The ABC risk management process is aligned to the five traditional pillars of risk management and is usually structured to map governance, identification, assessment, treatment, and monitoring into a formal lifecycle. To align with ratified and widely accepted standards such as International Organization for Standardization (ISO 31000), Committee of Sponsoring Organizations of the Treadway Commission (COSO ERM), and Project Management Institute, the document should be comprehensive enough to satisfy governance, audit, and operational requirements.
Click a section to expand details.
Defines:
Example: To establish a consistent framework for identifying, assessing, treating, monitoring, and reporting risks.
Defines:
Reference governing frameworks:
Standardized definitions for:
Core principles:
This is the Governance & Context pillar.
7.1 Risk Governance Structure
7.2 Roles and Responsibilities — Define RACI for:
7.3 Risk Appetite Statement — Include:
7.4 Risk Policy Alignment — Cross-reference:
7.5 Internal and External Context
This is the Identification pillar.
8.1 Objectives of Risk Identification
8.2 Risk Categories / Taxonomy
8.3 Identification Techniques
8.4 Risk Register Structure — Required fields:
8.5 Emerging Risk Identification
This is the Assessment pillar.
9.1 Assessment Methodology — Define:
9.2 Likelihood Criteria — Examples:
9.3 Impact Criteria — Dimensions:
9.4 Risk Scoring Model — Formula: Risk Score = Likelihood × Impact
9.5 Risk Matrix — Usually a 5×5 matrix.
9.6 Inherent Risk Assessment
9.7 Control Effectiveness Assessment
9.8 Residual Risk Assessment
9.9 Risk Prioritization — Ranking:
This is the Treatment pillar.
10.1 Risk Response Strategy — Standard responses:
10.2 Treatment Planning — Include:
10.3 Control Design Requirements
10.4 Business Continuity Alignment
10.5 Incident Response Integration
10.6 Contingency Planning
10.7 Risk Acceptance Procedure — Formal sign-off requirements.
This is the Monitoring & Improvement pillar.
11.1 Continuous Monitoring Framework
11.2 Key Risk Indicators (KRIs) — Include:
11.3 Key Control Indicators (KCIs)
11.4 Trigger Events — Examples:
11.5 Periodic Review Schedule
11.6 Risk Reassessment Criteria
Required by ISO and COSO across all pillars.
12.1 Reporting Cadence
12.2 Report Types
12.3 Escalation Procedures
12.4 Stakeholder Communication Matrix
13.1 Internal Audit Requirements
13.2 Independent Assurance
13.3 Control Testing
13.4 Compliance Validation
14.1 Awareness Program
14.2 Role-based Training
14.3 Certification Requirements
15.1 GRC Platform Requirements
15.2 Risk Register System
15.3 Dashboarding Requirements
15.4 Data Retention
16.1 Risk Maturity Assessment
16.2 KPI/KRI Effectiveness
16.3 Treatment Effectiveness Metrics
17.1 Lessons Learned
17.2 Incident Postmortems
17.3 Process Improvement Loop
17.4 Framework Review