Enterprise Risk Management
A risk framework that informs decisions instead of filling a binder: appetite, limits, governance, and reporting a board can use.
Our view
Most risk frameworks fail the same way: built to satisfy an examiner, then filed, while the business goes on deciding as if they did not exist. A framework earns its keep only when it shapes real decisions, when appetite and limits actually constrain what the firm does and reporting tells the board something it can act on. We build risk in at the point of decision, not onto a shelf.
When this is the work
When risk lives in a binder no one reads.
A board or examiner wants a real framework, or growth has outrun the controls around it. We build risk into how you decide, not onto a shelf.
- Risk lives in a binder, not in decisions
- A board or examiner wants a real framework
- Growth has outrun the controls
The Ore to Edge Discipline
The same three-phase discipline on every engagement, adapted to the demands of this work. See the full discipline.
Assay and refine
- Partner: build a risk taxonomy and map exposures with your team
- Collect: the macro, regulatory, and competitive risk environment
- Synthesize: where the firm is actually exposed
A map of where the firm is actually exposed
Alloy and form
- Set risk appetite and limits
- Model the exposures and how they interact
- Design the governance and reporting
A risk appetite, limits, and governance the board signs off on
Forge and hone
- Stand up the framework, the committee reporting, and the documentation
- Monitor against limits and re-calibrate appetite as conditions change
A framework that shapes decisions and passes the exam
What you get
A risk framework a board can use.
- A board-usable framework and appetite statement
- A limit structure and reporting
- Exam-ready documentation
Common questions
Enterprise Risk Management, in plain terms.
What is enterprise risk management?
It is the discipline of identifying the risks across an organization, setting how much risk it is willing to take, putting limits and controls around that, and reporting it so leadership and the board can decide with eyes open. The aim is better decisions, not a thicker binder.
What is a risk appetite statement?
A clear articulation of how much and what kinds of risk the organization is willing to accept in pursuit of its goals. It turns risk from a vague worry into an explicit boundary that guides real decisions and limits.
How is this different from compliance?
Compliance asks whether you are following the rules. Risk management asks whether you are taking the right risks, in the right amounts, to meet your objectives. The two overlap, but a clean compliance record does not mean risk is well managed.
We are a smaller institution. Do we need a full framework?
You need one that fits. The principles scale down: a proportionate taxonomy, a clear appetite, sensible limits, and reporting a board can use. The work draws on global-bank practice, sized to what you actually run.
Related capabilities
