Skip to main content
Audit & Assurance

Risk Management Services

Practice01/06

Risk Framework Design.

Note01
ISO 31000 and COSO ERM-aligned risk frameworks tailored to appetite and complexity.
Index06 Practices
01Risk Framework Design
02Risk Register Development
03Control Design
04Policy & Procedure Drafting
05Compliance Risk Mapping
06Monitoring Mechanism Design

Risk Advisory Scope

Our risk management services address the design and documentation of risk frameworks—distinct from internal audit, which evaluates these frameworks independently.

Risk Framework Design

Developing comprehensive risk management frameworks aligned with ISO 31000, COSO ERM, or industry-specific standards—tailored to your organisation's size, complexity, and risk appetite.

Risk Register Development

Building structured risk registers that capture, categorise, and prioritise risks across the organisation—with clear ownership, ratings, and treatment plans.

Control Design

Designing preventive and detective controls that address identified risks—ensuring controls are proportionate, practical, and integrated into business processes.

Policy & Procedure Drafting

Documenting risk management policies, procedures, and guidelines that provide clear direction for risk identification, assessment, treatment, and reporting.

Compliance Risk Mapping

Mapping regulatory and compliance obligations to business processes and controls—ensuring coverage and identifying gaps in your compliance framework.

Monitoring Mechanism Design

Establishing key risk indicators (KRIs), dashboards, and reporting structures that enable ongoing risk monitoring and timely escalation.

Risk Management vs. Internal Audit

Under the IIA Three Lines Model, risk management and internal audit serve distinct functions—one designs frameworks, the other evaluates them.

  • Second Line (Risk Management): Designs risk frameworks, policies, and monitoring mechanisms
  • Third Line (Internal Audit): Evaluates framework adequacy and operating effectiveness independently
  • Risk management reports to management; internal audit reports to the audit committee
  • Risk management owns the risk register; internal audit evaluates the register's completeness
  • This service addresses framework design—not independent evaluation of existing frameworks
  • For independent evaluation of risk management frameworks, see our Internal Audit services

Our Advisory Approach

Step 1

Current State Documentation

We document your existing risk management practices, governance structures, and any frameworks currently in place—establishing a baseline for development.

Step 2

Risk Identification Workshops

Facilitated sessions with management and key stakeholders to systematically identify risks across strategic, operational, financial, and compliance dimensions.

Step 3

Framework & Register Development

Building the risk management framework and populating the risk register with identified risks, assessments, ownership assignments, and treatment plans.

Step 4

Control & Policy Design

Designing controls to address prioritised risks and drafting policies and procedures that embed risk management into business operations.

Step 5

Monitoring Design & Handover

Establishing KRIs, reporting templates, and escalation protocols—then transitioning ownership to your team with training and documentation.

Common Questions

  1. What is enterprise risk management (ERM)?

    Enterprise risk management is an organisation-wide approach to identifying, assessing, treating, and monitoring the risks that could affect a company's objectives. Rather than handling risks separately in each department, it brings strategic, operational, financial, and compliance risks into a single, consistent view for the board and management. The aim is to keep risk within levels the organisation is prepared to accept and to support better-informed decisions. Designing and running this system sits with management, the second line in common governance models, distinct from the independent evaluation that internal audit provides.

  2. What is a risk management framework, and which standards are commonly used?

    A risk management framework is the structure of policies, roles, processes, and reporting that an organisation uses to manage risk consistently. It defines how risks are identified, who owns them, how they are rated, and how they are escalated and reviewed. Two widely used reference standards are ISO 31000, the international standard setting out principles and guidelines for risk management, and the COSO ERM framework, which links risk management to strategy and performance. We design frameworks aligned to these standards and scaled to the organisation's size and complexity.

  3. What is the difference between ISO 31000 and COSO ERM?

    Both are recognised risk management standards with different emphases. ISO 31000, published by the International Organization for Standardization, sets out principles and a general process for managing any type of risk, and is meant to be adapted by any organisation. It is guidance rather than a certifiable standard. COSO ERM, issued by the Committee of Sponsoring Organizations, focuses on integrating risk management with strategy and performance, and is structured around defined components and principles. Many Indian organisations draw on both: ISO 31000 for the process and COSO for the link to strategy and governance.

  4. What are the main categories of business risk?

    Risk is usually grouped into broad categories so that nothing material is overlooked. Common categories are strategic risk, arising from business choices and market changes; operational risk, from internal processes, people, and systems; financial risk, covering liquidity, credit, and market exposure; and compliance or regulatory risk, from the laws and obligations the organisation must meet. Many frameworks also separate out reputational risk and technology or cyber risk. A risk register captures these categories so each can be assessed and assigned an owner.

  5. What is a risk register, and what does it contain?

    A risk register is the central record of an organisation's identified risks. For each risk it typically records a description, the category, the likelihood of occurrence, the potential impact, the assessed rating before controls (inherent risk) and after controls (residual risk), the controls in place, the person who owns the risk, the planned treatment, and the current status. It is a living document, updated as risks change and as treatments take effect. In common governance models, management owns and maintains the register, while internal audit independently evaluates whether it is complete and current.

  6. What is the difference between inherent risk and residual risk?

    Inherent risk is the level of risk that exists before any controls are applied, the natural exposure of an activity on its own. Residual risk is the level that remains after controls and treatments are in place. For example, holding customer payment data online carries a high inherent risk of a breach; after access controls, encryption, and monitoring are applied, the lower remaining exposure is the residual risk. Comparing the two shows how much the controls reduce exposure, and whether the residual level sits within what the organisation is willing to accept.

  7. What is risk appetite, and how does it differ from risk tolerance?

    Risk appetite is the amount and type of risk an organisation is willing to accept in pursuing its objectives, set at board or senior management level. Risk tolerance is narrower: the acceptable variation around a specific objective or limit, often expressed as a threshold. Appetite is the broad statement of intent, for example a conservative stance on financial exposure; tolerance translates that into measurable boundaries for particular risks. A clearly stated appetite gives the people managing day-to-day risk a reference point for deciding what to escalate and what to accept.

  8. What are the available risk treatment options?

    Once a risk is assessed, an organisation chooses how to respond. The standard options are to avoid the risk by not undertaking the activity, to reduce it by applying controls that lower its likelihood or impact, to transfer or share it, for example through insurance or contractual terms, or to accept it where the residual level is within appetite. The choice weighs the cost of each option against the exposure it addresses. The selected treatment, its owner, and its status are recorded against the risk in the register.

  9. What are key risk indicators (KRIs)?

    Key risk indicators are measurable signals that show whether a particular risk is increasing or moving toward an unacceptable level. They act as an early warning, so management can act before a risk materialises. Examples include the rate of failed transactions, attrition in a critical function, or the number of overdue compliance tasks. Each indicator is usually given a threshold that triggers review or escalation when crossed. KRIs, together with dashboards and reporting templates, form the monitoring layer of a risk management framework.

  10. What steps does the risk management process involve?

    A typical risk management process runs in stages. First, the scope and context are set, including the objectives at stake and the organisation's risk appetite. Risks are then identified across the business and assessed for likelihood and impact. Each risk is evaluated against appetite to decide priority, then treated through the chosen response. Finally, risks and treatments are monitored and reported on a regular cycle, since the risk picture changes over time. Communication runs through every stage, so the board and management share a consistent view.

  11. How is risk management different from internal audit?

    They are separate functions with separate roles, often described through the Three Lines Model. Operational management is the first line, owning and managing risk day to day. Risk management is the second line: it designs the frameworks, policies, and monitoring that help the first line keep risk within appetite, and it reports to management. Internal audit is the third line: it independently evaluates whether the first and second lines are working, and reports to the audit committee or board. In short, risk management designs and runs the system, and internal audit independently checks it. Keeping the two separate preserves the independence of the audit function.

  12. Is risk management legally required for companies in India?

    For most companies the obligation is at policy and reporting level rather than a prescribed structure. Under Section 134(3)(n) of the Companies Act, 2013, a company's Board's report must include a statement on the development and implementation of a risk management policy, identifying elements of risk that may threaten the company's existence. Where a company has an audit committee, Section 177 includes evaluation of risk management systems within the committee's terms of reference. Beyond these baseline requirements, many unlisted and private companies adopt a formal framework voluntarily to support lending, growth, or governance expectations.

  13. Is a risk management committee mandatory for Indian companies?

    A board-level Risk Management Committee is mandatory only for specified listed entities, not for every company. Under Regulation 21 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, the requirement applies to the top 1,000 listed entities by market capitalisation, and to high value debt listed entities. The committee must have at least three members, with a majority drawn from the board including at least one independent director, and must meet at least twice in a financial year. Companies outside this scope are not required to form the committee, though some set up a similar oversight forum voluntarily.