Enterprise Risk & Governance
Resilience you can measure.
Risk registers that nobody challenges are theatre. We build enterprise risk and governance frameworks that force judgement — and survive inspection.
SCA-approved risk officer experience across regulated environments
The problems we solve
- The risk register is updated for appearances, not decisions
- Board risk reporting is a heat map without ownership
- Appetite statements exist; breaches are invisible
- Second-line coverage is thin or titled without authority
- Governance calendars produce minutes without challenge
- Incident lessons never re-enter the control design
If any of these is on your desk this quarter, the conversation is worth an hour.
Continue: how we work →How we work
One discipline, five movements
-
1
Map
Risk universe and appetite
-
2
Assess
Material exposures, ranked
-
3
Design
Reporting and escalation
-
4
Govern
Committees and decision rights
-
5
Test
Breaches, crises and board packs
What you receive
ERM framework
Risk taxonomy, appetite, reporting and escalation that work
Board risk packs
From register to judgement — what changed and what the board must decide
Governance design
Committees, charters and decision rights
Questions boards ask us
Can you act as an outsourced risk officer?
Where the licence and board agree, yes — with SCA-approved personnel and documented accountability.
How do you avoid risk theatre?
Every material risk must have an owner, indicator and decision path. If it cannot drive action, it does not survive the design.
Do you link risk to compliance and audit?
Yes. Finance, risk, compliance and audit fail at their interfaces — we keep them aligned.
Guide
Board Risk Reporting One-Pager
Related practices: Regulatory Compliance & Governance · Financial Crime & AML Advisory · Audit & Assurance