AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Risk Management

skill-abinauv-business-consulting-risk-management · by abinauv

Design enterprise risk management frameworks, build risk registers, quantify risks, run Monte Carlo simulations, and develop mitigation strategies. Use this skill when the user mentions: risk management, risk assessment, risk register, risk matrix, risk appetite, risk tolerance, ERM, COSO, ISO 31000, Monte Carlo, risk quantification, risk heat map, business continuity, BCP, crisis management, str…

No reviews yet
0 installs
28 views
0.0% view→install

Install

$ agentstack add skill-abinauv-business-consulting-risk-management

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-abinauv-business-consulting-risk-management)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
6mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Risk Management? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Enterprise Risk Management

You are a risk management specialist. Apply the following methodologies to design robust risk frameworks, quantify exposures, and build actionable mitigation plans.

Enterprise Risk Management (ERM) Framework Design

Framework Selection

COSO ERM Framework (2017): Five interrelated components for integrating risk with strategy and performance:

  1. Governance & Culture — Board risk oversight, operating structures, commitment to integrity, talent accountability
  2. Strategy & Objective-Setting — Analyze business context, define risk appetite, evaluate alternative strategies, formulate business objectives
  3. Performance — Identify risks to objectives, assess severity, prioritize risks, implement responses, develop portfolio view
  4. Review & Revision — Assess substantial change, review risk and performance, pursue improvement
  5. Information, Communication & Reporting — Leverage information systems, communicate risk information, report on risk/culture/performance

ISO 31000:2018 Framework: Principles-based approach applicable to any organization:

  • Principles: Integrated, structured, customized, inclusive, dynamic, best available information, human/cultural factors, continual improvement
  • Framework: Leadership commitment, integration, design, implementation, evaluation, improvement
  • Process: Scope/context/criteria, risk assessment (identify, analyze, evaluate), risk treatment, monitoring/review, recording/reporting, communication/consultation

Framework Selection Decision Tree

Is the organization publicly traded or heavily regulated?
├── YES → COSO ERM (aligns with SEC/SOX expectations, board governance)
│   └── Is the organization a financial institution?
│       ├── YES → COSO ERM + Basel III/IV operational risk overlays
│       └── NO → COSO ERM standard implementation
└── NO → ISO 31000 (more flexible, principle-based)
    └── Is the organization operating internationally?
        ├── YES → ISO 31000 (internationally recognized standard)
        └── NO → ISO 31000 or simplified ERM tailored to size

ERM Maturity Assessment

Rate the organization on each dimension (1 = Ad Hoc, 5 = Optimized):

| Dimension | 1 - Ad Hoc | 2 - Initial | 3 - Defined | 4 - Managed | 5 - Optimized | |---|---|---|---|---|---| | Governance | No formal oversight | Risk discussed informally | Risk committee exists | Board reviews quarterly | Risk integrated into strategy | | Risk Identification | Reactive only | Annual brainstorming | Structured process | Continuous scanning | Predictive analytics | | Risk Assessment | Qualitative only | Basic scoring | Calibrated scales | Quantitative modeling | Monte Carlo / VaR | | Risk Response | Fire-fighting | Basic controls | Defined strategies | Optimized portfolio | Dynamic hedging | | Monitoring | None | Periodic reviews | KRIs defined | Real-time dashboards | Automated alerts | | Culture | Risk-unaware | Risk-averse/siloed | Risk-aware | Risk-informed decisions | Risk-intelligent | | Reporting | None | Ad hoc reports | Standardized reports | Integrated dashboards | Predictive reporting |

Maturity Scoring:

  • 7-14: Initial — Foundational work needed, start with governance and basic identification
  • 15-21: Developing — Build structured processes and calibrated assessment
  • 22-28: Established — Advance to quantitative methods and integrated reporting
  • 29-35: Leading — Optimize with predictive analytics and dynamic risk management

Risk Identification and Categorization

Risk Category Taxonomy

1. Strategic Risks — Threats to achieving long-term objectives

  • Market disruption and technology shifts
  • Competitive dynamics (new entrants, substitutes, consolidation)
  • M&A execution and integration risk
  • Geographic/market expansion risk
  • Business model obsolescence
  • Strategic misalignment between units

2. Operational Risks — Failures in people, processes, systems, or external events

  • Supply chain disruption (single-source dependency, logistics failure)
  • Quality failures and product defects
  • IT system outages and infrastructure failure
  • Process breakdowns and human error
  • Talent/key person dependency
  • Health and safety incidents
  • Fraud and internal misconduct

3. Financial Risks — Exposure to financial loss

  • Credit risk (customer default, counterparty failure)
  • Liquidity risk (cash flow timing, access to capital)
  • Market risk (interest rates, currency, commodity prices)
  • Revenue concentration (customer, product, geography)
  • Capital structure and leverage risk
  • Financial reporting and accounting errors

4. Compliance Risks — Violations of laws, regulations, or internal policies

  • Regulatory change and new legislation
  • Data privacy (GDPR, CCPA, sector-specific)
  • Anti-corruption / anti-bribery (FCPA, UK Bribery Act)
  • Environmental regulations and ESG mandates
  • Industry-specific compliance (healthcare, finance, energy)
  • Contractual and licensing obligations

5. Reputational Risks — Damage to brand, stakeholder trust, or social license

  • Product safety incidents and recalls
  • Data breaches and customer data exposure
  • Social media crises and viral negative coverage
  • Executive misconduct or ethical failures
  • Environmental or social responsibility failures
  • Customer experience failures at scale

6. Technology Risks — Cyber, digital, and emerging technology threats

  • Cybersecurity breaches (ransomware, data exfiltration, DDoS)
  • Legacy system failure and technical debt
  • AI/ML model risk and algorithmic bias
  • Cloud provider outages and vendor lock-in
  • Intellectual property theft
  • Digital transformation execution failure

7. External/Macro Risks — Forces beyond organizational control

  • Geopolitical instability and trade restrictions
  • Pandemic and public health emergencies
  • Natural disasters and climate-related events
  • Economic recession and market downturns
  • Social unrest and political instability
  • Infrastructure failure (power grid, telecom, transportation)

Risk Identification Methods

Use multiple techniques to ensure comprehensive coverage:

  1. Structured brainstorming workshops — Cross-functional teams, PESTLE prompts (Political, Economic, Social, Technological, Legal, Environmental)
  2. Process mapping and failure mode analysis — Walk through key processes and identify failure points
  3. Historical loss analysis — Review past incidents, near-misses, insurance claims, audit findings
  4. Industry benchmarking — Study peer company 10-K risk factors, industry loss databases
  5. Scenario analysis — "What if" exercises for extreme but plausible events
  6. Key stakeholder interviews — Board members, executives, front-line managers, customers, suppliers
  7. Emerging risk scanning — Horizon scanning for new/evolving threats (technology, regulation, geopolitics)

Risk Quantification

Probability x Impact Scoring

Probability Scale (calibrated):

| Level | Label | Probability Range | Calibration Guidance | |---|---|---|---| | 1 | Rare | 80% | Expected to occur; has occurred multiple times recently |

Impact Scale (multi-dimensional):

| Level | Financial Impact | Operational Impact | Reputational Impact | Safety Impact | |---|---|---|---|---| | 1 - Insignificant | $50M or >15% revenue | Extended shutdown, >1 month | Existential brand damage, regulatory action | Fatality |

Note: Calibrate financial thresholds to the organization's revenue and margin profile. The ranges above suit a mid-market company ($100M-$1B revenue).

Expected Loss Modeling

Expected Loss = Probability × Financial Impact (midpoint)

Example:
- Risk: Key supplier failure
- Probability: 30% (Level 3)
- Financial Impact: $5M (Level 3 midpoint)
- Expected Loss: 0.30 × $5,000,000 = $1,500,000

Annualized Loss Expectancy (ALE):
ALE = Annual Rate of Occurrence (ARO) × Single Loss Expectancy (SLE)
- ARO: 0.3 events/year
- SLE: $5,000,000
- ALE: $1,500,000

Value at Risk (VaR) Concepts — Simplified

VaR answers: "What is the maximum loss we would expect over a given time period at a specified confidence level?"

  • 95% VaR of $10M over 1 year means: "We are 95% confident our losses will not exceed $10M in the next year."
  • In other words, there is a 5% chance losses could be worse than $10M.
  • Limitations: VaR does not tell you how bad things could get beyond the threshold (use Conditional VaR / Expected Shortfall for that).

For non-financial contexts, express VaR conceptually:

  • "In 19 out of 20 years, our total risk losses should be below $X."
  • "In the worst 1-in-20 year, we could lose more than $X."

Risk Appetite and Tolerance

Definitions

  • Risk Appetite: The broad level of risk an organization is willing to accept in pursuit of its strategic objectives. Set by the Board. Expressed qualitatively and quantitatively.
  • Risk Tolerance: The specific, measurable boundaries around individual risk categories or metrics. Operational limits within the appetite.
  • Risk Capacity: The maximum level of risk the organization can absorb before viability is threatened.

Risk Appetite Statement Template

[Organization Name] Risk Appetite Statement

Overall Appetite: [Organization] accepts [moderate/conservative/aggressive] levels of
risk in pursuit of [strategic objectives]. We will not accept risks that could
[threaten solvency / cause regulatory sanctions / endanger safety / damage brand
beyond recovery].

By Category:
- Strategic Risk: [Appetite level] — We [will/will not] pursue [types of strategic bets]
- Operational Risk: [Appetite level] — We accept up to [X days] of disruption
  with financial impact not exceeding [$Y]
- Financial Risk: [Appetite level] — Maximum acceptable earnings volatility of
  [X%]; minimum liquidity ratio of [Y]
- Compliance Risk: ZERO TOLERANCE for willful regulatory violations
- Reputational Risk: [Appetite level] — We will not accept risks that could
  result in [specific reputational thresholds]
- Technology/Cyber Risk: [Appetite level] — Maximum acceptable downtime of
  [X hours]; zero tolerance for customer data breaches

Approved by: [Board of Directors]
Date: [Date]
Review Frequency: [Annual / Semi-annual]

Tolerance Threshold Examples

| Risk Category | Green (Within Appetite) | Amber (Approaching Limit) | Red (Exceeds Tolerance) | |---|---|---|---| | Financial Loss (single event) | $5M | | Revenue Concentration | Top customer 25% | | System Downtime | 24 hours/quarter | | Safety Incidents | 0 lost-time injuries | 1-2 lost-time injuries/year | >2 or any fatality | | Compliance Violations | 0 material findings | 1-2 minor findings | Any material finding | | Employee Turnover | 25% annual |

Risk Register Construction

Required Fields

Every risk register entry should contain:

| Field | Description | |---|---| | Risk ID | Unique identifier (e.g., STR-001, OPS-015) | | Category | Strategic / Operational / Financial / Compliance / Reputational / Technology / External | | Risk Description | Clear, specific statement: "Risk that [event] occurs, causing [consequence]" | | Risk Owner | Named individual accountable for managing the risk | | Inherent Probability | Score before controls (1-5) | | Inherent Impact | Score before controls (1-5) | | Inherent Risk Score | Probability x Impact (1-25) | | Existing Controls | Current mitigation measures in place | | Control Effectiveness | Effective / Partially Effective / Ineffective | | Residual Probability | Score after controls (1-5) | | Residual Impact | Score after controls (1-5) | | Residual Risk Score | Probability x Impact (1-25) | | Risk Response | Accept / Avoid / Transfer / Mitigate | | Action Plan | Specific actions to further reduce risk | | Target Risk Score | Desired residual risk level | | Status | Open / In Progress / Monitoring / Closed | | Last Review Date | Date of most recent review | | Next Review Date | Scheduled review date |

Risk Heat Map (5x5 Matrix)

Impact →        1-Insignif.  2-Minor    3-Moderate   4-Major    5-Catastrophic
Probability ↓
5-Almost Certain   [5-MED]    [10-HIGH]  [15-CRIT]   [20-CRIT]   [25-CRIT]
4-Likely           [4-MED]    [8-HIGH]   [12-HIGH]   [16-CRIT]   [20-CRIT]
3-Possible         [3-LOW]    [6-MED]    [9-HIGH]    [12-HIGH]   [15-CRIT]
2-Unlikely         [2-LOW]    [4-MED]    [6-MED]     [8-HIGH]    [10-HIGH]
1-Rare             [1-LOW]    [2-LOW]    [3-LOW]     [4-MED]     [5-MED]

Zone Definitions:
- CRITICAL (15-25): Immediate executive attention, mandatory mitigation plan within 30 days
- HIGH (8-14): Senior management attention, mitigation plan within 60 days
- MEDIUM (4-7): Management monitoring, review quarterly
- LOW (1-3): Accept and monitor, review annually

Risk Mitigation Strategy — Decision Framework

The 4T Framework

Is the risk within our risk appetite?
├── YES → ACCEPT (Tolerate)
│   └── Document acceptance rationale
│   └── Monitor for changes in probability/impact
│   └── Set trigger points for reassessment
│
└── NO → Can we eliminate the risk source entirely?
    ├── YES → AVOID (Terminate)
    │   └── Exit the activity, market, or product line
    │   └── Cost-benefit: Is avoidance worth the opportunity cost?
    │
    └── NO → Can a third party bear the risk more efficiently?
        ├── YES → TRANSFER
        │   └── Insurance (property, liability, cyber, D&O)
        │   └── Contractual transfer (indemnification, limitation of liability)
        │   └── Outsourcing (but retain oversight and residual risk)
        │   └── Hedging (financial instruments for market risk)
        │
        └── NO → MITIGATE (Treat)
            └── Preventive controls (reduce probability)
            │   └── Training, process redesign, automation, redundancy
            └── Detective controls (identify occurrence quickly)
            │   └── Monitoring, alerts, audits, inspections
            └── Corrective controls (reduce impact when it occurs)
                └── Incident response plans, backup systems, crisis comms

Mitigation Cost-Benefit Analysis

Should we invest in this mitigation?

Mitigation Value = (Expected Loss Before - Expected Loss After) - Cost of Mitigation

Example:
- Current Expected Loss: $1,500,000/year (30% × $5M)
- After Mitigation: $300,000/year (10% × $3M)
- Annual Risk Reduction: $1,200,000
- Cost of Mitigation: $400,000/year
- Net Value: $800,000/year → INVEST

Rule of thumb: Invest if mitigation cost 12 months)
- EV revenue as % of total (target: >15% by Year 3)
- OEM customer EV transition announcements (track quarterly)

Residual Risk Score (after mitigation): 3 × 4 = 12 (High, but managed)
Target Risk Score (Year 3): 2 × 3 = 6 (Medium)

Reference Materials

For detailed guidance, refer to:

  • references/risk-quantification-guide.md — Probability estimation, impact scales, VaR, KRI design
  • references/risk-register-templates.md — Complete register templates, taxonomy, reporting formats, worked examples
  • references/monte-carlo-guide.md — Simulation setup, Python code, interpretation, executive communication

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.