Risk Framework Design
Developing comprehensive risk management frameworks aligned with ISO 31000, COSO ERM, or industry-specific standards—tailored to your organisation's size, complexity, and risk appetite.
Our risk management services address the design and documentation of risk frameworks—distinct from internal audit, which evaluates these frameworks independently.
Developing comprehensive risk management frameworks aligned with ISO 31000, COSO ERM, or industry-specific standards—tailored to your organisation's size, complexity, and risk appetite.
Building structured risk registers that capture, categorise, and prioritise risks across the organisation—with clear ownership, ratings, and treatment plans.
Designing preventive and detective controls that address identified risks—ensuring controls are proportionate, practical, and integrated into business processes.
Documenting risk management policies, procedures, and guidelines that provide clear direction for risk identification, assessment, treatment, and reporting.
Mapping regulatory and compliance obligations to business processes and controls—ensuring coverage and identifying gaps in your compliance framework.
Establishing key risk indicators (KRIs), dashboards, and reporting structures that enable ongoing risk monitoring and timely escalation.
Under the IIA Three Lines Model, risk management and internal audit serve distinct functions—one designs frameworks, the other evaluates them.
We document your existing risk management practices, governance structures, and any frameworks currently in place—establishing a baseline for development.
We document your existing risk management practices, governance structures, and any frameworks currently in place—establishing a baseline for development.
Facilitated sessions with management and key stakeholders to systematically identify risks across strategic, operational, financial, and compliance dimensions.
Facilitated sessions with management and key stakeholders to systematically identify risks across strategic, operational, financial, and compliance dimensions.
Building the risk management framework and populating the risk register with identified risks, assessments, ownership assignments, and treatment plans.
Building the risk management framework and populating the risk register with identified risks, assessments, ownership assignments, and treatment plans.
Designing controls to address prioritised risks and drafting policies and procedures that embed risk management into business operations.
Designing controls to address prioritised risks and drafting policies and procedures that embed risk management into business operations.
Establishing KRIs, reporting templates, and escalation protocols—then transitioning ownership to your team with training and documentation.
Establishing KRIs, reporting templates, and escalation protocols—then transitioning ownership to your team with training and documentation.
Enterprise risk management is an organisation-wide approach to identifying, assessing, treating, and monitoring the risks that could affect a company's objectives. Rather than handling risks separately in each department, it brings strategic, operational, financial, and compliance risks into a single, consistent view for the board and management. The aim is to keep risk within levels the organisation is prepared to accept and to support better-informed decisions. Designing and running this system sits with management, the second line in common governance models, distinct from the independent evaluation that internal audit provides.
A risk management framework is the structure of policies, roles, processes, and reporting that an organisation uses to manage risk consistently. It defines how risks are identified, who owns them, how they are rated, and how they are escalated and reviewed. Two widely used reference standards are ISO 31000, the international standard setting out principles and guidelines for risk management, and the COSO ERM framework, which links risk management to strategy and performance. We design frameworks aligned to these standards and scaled to the organisation's size and complexity.
Both are recognised risk management standards with different emphases. ISO 31000, published by the International Organization for Standardization, sets out principles and a general process for managing any type of risk, and is meant to be adapted by any organisation. It is guidance rather than a certifiable standard. COSO ERM, issued by the Committee of Sponsoring Organizations, focuses on integrating risk management with strategy and performance, and is structured around defined components and principles. Many Indian organisations draw on both: ISO 31000 for the process and COSO for the link to strategy and governance.
Risk is usually grouped into broad categories so that nothing material is overlooked. Common categories are strategic risk, arising from business choices and market changes; operational risk, from internal processes, people, and systems; financial risk, covering liquidity, credit, and market exposure; and compliance or regulatory risk, from the laws and obligations the organisation must meet. Many frameworks also separate out reputational risk and technology or cyber risk. A risk register captures these categories so each can be assessed and assigned an owner.
A risk register is the central record of an organisation's identified risks. For each risk it typically records a description, the category, the likelihood of occurrence, the potential impact, the assessed rating before controls (inherent risk) and after controls (residual risk), the controls in place, the person who owns the risk, the planned treatment, and the current status. It is a living document, updated as risks change and as treatments take effect. In common governance models, management owns and maintains the register, while internal audit independently evaluates whether it is complete and current.
Inherent risk is the level of risk that exists before any controls are applied, the natural exposure of an activity on its own. Residual risk is the level that remains after controls and treatments are in place. For example, holding customer payment data online carries a high inherent risk of a breach; after access controls, encryption, and monitoring are applied, the lower remaining exposure is the residual risk. Comparing the two shows how much the controls reduce exposure, and whether the residual level sits within what the organisation is willing to accept.
Risk appetite is the amount and type of risk an organisation is willing to accept in pursuing its objectives, set at board or senior management level. Risk tolerance is narrower: the acceptable variation around a specific objective or limit, often expressed as a threshold. Appetite is the broad statement of intent, for example a conservative stance on financial exposure; tolerance translates that into measurable boundaries for particular risks. A clearly stated appetite gives the people managing day-to-day risk a reference point for deciding what to escalate and what to accept.
Once a risk is assessed, an organisation chooses how to respond. The standard options are to avoid the risk by not undertaking the activity, to reduce it by applying controls that lower its likelihood or impact, to transfer or share it, for example through insurance or contractual terms, or to accept it where the residual level is within appetite. The choice weighs the cost of each option against the exposure it addresses. The selected treatment, its owner, and its status are recorded against the risk in the register.
Key risk indicators are measurable signals that show whether a particular risk is increasing or moving toward an unacceptable level. They act as an early warning, so management can act before a risk materialises. Examples include the rate of failed transactions, attrition in a critical function, or the number of overdue compliance tasks. Each indicator is usually given a threshold that triggers review or escalation when crossed. KRIs, together with dashboards and reporting templates, form the monitoring layer of a risk management framework.
A typical risk management process runs in stages. First, the scope and context are set, including the objectives at stake and the organisation's risk appetite. Risks are then identified across the business and assessed for likelihood and impact. Each risk is evaluated against appetite to decide priority, then treated through the chosen response. Finally, risks and treatments are monitored and reported on a regular cycle, since the risk picture changes over time. Communication runs through every stage, so the board and management share a consistent view.
They are separate functions with separate roles, often described through the Three Lines Model. Operational management is the first line, owning and managing risk day to day. Risk management is the second line: it designs the frameworks, policies, and monitoring that help the first line keep risk within appetite, and it reports to management. Internal audit is the third line: it independently evaluates whether the first and second lines are working, and reports to the audit committee or board. In short, risk management designs and runs the system, and internal audit independently checks it. Keeping the two separate preserves the independence of the audit function.
For most companies the obligation is at policy and reporting level rather than a prescribed structure. Under Section 134(3)(n) of the Companies Act, 2013, a company's Board's report must include a statement on the development and implementation of a risk management policy, identifying elements of risk that may threaten the company's existence. Where a company has an audit committee, Section 177 includes evaluation of risk management systems within the committee's terms of reference. Beyond these baseline requirements, many unlisted and private companies adopt a formal framework voluntarily to support lending, growth, or governance expectations.
A board-level Risk Management Committee is mandatory only for specified listed entities, not for every company. Under Regulation 21 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, the requirement applies to the top 1,000 listed entities by market capitalisation, and to high value debt listed entities. The committee must have at least three members, with a majority drawn from the board including at least one independent director, and must meet at least twice in a financial year. Companies outside this scope are not required to form the committee, though some set up a similar oversight forum voluntarily.