Blog

Risk management, explained.

Practical guides for risk and compliance teams — how to build the fundamentals well, and how to think about enterprise risk the COSO way.

EXPLAINER · 8 min read · September 2026

Inherent vs residual risk, with worked examples

Two numbers, one risk. What each actually means, how control effectiveness moves the score, and three worked examples with the arithmetic shown.

GUIDE · 7 min read · August 2026

How to build a risk register (step by step)

From identifying and describing risks to scoring inherent and residual risk, mapping controls, and keeping the register alive — the eight steps that make a register people actually use.

GUIDE · 6 min read · August 2026

How to set risk appetite and tolerance

Turn vague intent into measurable boundaries — appetite levels, tolerance thresholds, KRIs and escalation triggers — with a worked example.

GUIDE · 6 min read · August 2026

How to choose KRIs that actually work

Leading vs lagging indicators, tying each KRI to a real risk, setting green/amber/red thresholds, and making breaches impossible to miss.

EXPLAINER · 7 min read · August 2026

COSO ERM 2017 explained: the five components

A plain-English tour of the COSO ERM framework — governance & culture, strategy, performance, review, and reporting — and how to put it into practice.

More guides on the way — governance, controls, incident management and risk quantification. Want us to cover something specific? Tell us →

Put the theory to work

See these fundamentals as a living, mobile, bilingual risk program.