Expertise

Enterprise Risk Management — Jonas Osman Abdelfour

Risk taxonomy, appetite, RCSAs, scenario analysis and executive reporting — the disciplines that make enterprise risk a decision-making tool rather than a compliance exercise.

Enterprise risk management (ERM) is only credible when it changes decisions. That requires a consistent taxonomy, an appetite that translates into limits, quality RCSAs that reflect how the business actually operates, and reporting that highlights what matters at the level it needs to be heard.

What this work covers

A representative — not exhaustive — set of areas addressed in engagements of this type.

  • Enterprise risk taxonomy
  • Risk appetite framework
  • Key risk indicators (KRIs)
  • Risk and control self-assessment
  • Scenario analysis & stress testing
  • Operational risk management
  • Emerging risk identification
  • Risk aggregation and profile
  • Executive & board risk reporting
  • Risk data quality and MI
  • Integration with capital planning
  • Integration with strategy

How it operates in practice

ERM engagements start with the appetite: is it specific, measurable, and demonstrably used? From there, the taxonomy, RCSA methodology and KRIs are tested for alignment. Reporting is redesigned to highlight breaches, trends and forward-looking indicators — with clear ownership and escalation.

Related insights

All insights →