Enterprise risk assessment with risk register, heat map, mitigation planning, and KRI framework. USE THIS SKILL when the user asks about risk identification, risk register, risk heat map, ERM framework, enterprise risk management, risk appetite, risk tolerance, key risk indicators, risk scoring, risk universe, control effectiveness, residual risk, inherent risk, or "what are our biggest risks." Also trigger when asked to build a risk matrix, assess control effectiveness, design a KRI dashboard, evaluate ERM maturity, or develop a risk mitigation plan for any organization or business unit.
インストール
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
Enterprise risk assessment with risk register, heat map, mitigation planning, and KRI framework. USE THIS SKILL when the user asks about risk identification, risk register, risk heat map, ERM framework, enterprise risk management, risk appetite, risk tolerance, key risk indicators, risk scoring, risk universe, control effectiveness, residual risk, inherent risk, or "what are our biggest risks." Also trigger when asked to build a risk matrix, assess control effectiveness, design a KRI dashboard, evaluate ERM maturity, or develop a risk mitigation plan for any organization or business unit.
Enterprise Risk Assessment
Required Inputs
Organization: Company or business unit name, industry, size (revenue and headcount).
Scope: Full enterprise risk assessment or specific category (Strategic, Operational, Financial, Compliance, Reputational).
Risk Context: Known incidents, near-misses, regulatory findings, audit observations, or strategic changes driving the assessment.
Existing Controls: Current risk management practices, policies, and control frameworks in place (if any).
Stakeholder Access: Availability of leadership, functional heads, and frontline staff for workshops and interviews.
Place risk IDs (R01, R02, etc.) in the appropriate cell based on their residual likelihood and impact scores.
9. Risk Appetite Framework
Define acceptable risk levels by category. Risk appetite is set by the board; risk tolerance is the operational boundary.
Risk Category
Risk Appetite
Risk Tolerance (Max Residual Score)
Rationale
Strategic
Moderate-High
16
Organization accepts strategic risk to pursue growth; no existential bets
Operational
Low-Moderate
12
Operational disruptions must be contained; no prolonged outages
Financial
Low
9
Protect balance sheet; no risk of covenant breach or liquidity crisis
Compliance
Very Low
6
Zero tolerance for regulatory violations or legal non-compliance
Reputational
Low
9
Protect brand; avoid any sustained negative media exposure
Appetite breach protocol: Any risk with a residual score exceeding the tolerance threshold requires a documented risk acceptance by the appropriate authority:
Residual Score vs. Tolerance
Acceptance Authority
Documentation
Within tolerance
Risk owner (management)
Standard risk register entry
1-4 points above tolerance
Senior leadership / C-suite
Written risk acceptance memo with rationale and timeline
5+ points above tolerance
Board / Audit Committee
Board paper with mitigation plan and progress tracking
10. Mitigation Strategy Selection
For each risk requiring mitigation, select from four strategies:
Strategy
Definition
When to Use
Example
Accept
Consciously accept the risk without additional mitigation
Risk is within appetite; cost of mitigation exceeds expected loss; risk is inherent to the business model
Accepting competitive risk in a mature market
Mitigate
Implement controls to reduce likelihood, impact, or both
Risk exceeds appetite and can be reduced to acceptable level with reasonable investment
Installing backup generators; implementing fraud detection system
Transfer
Shift risk to a third party through insurance, contract, or outsourcing
Risk is insurable; contractual risk allocation is possible; outsourcing transfers operational risk
Purchasing cyber insurance; contractual indemnities; outsourcing IT operations
Avoid
Eliminate the risk by changing strategy, exiting a market, or stopping an activity
Risk is unacceptable and cannot be mitigated or transferred at reasonable cost
Exiting a market with unmanageable regulatory risk; discontinuing a product line
Mitigation plan template per risk:
Element
Detail
Risk ID
R-XX
Current residual score
XX (Likelihood X x Impact X)
Target residual score
XX (Likelihood X x Impact X)
Strategy
Accept / Mitigate / Transfer / Avoid
Specific actions
[Numbered list of mitigation actions]
Owner
[Role — not individual name]
Timeline
[Start date — completion date]
Cost estimate
$[X]
Dependencies
[Other actions, approvals, or resources required]
Success measure
[How will we know the mitigation worked?]
11. Key Risk Indicators (KRIs)
Design KRIs with threshold-based alerting for continuous risk monitoring:
Risk
KRI
Green (Normal)
Amber (Elevated)
Red (Critical)
Frequency
Owner
Cyber breach
Failed login attempts per day
<100
100-500
>500
Daily
CISO
Cyber breach
Days since last penetration test
<90
90-180
>180
Monthly
CISO
Customer concentration
Revenue from top customer (%)
<15%
15-25%
>25%
Quarterly
CCO
Talent attrition
Voluntary turnover rate (annualized)
<10%
10-18%
>18%
Monthly
CHRO
Liquidity
Days cash on hand
>90
60-90
<60
Weekly
CFO
Regulatory
Open audit findings (past due)
0
1-3
>3
Monthly
CCO/GC
Operational
System uptime (%)
>99.5%
99.0-99.5%
<99.0%
Weekly
CTO
Supply chain
Supplier on-time delivery rate
>95%
90-95%
<90%
Monthly
COO
Financial reporting
Adjusting journal entries per close
<5
5-15
>15
Monthly
CFO
Reputation
Social media sentiment score
>0.7
0.5-0.7
<0.5
Weekly
CMO
KRI design principles:
Each KRI must be measurable with available data (do not design KRIs that cannot be collected).
Green/Amber/Red thresholds must be calibrated to the organization's risk appetite.
Amber = investigate and prepare; Red = escalate and act.
Review thresholds semi-annually; recalibrate based on trends and incidents.
12. Risk Reporting and Governance
Reporting Level
Audience
Frequency
Content
Format
Operational
Risk owners, functional teams
Weekly / Monthly
KRI dashboard; incident reports; control test results
Dashboard with drill-down
Management
C-suite, risk committee
Monthly
Top 10 risks; KRI summary; new/emerging risks; mitigation progress
Risk report (3-5 pages)
Board / Audit Committee
Board members
Quarterly
Risk heat map; appetite breaches; material incidents; ERM maturity progress