerformance: identifies risk (principle 10)
2. Risk analysis6.4.3 Risk analysis and 6.4.4 Risk evaluationPerformance: assesses severity and prioritises risks (principles 11 and 12)
3. Risk mitigation planning6.5 Risk treatment: selecting options and preparing plansPerformance: implements risk responses (principle 13)
4. Risk management implementation6.5.3 Implementing treatment plans, and 5.5 Implementation of the frameworkPerformance (principles 13 and 14) and Governance and Culture
5. Review and tracking6.6 Monitoring and review, and 6.7 Recording and reportingReview and Revision (principles 15 and 16), and Information, Communication and Reporting (principles 18 to 20)
6. Continuous improvement5.7 Improvement, and the principle of continual improvementReview and Revision: pursues improvement in ERM (principle 17)

Communication and consultation is not a separate step: it runs through all six. Risk owners, subject matter experts and decision makers should be involved at every stage, otherwise the register describes the risk team’s view rather than the organisation’s.

Before you start: scope, context and risk criteria

The ERM process only produces consistent results when everyone uses the same rules. Before the first workshop, agree:

  • Objectives and scope. The strategic and business objectives the risks relate to, and whether the cycle covers the whole organisation or a division, program or project.
  • Risk appetite. A board-approved statement of how much risk the organisation will accept in pursuit of those objectives, by category, translated into tolerances. See our enterprise risk management services for how we build appetite statements.
  • Risk criteria. One likelihood scale, one consequence scale across financial, customer, safety, compliance and reputational impacts, and one matrix that combines them into a rating.
  • Risk taxonomy. A short, agreed list of risk categories so similar risks are grouped and reported together.
  • Roles. Who owns risks, who facilitates, who challenges and who decides, using the Three Lines Model described below.

Step 1: Risk identification

Hands grouping sticky notes into clusters on a whiteboard during a risk identification workshop
Good risk identification brings the people who do the work into the room.

Risk identification finds, recognises and describes the risks that could help or stop you achieving your objectives. The aim is a complete picture, not a long list: twenty well-described enterprise risks are more useful than two hundred vague ones.

Techniques that work

  • Facilitated workshops with each business unit, structured around objectives rather than around a blank page.
  • Interviews with executives and key process owners, who often see strategic and emerging risks first.
  • Process walk-throughs of critical services, following how a customer outcome is delivered and where it could fail.
  • Structured what-if technique (SWIFT) and scenario analysis, two of the methods described in IEC 31010:2019, the companion standard on risk assessment techniques.
  • Evidence from the past: incidents, near misses, complaints, audit findings, regulator correspondence and insurance claims.
  • Horizon scanning for emerging risks such as new regulation, artificial intelligence, climate and geopolitical change.

Write risks so they can be managed

A useful risk statement names the cause, the event and the consequence. For example: “Because payroll depends on a single software vendor (cause), a prolonged vendor outage (event) could delay staff pay by more than two days (consequence), breaching enterprise agreements and damaging trust.” Compare that with “IT risk”, which nobody can own, measure or treat.

Output of step 1: a draft risk register with clear risk statements, categories, owners and the existing controls for each risk.

Step 2: Risk analysis and evaluation

Tablet on a desk showing an abstract likelihood and consequence heat map shading from green to red
A shared rating scale lets the board compare very different risks side by side.

Risk analysis builds an understanding of each risk: what drives it, how likely it is, how severe the consequences could be, and how well existing controls work. Risk evaluation then compares the result with your risk criteria and appetite to decide which risks need action first.

Inherent and residual risk

Inherent risk is the level of risk before considering controls. Residual risk is the level that remains with current controls operating. The gap between the two shows how much you rely on those controls, which tells internal audit and the second line where testing matters most.

An example rating approach

Most organisations use a five by five matrix. The descriptions below are illustrative and should be calibrated to your size, appetite and obligations:

Combined ratingTypical meaningExpected response
ExtremeAlmost certain or likely, with major or severe consequencesImmediate executive action and board visibility; outside appetite
HighLikely with moderate consequences, or possible with major consequencesTreatment plan within an agreed short timeframe, executive oversight
MediumPossible with moderate consequencesManaged within the business unit, monitored through KRIs
LowUnlikely or rare with minor consequencesAccepted and monitored through routine processes

For the small number of risks with the largest potential impact, such as a major cyber incident, loss of a critical supplier or a prolonged outage of a core system, qualitative ratings can be complemented by scenario analysis and quantitative estimates. Techniques such as bow-tie analysis, which links causes, controls and consequences on one diagram, and Monte Carlo simulation for financial exposure, help the board weigh the cost of treatment against the exposure it removes.

Output of step 2: inherent and residual ratings, control effectiveness assessments, and a prioritised list of risks that sit outside appetite.

Step 3: Risk mitigation planning

Engineer fitting a new steel support beneath a scale model of a suspension bridge, representing risk treatment planning
Treatment plans strengthen the parts of the organisation that carry the most weight.

Risk mitigation planning, called risk treatment in ISO 31000, decides what to do about each priority risk. ISO 31000:2018 lists the options as:

  • Avoid the risk by deciding not to start or continue the activity that gives rise to it.
  • Take or increase the risk to pursue an opportunity, where the reward justifies it and it stays within appetite.
  • Remove the risk source.
  • Change the likelihood, for example with preventive controls, training or redesigned processes.
  • Change the consequences, for example with backups, continuity plans, segregation or incident response.
  • Share the risk, for example through contracts, outsourcing or insurance.
  • Retain the risk by informed decision, documented and approved at the right level.

What a good treatment plan contains

  • The specific actions, and the cause or consequence each one addresses
  • An accountable owner and a realistic due date for every action
  • The resources and budget required, and the cost compared with the reduction in risk
  • The target residual rating once the actions are complete
  • How progress and effectiveness will be measured, including any new KRI
  • Any new risks the treatment itself might introduce

Output of step 3: approved treatment plans for every risk outside appetite, and documented acceptance for risks the organisation chooses to retain.

Step 4: Risk management implementation

A plan only reduces risk once it changes how work is done. Implementation turns treatment plans into controls that operate every day, and embeds risk thinking into the decisions that create risk in the first place.

  • Build controls into processes and systems, such as approval workflows, access controls, supplier onboarding checks and automated monitoring, rather than relying on memory.
  • Integrate risk into decisions: business cases, project gates, procurement, product launches and strategic planning should each include a short risk assessment against appetite.
  • Train risk owners on the framework, the rating scales and what is expected of them each cycle.
  • Record evidence that controls operate, so assurance can test them without chasing people.
  • Test control design and operating effectiveness for key controls, through second line reviews and internal audit.

Who does what: the Three Lines Model

RoleResponsibility in the ERM process
Board and risk committeeApproves the framework and risk appetite, oversees the risk profile and challenges management
Executive teamSets the tone, owns enterprise risks, allocates resources to treatment and makes risk decisions
First line: risk owners and managementIdentify and manage risks in their area, operate controls and deliver treatment actions
Second line: risk and compliance functionsMaintain the framework, facilitate assessments, challenge ratings and report the risk profile
Third line: internal auditProvides independent assurance to the board that the framework and key controls work

The Institute of Internal Auditors’ Three Lines Model (2020) is the most widely used way to describe these roles. Clear roles avoid the two most common failures: a risk team that owns every risk on behalf of the business, and a business that treats risk management as someone else’s paperwork.

Output of step 4: treatment actions delivered, controls operating with evidence, and risk assessment built into key decisions.

Step 5: Review and tracking

Risk manager at a desk reviewing a dashboard of abstract trend lines and status tiles, representing key risk indicator monitoring
Key risk indicators show when a risk is moving before it becomes an incident.

Risks change. Review and tracking, covering monitoring and review and recording and reporting in ISO 31000, keeps the risk profile current and makes sure the right people see the right information at the right time.

What to track

  • Key risk indicators (KRIs) with green, amber and red thresholds linked to appetite, for example critical vulnerabilities open past their due date, unplanned downtime of a critical service, staff turnover in key roles or overdue high-rated audit findings.
  • Treatment actions against their due dates, with escalation for anything overdue.
  • Control effectiveness results from testing and assurance.
  • Incidents and near misses, linked back to the risks they relate to.
  • Changes in context, such as new regulation, a merger, a new technology or a major supplier change, which should trigger an out-of-cycle review.

A practical reporting rhythm

AudienceWhat they receiveTypical frequency
Risk ownersTheir risks, KRIs and overdue actionsMonthly
Executive risk committeeEnterprise risk profile, risks outside appetite, emerging risksMonthly or quarterly
Board audit and risk committeeRisk profile against appetite, trends, key assurance resultsQuarterly
BoardAnnual review of the framework and risk appetiteAnnually, and after major change

Board reports work best when they are short, trend-based and written for directors rather than specialists. Our guide to board cyber risk KRIs and quarterly reporting shows the indicators we typically recommend for cyber.

Output of step 5: an up-to-date register, KRI dashboards, action tracking and a regular reporting pack.

Step 6: Continuous improvement

Looking up through a spiral staircase rising towards a bright skylight, representing continuous improvement of risk management
Each cycle of the ERM process should leave the organisation a little more capable than the last.

Continual improvement is one of the eight principles of ISO 31000, and improvement closes the loop of its framework. The final step asks two questions: are our risks better managed than last cycle, and is our risk management itself getting better?

  • Learn from events. Run post-incident and near-miss reviews, and ask whether the risk was on the register, rated sensibly and treated with controls that worked.
  • Evaluate the framework. Check whether the appetite, criteria, taxonomy and reporting still fit the organisation’s strategy and size.
  • Measure maturity. Assess risk management maturity across governance, process, people, data and culture, and set a target for the next year. Our maturity assessment service applies the same approach to cyber.
  • Listen to risk culture. Short surveys and conversations show whether people feel able to raise risks and bad news early.
  • Feed it back. Improvements become inputs to step 1 of the next cycle, with updated context, criteria and focus areas.

Output of step 6: lessons learned, an updated framework and a maturity roadmap that shapes the next cycle.

Common mistakes in the ERM process

  • Treating ERM as an annual compliance exercise, with the register updated only before the audit committee meets.
  • Vague risk statements such as “cyber risk” or “people risk” that cannot be owned or measured.
  • Different scales in different teams, so ratings cannot be compared or aggregated.
  • Assuming controls work without testing their design and operation.
  • Treatment actions without owners or dates, or overdue actions with no escalation.
  • Reporting activity instead of risk: counting workshops held rather than showing which risks moved and why.
  • Cyber, compliance and operational risks in separate silos that never reach the board in one view.

How GRCLens supports each step of the ERM process

A risk process stays alive when the register, controls, actions, evidence and indicators live in one system. GRCLens, the governance, risk and compliance platform built by SSC, supports the full cycle:

ERM stepHow GRCLens helps
Risk identificationA central risk register with categories, owners, causes, consequences and linked controls
Risk analysisConfigurable likelihood and consequence scales, inherent and residual ratings, and risk heat maps
Risk mitigation planningTreatment actions with owners, due dates and target ratings, linked to each risk
ImplementationA control library mapped to frameworks such as ISO 27001, with an evidence repository
Review and trackingKey risk indicators, dashboards, version history and scheduled board-ready reports
Continuous improvementPoint-in-time assessment history so you can see maturity and risk trends over time

We also work with your existing GRC tool if you have one; the process matters more than the software.

Applying the ERM process in Australia and New Zealand

In Australia, ISO 31000:2018 is adopted as AS ISO 31000:2018 and is the usual reference for public and private sector risk frameworks. Several obligations build on the same process: APRA CPS 220 requires regulated institutions to maintain a board-approved risk management framework, CPS 230 adds operational risk and critical operations, and the SOCI Act requires responsible entities for critical infrastructure assets to maintain a Critical Infrastructure Risk Management Program. In New Zealand, directors are expected to oversee material risks, and public sector agencies apply risk management through the Protective Security Requirements. Running one enterprise process that feeds each of these avoids duplicated registers and conflicting ratings. For more detail, see our guide to the enterprise risk management framework for Australian organisations.

How SSC can help

We design, run and uplift the enterprise risk management process for organisations across Australia and New Zealand, from a first enterprise risk register to a mature, board-reported program. Typical engagements include facilitating risk identification workshops, building rating criteria and appetite statements, designing KRIs and board reporting, and reviewing an existing framework against ISO 31000.

To talk about your risk process, contact our team.

Frequently asked questions

The ERM process has six steps: risk identification, risk analysis and evaluation, risk mitigation planning, risk management implementation, review and tracking, and continuous improvement. Communication and consultation with stakeholders runs through every step, and the last step feeds back into the first, so the process is a continuous cycle.

The framework is the set of arrangements that supports risk management: leadership and commitment, policy, roles, risk appetite and reporting structures. The process is the cycle of activities that runs inside it: identifying, analysing, treating, monitoring and improving. ISO 31000:2018 describes the framework in clause 5 and the process in clause 6.

Inherent risk is the level of risk before considering controls. Residual risk is the level that remains with existing controls operating. Comparing the two shows how much the organisation relies on its controls, and where control testing matters most.

ISO 31000:2018 lists avoiding the risk, taking or increasing it to pursue an opportunity, removing the risk source, changing the likelihood, changing the consequences, sharing the risk through contracts or insurance, and retaining it by informed decision. These are often summarised as avoid, reduce, transfer and accept.

Risk owners typically review their risks and actions monthly, executives review the enterprise profile monthly or quarterly, and the board or its risk committee reviews it quarterly, with an annual review of the framework and risk appetite. Significant events such as a major incident, acquisition or new regulation should trigger an immediate review.

Either can work, and many organisations use both. ISO 31000:2018 gives concise, principle-based guidelines and is widely used in Australia and New Zealand; it is not certifiable. COSO ERM 2017 places strong emphasis on linking risk to strategy and performance. The six-step process on this page is consistent with both.

A key risk indicator is a measurable signal that a risk is increasing or decreasing, such as overdue critical patches or unplanned downtime of a critical service. Each KRI has thresholds linked to risk appetite, so crossing a threshold triggers a defined escalation.