Platform
Enterprise & Operational Risk

Enterprise Risk Management

One register, one taxonomy, one view of risk across the enterprise

A single system of record for identifying, assessing, treating and monitoring risk across every business unit, geography and function. OnyxOne ERM replaces disconnected spreadsheets and siloed registers with a shared risk taxonomy, a live risk register, configurable assessment methodologies and board-ready reporting — so the same risk means the same thing everywhere, and leadership sees the true, aggregated picture.

At a glance

How it works, visually

Risk assessment at a glanceIllustrative
51015202548121620369121524681012345Likelihood54321Impact12345LowModerateElevatedHighCritical

An illustrative 5×5 likelihood × impact heatmap — the kind of view risk teams work from. Values are an example.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Risk lives in spreadsheets nobody trusts

Most enterprises manage risk in dozens of disconnected spreadsheets owned by different teams. Versions drift, scoring is inconsistent, and by the time a register reaches the board it is already out of date. Leadership cannot answer a simple question — what are our top risks right now — with confidence.

No shared language for risk

When each function invents its own categories, scales and definitions, risks cannot be compared or aggregated. A 'high' risk in one unit is a 'medium' in another, and the same underlying exposure is recorded three different ways. Enterprise-level rollups become guesswork rather than evidence.

Assessments are point-in-time, not continuous

Annual risk workshops capture a snapshot and then go stale. Between cycles, new risks emerge, controls degrade and appetite is breached without anyone noticing until an incident forces the issue. The organisation is always reacting to yesterday's risk picture.

Risk and controls are managed separately

Risk registers and control frameworks are often owned by different teams in different tools, so there is no reliable line of sight from a risk to the controls that are supposed to mitigate it, or to whether those controls actually work. Residual risk is asserted, not evidenced.

Appetite exists on paper only

Boards approve a risk-appetite statement, but nothing connects it to day-to-day operations. Limits and tolerances are not enforced, breaches are not surfaced automatically, and the appetite statement becomes a document rather than a live control.

The approach

How OnyxOne addresses it

A single enterprise risk register

Every risk — strategic, financial, operational, compliance, technology, third-party — is captured once in a shared register with a common structure: cause, event, consequence, owner, category, inherent and residual scoring, linked controls and treatment plan. One record, one owner, one source of truth.

A configurable risk taxonomy and scoring model

You define the taxonomy, impact and likelihood scales, scoring matrix and heat-map thresholds to match your own methodology — qualitative, quantitative or hybrid. OnyxOne enforces that model consistently across every unit, so scores are comparable and roll up cleanly to the enterprise view.

Risks linked directly to controls

Each risk is mapped to the controls that mitigate it, and residual risk is calculated from control design and operating effectiveness rather than being typed in by hand. When a control fails testing, the residual risk it supports is flagged for reassessment automatically.

Appetite and tolerance made operational

Risk-appetite statements, limits and tolerances are configured against categories and individual risks. When an assessment or a monitored indicator crosses a threshold, the breach is surfaced to the owner and to oversight — appetite becomes an active guardrail, not a filed statement.

Aggregation and board-ready reporting

Risks roll up the organisational hierarchy into heat maps, top-risk registers and trend views. Committee and board packs are generated from the live register, so what leadership reviews is the current position with a full audit trail of how it changed.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Enterprise risk register

A central, structured register with cause–event–consequence modelling, ownership, categories and lifecycle status.

Configurable methodology

Define your own impact/likelihood scales, scoring matrix, heat-map bands and inherent-vs-residual logic.

Risk taxonomy & hierarchy

A shared taxonomy and organisational hierarchy so risks aggregate consistently across units and geographies.

Risk & control association

Map risks to controls and derive residual risk from control effectiveness rather than manual entry.

Risk-appetite & tolerance

Set appetite, limits and tolerances by category or risk, with automatic breach detection.

Key risk indicators (KRIs)

Track leading indicators against thresholds and link movements to the risks they signal.

Assessment campaigns

Launch periodic or ad-hoc assessment cycles with assigned owners, due dates and reminders.

Treatment & action plans

Capture accept / mitigate / transfer / avoid decisions with owners, milestones and target dates.

Heat maps & dashboards

Interactive heat maps, top-risk views and trend analysis at every level of the hierarchy.

Immutable history

Every score change, treatment decision and reassessment is versioned and preserved for audit.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Identify & registerRisks are captured into the register from workshops, control failures, incidents,audit findings and business-as-usual, each structured with cause, event,…02Assess inherent riskOwners score inherent impact and likelihood against your defined scales, placingeach risk on the enterprise heat map before mitigation is considered.03Map controls & derive residualMitigating controls are linked to each risk, and residual risk is derived fromcontrol design and tested operating effectiveness rather than asserted.04Decide treatmentFor risks outside appetite, owners record a treatment decision — accept, mitigate,transfer or avoid — with an action plan, owner and target date.05Monitor indicators & appetiteKey risk indicators and appetite thresholds are tracked continuously, surfacingbreaches and emerging exposures between formal assessment cycles.06Aggregate & reportRisks roll up the hierarchy into committee and board reporting, with a full audittrail of how the enterprise risk profile changed over the period.

Every result, decision and override is captured against the record it belongs to.

01

Identify & register

Risks are captured into the register from workshops, control failures, incidents, audit findings and business-as-usual, each structured with cause, event, consequence, owner and category.

02

Assess inherent risk

Owners score inherent impact and likelihood against your defined scales, placing each risk on the enterprise heat map before mitigation is considered.

03

Map controls & derive residual

Mitigating controls are linked to each risk, and residual risk is derived from control design and tested operating effectiveness rather than asserted.

04

Decide treatment

For risks outside appetite, owners record a treatment decision — accept, mitigate, transfer or avoid — with an action plan, owner and target date.

05

Monitor indicators & appetite

Key risk indicators and appetite thresholds are tracked continuously, surfacing breaches and emerging exposures between formal assessment cycles.

06

Aggregate & report

Risks roll up the hierarchy into committee and board reporting, with a full audit trail of how the enterprise risk profile changed over the period.

The value

What your team gains

Single source of truth

One trusted risk picture

Replace scattered spreadsheets with one live register, so leadership can answer 'what are our top risks' from a single, current, auditable source.

Consistent

Comparable, aggregatable scoring

A shared taxonomy and scoring model means risks mean the same thing everywhere and roll up cleanly to the enterprise view.

Continuous

Always-current, not annual

Indicators, appetite breaches and control failures update the picture between cycles, so the register reflects reality rather than last year's workshop.

Evidenced

Residual risk you can defend

Residual risk is derived from tested control effectiveness and captured with a full history, so it withstands challenge from audit and the board.

Clear ownership and accountability

Every risk, control and action has a named owner and due date, making follow-through visible rather than optional.

Faster, credible board reporting

Committee and board packs are assembled from the live register, cutting manual preparation and eliminating stale or reconciled-by-hand numbers.

Built for

Industries it serves

Financial ServicesBankingInsuranceInvestment FirmsFintechRegulated EnterprisesCorporate & Trust Service ProvidersGaming
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Controls & audit
  • Connects to your internal-controls and audit modules so residual risk reflects real control testing
Incident & loss data
  • Ingests operational incidents and loss events from your incident and case systems to inform risk scoring
Identity & directory
  • Aligns risk and action ownership with your existing identity provider and HR directory for accurate accountability
Business intelligence
  • Exports the register and metrics to your existing BI and data-warehouse tools for wider analysis
Collaboration & notification
  • Routes assessment tasks, breaches and reminders through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Risk data is encrypted in transit and at rest, with access governed by granular, role-based permissions.
  • Segregation of duties can prevent the same person from both owning and signing off a risk assessment where policy requires it.
  • Every score change, treatment decision and reassessment is written to an append-only audit trail.
  • Confidential or board-sensitive risks can be restricted to named roles and hidden from wider rollups where required.
  • Data residency and retention for the risk register are configurable to your regulatory obligations.

Compliance support

  • Supports enterprise risk-management practice aligned to recognised frameworks such as COSO ERM and ISO 31000
  • Underpins operational-resilience and operational-risk obligations for regulated firms
  • Provides the risk-assessment evidence expected under AML and financial-crime regimes
  • Feeds governance and three-lines-of-defence oversight expectations
  • Supplies documented, dated evidence for internal audit and external regulatory review

Reports & exports

  • Enterprise and unit-level risk registers (current and point-in-time)
  • Risk heat maps and top-risk reports by category and hierarchy
  • Risk-appetite and tolerance breach reports
  • Key-risk-indicator dashboards and trend analysis
  • Treatment / action-plan status and overdue-action reports
  • Committee and board risk packs with change history
Best practice

How to get the most from it

Agree the taxonomy before you scale

Fix a shared risk taxonomy and scoring model up front. Consistent definitions are what make enterprise aggregation meaningful; retrofitting them later is painful.

Derive residual risk, don't type it

Link risks to controls and let residual risk follow tested control effectiveness. A residual score that isn't backed by control evidence will not survive scrutiny.

Make appetite operational

Translate the board's appetite statement into concrete limits and tolerances the platform can monitor, so breaches surface automatically instead of at year-end.

Keep the register live

Feed incidents, audit findings and indicator movements into the register continuously. A register only reviewed annually is a document, not a control.

FAQ

Questions, answered

Can we keep our own risk methodology?

Yes. You configure the taxonomy, impact and likelihood scales, scoring matrix, heat-map bands and inherent-versus-residual logic. OnyxOne enforces your model consistently rather than imposing a fixed one.

How does residual risk get calculated?

Each risk is linked to its mitigating controls, and residual risk is derived from control design and tested operating effectiveness. When a linked control fails testing, the affected residual risk is flagged for reassessment automatically.

Does this connect risk to controls and audit?

Yes. Risks map to the internal-controls and audit modules, so control testing and audit findings feed directly into the risk picture rather than living in a separate silo.

How is risk appetite enforced?

You set appetite, limits and tolerances against categories or individual risks. When an assessment or a monitored indicator crosses a threshold, the breach is surfaced to the risk owner and to oversight.

Can different business units see only their own risks?

Yes. Role-based permissions and the organisational hierarchy control visibility, so units see their own register while oversight sees the aggregated enterprise view. Sensitive risks can be further restricted.

See Enterprise Risk Management in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.