Enterprise Risk Management
One register, one taxonomy, one view of risk across the enterprise
A single system of record for identifying, assessing, treating and monitoring risk across every business unit, geography and function. OnyxOne ERM replaces disconnected spreadsheets and siloed registers with a shared risk taxonomy, a live risk register, configurable assessment methodologies and board-ready reporting — so the same risk means the same thing everywhere, and leadership sees the true, aggregated picture.
How it works, visually
An illustrative 5×5 likelihood × impact heatmap — the kind of view risk teams work from. Values are an example.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Risk lives in spreadsheets nobody trusts
Most enterprises manage risk in dozens of disconnected spreadsheets owned by different teams. Versions drift, scoring is inconsistent, and by the time a register reaches the board it is already out of date. Leadership cannot answer a simple question — what are our top risks right now — with confidence.
No shared language for risk
When each function invents its own categories, scales and definitions, risks cannot be compared or aggregated. A 'high' risk in one unit is a 'medium' in another, and the same underlying exposure is recorded three different ways. Enterprise-level rollups become guesswork rather than evidence.
Assessments are point-in-time, not continuous
Annual risk workshops capture a snapshot and then go stale. Between cycles, new risks emerge, controls degrade and appetite is breached without anyone noticing until an incident forces the issue. The organisation is always reacting to yesterday's risk picture.
Risk and controls are managed separately
Risk registers and control frameworks are often owned by different teams in different tools, so there is no reliable line of sight from a risk to the controls that are supposed to mitigate it, or to whether those controls actually work. Residual risk is asserted, not evidenced.
Appetite exists on paper only
Boards approve a risk-appetite statement, but nothing connects it to day-to-day operations. Limits and tolerances are not enforced, breaches are not surfaced automatically, and the appetite statement becomes a document rather than a live control.
How OnyxOne addresses it
A single enterprise risk register
Every risk — strategic, financial, operational, compliance, technology, third-party — is captured once in a shared register with a common structure: cause, event, consequence, owner, category, inherent and residual scoring, linked controls and treatment plan. One record, one owner, one source of truth.
A configurable risk taxonomy and scoring model
You define the taxonomy, impact and likelihood scales, scoring matrix and heat-map thresholds to match your own methodology — qualitative, quantitative or hybrid. OnyxOne enforces that model consistently across every unit, so scores are comparable and roll up cleanly to the enterprise view.
Risks linked directly to controls
Each risk is mapped to the controls that mitigate it, and residual risk is calculated from control design and operating effectiveness rather than being typed in by hand. When a control fails testing, the residual risk it supports is flagged for reassessment automatically.
Appetite and tolerance made operational
Risk-appetite statements, limits and tolerances are configured against categories and individual risks. When an assessment or a monitored indicator crosses a threshold, the breach is surfaced to the owner and to oversight — appetite becomes an active guardrail, not a filed statement.
Aggregation and board-ready reporting
Risks roll up the organisational hierarchy into heat maps, top-risk registers and trend views. Committee and board packs are generated from the live register, so what leadership reviews is the current position with a full audit trail of how it changed.
What's in the module
Turn on what you need and add more as your programme scales.
Enterprise risk register
A central, structured register with cause–event–consequence modelling, ownership, categories and lifecycle status.
Configurable methodology
Define your own impact/likelihood scales, scoring matrix, heat-map bands and inherent-vs-residual logic.
Risk taxonomy & hierarchy
A shared taxonomy and organisational hierarchy so risks aggregate consistently across units and geographies.
Risk & control association
Map risks to controls and derive residual risk from control effectiveness rather than manual entry.
Risk-appetite & tolerance
Set appetite, limits and tolerances by category or risk, with automatic breach detection.
Key risk indicators (KRIs)
Track leading indicators against thresholds and link movements to the risks they signal.
Assessment campaigns
Launch periodic or ad-hoc assessment cycles with assigned owners, due dates and reminders.
Treatment & action plans
Capture accept / mitigate / transfer / avoid decisions with owners, milestones and target dates.
Heat maps & dashboards
Interactive heat maps, top-risk views and trend analysis at every level of the hierarchy.
Immutable history
Every score change, treatment decision and reassessment is versioned and preserved for audit.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Identify & register
Risks are captured into the register from workshops, control failures, incidents, audit findings and business-as-usual, each structured with cause, event, consequence, owner and category.
Assess inherent risk
Owners score inherent impact and likelihood against your defined scales, placing each risk on the enterprise heat map before mitigation is considered.
Map controls & derive residual
Mitigating controls are linked to each risk, and residual risk is derived from control design and tested operating effectiveness rather than asserted.
Decide treatment
For risks outside appetite, owners record a treatment decision — accept, mitigate, transfer or avoid — with an action plan, owner and target date.
Monitor indicators & appetite
Key risk indicators and appetite thresholds are tracked continuously, surfacing breaches and emerging exposures between formal assessment cycles.
Aggregate & report
Risks roll up the hierarchy into committee and board reporting, with a full audit trail of how the enterprise risk profile changed over the period.
What your team gains
One trusted risk picture
Replace scattered spreadsheets with one live register, so leadership can answer 'what are our top risks' from a single, current, auditable source.
Comparable, aggregatable scoring
A shared taxonomy and scoring model means risks mean the same thing everywhere and roll up cleanly to the enterprise view.
Always-current, not annual
Indicators, appetite breaches and control failures update the picture between cycles, so the register reflects reality rather than last year's workshop.
Residual risk you can defend
Residual risk is derived from tested control effectiveness and captured with a full history, so it withstands challenge from audit and the board.
Clear ownership and accountability
Every risk, control and action has a named owner and due date, making follow-through visible rather than optional.
Faster, credible board reporting
Committee and board packs are assembled from the live register, cutting manual preparation and eliminating stale or reconciled-by-hand numbers.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Connects to your internal-controls and audit modules so residual risk reflects real control testing
- Ingests operational incidents and loss events from your incident and case systems to inform risk scoring
- Aligns risk and action ownership with your existing identity provider and HR directory for accurate accountability
- Exports the register and metrics to your existing BI and data-warehouse tools for wider analysis
- Routes assessment tasks, breaches and reminders through your existing email and messaging channels
Security, compliance & reporting
Security & data handling
- Risk data is encrypted in transit and at rest, with access governed by granular, role-based permissions.
- Segregation of duties can prevent the same person from both owning and signing off a risk assessment where policy requires it.
- Every score change, treatment decision and reassessment is written to an append-only audit trail.
- Confidential or board-sensitive risks can be restricted to named roles and hidden from wider rollups where required.
- Data residency and retention for the risk register are configurable to your regulatory obligations.
Compliance support
- Supports enterprise risk-management practice aligned to recognised frameworks such as COSO ERM and ISO 31000
- Underpins operational-resilience and operational-risk obligations for regulated firms
- Provides the risk-assessment evidence expected under AML and financial-crime regimes
- Feeds governance and three-lines-of-defence oversight expectations
- Supplies documented, dated evidence for internal audit and external regulatory review
Reports & exports
- Enterprise and unit-level risk registers (current and point-in-time)
- Risk heat maps and top-risk reports by category and hierarchy
- Risk-appetite and tolerance breach reports
- Key-risk-indicator dashboards and trend analysis
- Treatment / action-plan status and overdue-action reports
- Committee and board risk packs with change history
How to get the most from it
Agree the taxonomy before you scale
Fix a shared risk taxonomy and scoring model up front. Consistent definitions are what make enterprise aggregation meaningful; retrofitting them later is painful.
Derive residual risk, don't type it
Link risks to controls and let residual risk follow tested control effectiveness. A residual score that isn't backed by control evidence will not survive scrutiny.
Make appetite operational
Translate the board's appetite statement into concrete limits and tolerances the platform can monitor, so breaches surface automatically instead of at year-end.
Keep the register live
Feed incidents, audit findings and indicator movements into the register continuously. A register only reviewed annually is a document, not a control.
Questions, answered
Can we keep our own risk methodology?
Yes. You configure the taxonomy, impact and likelihood scales, scoring matrix, heat-map bands and inherent-versus-residual logic. OnyxOne enforces your model consistently rather than imposing a fixed one.
How does residual risk get calculated?
Each risk is linked to its mitigating controls, and residual risk is derived from control design and tested operating effectiveness. When a linked control fails testing, the affected residual risk is flagged for reassessment automatically.
Does this connect risk to controls and audit?
Yes. Risks map to the internal-controls and audit modules, so control testing and audit findings feed directly into the risk picture rather than living in a separate silo.
How is risk appetite enforced?
You set appetite, limits and tolerances against categories or individual risks. When an assessment or a monitored indicator crosses a threshold, the breach is surfaced to the risk owner and to oversight.
Can different business units see only their own risks?
Yes. Role-based permissions and the organisational hierarchy control visibility, so units see their own register while oversight sees the aggregated enterprise view. Sensitive risks can be further restricted.
Related modules
See Enterprise Risk Management in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.