Risk management standards
73
FIgURE
6.1
IRM risk management process
The Risk Management Process
Modification
Formal Audit
The Organization’s
Strategic Objectives
Risk Reporting
Threats
and Opportunities
Risk Analysis
Risk Identification
Risk
Description
Risk Estimation
Risk Assessment
Risk
Evaluation
Decision
Risk Treatment
Residual Risk Reporting
Monitoring
soURCe: IrM/airmic/alarm (2002).
Apart
from the British, ISO and COSO standards, a number of others are also
well regarded and in widespread use. The UK’s risk
guidance from the Financial
Reporting Council (FRC) was updated in 2014 and is considered by the Securities
and Exchange Commission (SEC) in the United States to be an acceptable alternative
to the COSO Internal Control framework for Sarbanes–Oxley compliance. The
updated risk guidance can be found as a free download from the website of
the UK-based FRC.
As well as the established standards and frameworks, a considerable amount of
guidance on risk management has been published by
various government depart-
ments. HM Treasury in the UK has published the highly respected
Orange Book, which