Inherent vs residual risk, with worked examples
Two numbers, one risk. What each actually means, how control effectiveness moves the score, and three worked examples with the arithmetic shown.
Practical guides for risk and compliance teams — how to build the fundamentals well, and how to think about enterprise risk the COSO way.
Two numbers, one risk. What each actually means, how control effectiveness moves the score, and three worked examples with the arithmetic shown.
Structure, origins, terminology and the certification question people get wrong — plus why treating the choice as binary is the real mistake.
From identifying and describing risks to scoring inherent and residual risk, mapping controls, and keeping the register alive — the eight steps that make a register people actually use.
Turn vague intent into measurable boundaries — appetite levels, tolerance thresholds, KRIs and escalation triggers — with a worked example.
Leading vs lagging indicators, tying each KRI to a real risk, setting green/amber/red thresholds, and making breaches impossible to miss.
A plain-English tour of the COSO ERM framework — governance & culture, strategy, performance, review, and reporting — and how to put it into practice.
More guides on the way — governance, controls, incident management and risk quantification. Want us to cover something specific? Tell us →
See these fundamentals as a living, mobile, bilingual risk program.