- Board Risk & Internal Control Oversight Cycle — Executive; with Risk Management · 7 steps
Support the independent board’s risk and internal-control oversight, annual governance-framework evaluation and approval of strategy and policies; adopt the minutes and carry an owned directives register into implementation and the next cycle.
- Combined Assurance Mapping — Internal Audit; with Risk Management · 7 steps
Map effective assurance across the Three Lines, resolve self-review safeguards, assess independent reliance and agree coverage commitments; govern remaining gaps and deliver the map and evidence to audit-committee reporting.
- Continuous Controls Monitoring (ISCM) Cycle — IT; with Risk Management · 4 steps
Run recurring control monitoring by collecting metrics, comparing thresholds, triaging degradation, updating POA&M, reporting health, and tuning cadence.
- Control Design — Business Operations; with Risk Management · 3 steps
Design a new control from objective definition through attribute specification, risk mapping, evidence and test approach definition, and final control record creation.
- Control Exception Evaluation and Remediation — Internal Audit; with Risk Management · 2 steps
Evaluate exception scope, impact, severity and compensating controls, then obtain management-owned remediation and authorized escalation.
- Control Library Lifecycle — Risk Management; with Finance · 3 steps
Review proposed controls for duplication, classification and risk-policy-process linkage; govern publication and rework, then review operating changes and preserve history when a control is retired.
- Domain Oversight and Management Review — Risk Management; with Executive · 1 steps
Assess the domain’s register, operating evidence, risk posture and control exceptions, then record management priorities, resources and escalations with domain-owner and independent-reviewer approval.
- Emerging Risk & Horizon Scan — Risk Management · 1 steps
Scan the forward horizon for signals of an emerging exposure, assess plausibility and velocity, and decide whether it enters the register or stays on the watchlist.
- Enterprise GRC Platform Integration Bridge — IT; with Risk Management · 5 steps
Define mappings, migrate or provision records, run bidirectional sync, monitor health, resolve conflicts, and confirm system-of-record coverage.
- Enterprise Risk Assessment & Portfolio Oversight Cycle — Risk Management · 8 steps
Assess enterprise risks on a fixed appetite and scoring basis, obtain owned responses and appropriate acceptance authority, and approve the residual portfolio and movement narrative for governance reporting.
- Enterprise Risk Register Lifecycle — Risk Management · 6 steps
Maintain the risk register with distinct Three Lines responsibilities, evidence-backed owner-approved ratings and calibrated KRIs; govern treatment or acceptance and hand the maintained portfolio to assessment and appetite reporting.
- Enterprise Risk Treatment Operations Cycle — Business Operations; with Risk Management · 5 steps
Assess enterprise threats and opportunities, implement owned treatment for tolerance breaches and reassess residual exposure; obtain required senior acceptance and approve a current register, portfolio report and change-monitoring record.
- ERM Risk Identification & Register Refresh — Risk Management · 1 steps
Run a periodic enterprise risk identification cycle, consolidate candidate risks, and approve the resulting register changes.
- ESG-Related Risk Materiality & Integration — Risk Management; with Executive · 5 steps
Assess ESG impacts, risks and opportunities with affected stakeholders and information users; validate material topics, evaluate responses and disclosure readiness, and govern gaps or acceptance before board reporting.
- Framework Adoption & Cross-Mapping — Compliance & Legal; with Risk Management · 5 steps
Set obligation- and appetite-based framework targets, assess current evidence and crosswalk coverage, and govern risk-ranked gaps; deliver approved policy/control work with a maintained mapping table and versioned adoption record.
- GCP Physical and Environmental Subservice Reliance — IT; with Risk Management · 5 steps
Evaluate GCP assurance-report scope, physical and environmental controls, exceptions and user responsibilities; record a bounded reliance decision rather than claiming to operate provider facilities.
- ISMS Risk Assessment & Treatment Cycle — IT; with Risk Management · 7 steps
Perform ISO 27005 risk assessment and treatment planning to produce current risks and SoA inputs for ISO 27001 control applicability.
- Issue Remediation and Verification — Risk Management; with Business Operations · 2 steps
Agree cause-based, separately owned remediation actions and validate each by its committed method; approve the finding’s closure only when every linked action is validated and closed.
- Issue Triage & Disposition — Risk Management · 2 steps
Substantiate a reported issue, assess its severity and cause, select a governed disposition, and approve the triage record.
- Policy Exception & Risk Acceptance — Risk Management; with Compliance & Legal · 6 steps
Manage policy exceptions end-to-end: justify, risk-assess, compensate, approve time-bound, register with expiry, and re-review.
- Quarterly Board & Audit-Committee GRC Reporting — Risk Management; with Internal Audit, Executive · 6 steps
Compile the quarterly GRC board pack across risk profile, audit, SOX, regulatory deadlines, control health, incidents, issues, and decisions.
- Risk & Control Self-Assessment (RCSA) Program — Business Operations; with Risk Management · 8 steps
Run first-line risk and control self-assessment with evidence-backed owner ratings and native attestations, second-line challenge and calibration, explicit unassessed units, risk-register updates, remediation or acceptance handoffs, and risk-committee reporting.
- Risk & Resilience Framework Governance — Risk Management; with Executive · 8 steps
Establish, approve, and maintain the enterprise risk management framework and its ICT operational-resilience (DORA) and regulated-technology extensions - accountabilities, resources, processes, and risk tolerance - with management-body sponsorship, planned implementation across the organization, and at-least-annual review.
- Risk Appetite & Tolerance Calibration — Risk Management · 2 steps
Set or recalibrate the appetite statement and tolerance thresholds for a risk, test the current position against them, and approve the escalation record.
- Risk Appetite Definition & Board Reporting — Executive; with Risk Management · 8 steps
Define appetite statements, tolerances, KRIs, board approval, monitoring, and ERM reporting for governance oversight.
- Risk Assessment and Treatment Review — Risk Management · 2 steps
Apply the approved rating method to a defined scenario, evaluate controls, select treatment and approve residual risk and monitoring.
- Risk Communication, Reporting & Performance Review — Risk Management · 8 steps
Each quarter - and on an event-driven basis whenever a significant matter arises - the ERM office runs structured stakeholder consultation across the risk process, including supplier and third-party risk and human and cultural factors, and delivers the cadenced risk, control, and performance reporting packages internally at every level and to external stakeholders and partners. The same cycle reviews risk-management and internal-control performance against the framework's design and intended outcomes with accountable management, then converts the lessons into owned, tracked improvement actions driven to closure.
- Risk Register Intake — Risk Management · 4 steps
Capture a new risk from initial identification through inherent scoring, control mapping, residual scoring, and owner assignment with a defined review cadence.
- SOC Report, Subservice & CUEC Review — Risk Management · 2 steps
Evaluate a service-organization report, subservice coverage, exceptions, and complementary user-entity controls for a governed reliance decision.
- Strategic Context & Objectives Alignment Cycle — Executive; with Risk Management · 9 steps
Annually refresh the organization's documented mission, stakeholder expectations, and critical objectives and dependencies, and communicate that context to those who scope and prioritize risk work. Realign strategy with mission and risk profile, cascade objectives and publish the roadmap, then close by documenting mission-essential business processes and information-protection needs as the approved basis for risk-assessment scoping.
- System and Third-Party Risk Review — Risk Management; with IT, Procurement · 2 steps
Evaluate system criticality, data flows, supplier evidence, gaps and compensating controls before accepting its risk posture.
- Vendor Risk Assessment and Disposition — Procurement; with Risk Management, IT · 2 steps
Assess the actual supplier's contracts, assurance reports, access, continuity and exit evidence; obtain expert challenge and an authorized reliance disposition.