Solutions
Risk Management

Enterprise & Operational Risk Management

See, assess and treat risk across the whole enterprise

Risk that lives in disconnected registers, spreadsheets and heads cannot be managed as a whole. This programme composes enterprise risk management, operational risk, business continuity and incident management into one framework, so risks are identified, assessed against a consistent scale, mapped to the controls that mitigate them, and tracked to treatment — with a live picture the board can actually see.

At a glance

One programme, on one platform

Enterprise & Operational Risk Management on OnyxOneSchematic
Your teamsCompliance · risk · legalAnalysts & investigatorsScreen, review and decideOversight & approvalsSign-off and reportingOnyxOneCompliance & risk OSScreening · Due diligenceCases · Risk · MonitoringPolicy · Reporting · AuditSystems & sourcesConfigured per deploymentScreening data providersSanctions · PEP · mediaYour systems of recordOnboarding · core systemsOne platform for the whole programme — not a stack of disconnected tools and spreadsheets.

Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.

The programme

What this programme is, and why it matters

A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.

Assessing likelihood against impactSchematic
51015202548121620369121524681012345Likelihood54321Impact12345LowModerateElevatedHighCritical

How the programme scores and prioritises risk so attention lands where exposure is greatest. Values are illustrative.

One risk register, one language

The programme brings enterprise and operational risks onto a single register assessed against one likelihood-and-impact scale, so risks across the business can be compared, aggregated and prioritised rather than living in incompatible local spreadsheets.

Risks, controls and treatment, connected

Every risk is mapped to the controls that mitigate it and the treatment actions that reduce it, so residual risk is visible and the effect of a failing control is traceable — not discovered after an event.

Operational resilience, evidenced

Business continuity, recovery arrangements and incidents are captured in a structured way against the risks they relate to, so operational-resilience evidence exists as a by-product of the work rather than being assembled after a disruption.

A picture the board can see

Because risk, controls and treatment share one record, the programme produces a live, aggregated view of the firm's risk profile against appetite — the picture a board and risk committee need to govern, not a quarter-old snapshot.

The challenge

What makes this hard today

The operational realities this programme is designed to resolve.

Fragmented registers

Risks recorded in local spreadsheets with different scales cannot be aggregated, so no one sees the enterprise picture.

Risks divorced from controls

When the risk register and the control library are separate, the firm cannot tell which controls actually mitigate which risks, or what a control failure exposes.

Assessment inconsistency

Without a shared scale and method, the same risk is scored differently across teams, and prioritisation becomes subjective.

Treatment that stalls

Mitigation actions tracked outside the register lose owners and deadlines, so risks sit above appetite with no progress.

Resilience proven after the fact

Continuity and incident evidence assembled only when a disruption or review demands it is incomplete and hard to defend.

How it works

The operating model, at a glance

How the composed programme runs — from the data it takes in to the decisions and evidence it produces.

A representative flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.

01

Set the framework

Define the risk taxonomy, the likelihood-and-impact scale, appetite thresholds and the roles that own each part.

02

Identify & assess

Capture risks across the enterprise and its operations, and assess them consistently against the shared scale.

03

Map to controls

Link each risk to the controls that mitigate it, so residual risk and control dependency are visible.

04

Treat & track

Assign treatment actions with owners and deadlines, and track risks toward appetite as mitigation lands.

05

Monitor & report

Capture incidents and continuity activity against risks, and report the live enterprise picture to management and the board.

Capabilities

What the programme gives you

The concrete capabilities the composed programme provides, end to end.

Enterprise risk register

One register for risks across the business, assessed against a single likelihood-and-impact scale so they can be compared and aggregated.

Risk-and-control mapping

Link risks to the controls that mitigate them, making residual risk and the exposure of a failing control visible and traceable.

Risk appetite & thresholds

Define appetite and thresholds so the programme flags where risk sits above tolerance and needs treatment or acceptance.

Treatment tracking

Assign mitigation actions with owners and deadlines and track risks toward appetite as treatment is completed.

Business continuity & recovery

Capture continuity and recovery arrangements against the risks they address, so resilience evidence exists before it is needed.

Incident capture

Record incidents against the risks and controls they relate to, closing the loop between what happened and what mitigates it.

The workflow

The end-to-end workflow

A defined process with clear ownership at every stage, captured against the record it belongs to.

The workflow, step by stepSchematic
01IdentifyRisks are captured across the enterprise and its operations against a sharedtaxonomy.02AssessEach risk is scored on the common likelihood-and-impact scale to give inherent risk.03Map controlsRisks are linked to mitigating controls to reveal residual risk against appetite.04TreatTreatment actions are assigned with owners and deadlines where residual risk exceedsappetite.05MonitorIncidents and continuity activity are captured against risks, and controleffectiveness is tracked.06ReportThe live, aggregated risk picture is reported to management and the board againstappetite.

Every result, decision and override is captured against the record it belongs to.

01

Identify

Risks are captured across the enterprise and its operations against a shared taxonomy.

02

Assess

Each risk is scored on the common likelihood-and-impact scale to give inherent risk.

03

Map controls

Risks are linked to mitigating controls to reveal residual risk against appetite.

04

Treat

Treatment actions are assigned with owners and deadlines where residual risk exceeds appetite.

05

Monitor

Incidents and continuity activity are captured against risks, and control effectiveness is tracked.

06

Report

The live, aggregated risk picture is reported to management and the board against appetite.

Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.

Systems of record
  • Ingests operational and loss data from your existing systems to inform risk assessment
Controls & assurance
  • Shares the control library with your assurance programme so risks and controls map to the same objects
Incident & service management
  • Connects to your incident or service-management tooling so operational events land against the right risks
Reporting & analytics
  • Feeds the aggregated risk picture into executive and board reporting
Collaboration & notification
  • Routes risk assessments, treatment actions and reminders through your existing email and messaging tools
Assurance

Security & reporting

Security & data handling

  • Risk, control and incident data are encrypted in transit and at rest.
  • Access to the risk register and sensitive incident data is role-based.
  • Every risk assessment, control mapping, treatment update and incident is written to an append-only audit trail.
  • Changes to the risk scale, appetite and taxonomy are versioned and attributed.
  • Data residency and retention are configurable to your obligations.

Reports & returns

  • Enterprise risk profile against appetite
  • Residual-risk and control-coverage reporting
  • Treatment-action status and overdue reporting
  • Operational-resilience, continuity and incident reporting
  • Executive and board risk management information
The value

What your team gains

The enterprise picture, in one place

A single register on one scale lets the firm see, compare and aggregate risk across the business rather than in fragments.

Residual risk you can trust

Mapping risks to controls makes residual risk visible and shows what a control failure actually exposes.

Treatment that moves

Actions with owners and deadlines on the register keep mitigation progressing toward appetite.

Resilience evidence that already exists

Continuity and incident activity captured as you work means resilience can be shown, not scrambled together after an event.

FAQ

Questions, answered

How is this different from operational risk alone?

Operational risk is one part of it. This programme spans enterprise and operational risk, links them to controls, and adds continuity and incident capture — so the firm manages risk as a connected whole against a single appetite.

Why map risks to controls?

Mapping makes residual risk real: you can see which controls mitigate which risks, what a failing control exposes, and where treatment is genuinely needed rather than assumed.

Does it help with operational resilience?

Yes. Continuity, recovery and incident activity are captured against the risks they relate to, so resilience evidence is a by-product of the work rather than assembled after a disruption.

Can the board see a live picture?

Because risk, controls and treatment share one record, the programme produces an aggregated, current view of the firm's risk profile against appetite for management and the board.

Are SOC 2 or ISO 27001 held?

Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.

Stand up your Enterprise & Operational Risk Management programme

Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.