# Risk Management

> Design enterprise risk management frameworks, build risk registers, quantify risks, run Monte Carlo simulations, and develop mitigation strategies. Use this skill when the user mentions: risk management, risk assessment, risk register, risk matrix, risk appetite, risk tolerance, ERM, COSO, ISO 31000, Monte Carlo, risk quantification, risk heat map, business continuity, BCP, crisis management, str…

- **Type:** Skill
- **Install:** `agentstack add skill-abinauv-business-consulting-risk-management`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [abinauv](https://agentstack.voostack.com/s/abinauv)
- **Installs:** 0
- **Category:** [Data & Analytics](https://agentstack.voostack.com/c/data-and-analytics)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [abinauv](https://github.com/abinauv)
- **Source:** https://github.com/abinauv/business-consulting/tree/main/skills/risk-management
- **Website:** https://github.com/abinauv/business-consulting/blob/main/README.md

## Install

```sh
agentstack add skill-abinauv-business-consulting-risk-management
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Enterprise Risk Management

You are a risk management specialist. Apply the following methodologies to design robust risk frameworks, quantify exposures, and build actionable mitigation plans.

## Enterprise Risk Management (ERM) Framework Design

### Framework Selection

**COSO ERM Framework (2017):**
Five interrelated components for integrating risk with strategy and performance:
1. **Governance & Culture** — Board risk oversight, operating structures, commitment to integrity, talent accountability
2. **Strategy & Objective-Setting** — Analyze business context, define risk appetite, evaluate alternative strategies, formulate business objectives
3. **Performance** — Identify risks to objectives, assess severity, prioritize risks, implement responses, develop portfolio view
4. **Review & Revision** — Assess substantial change, review risk and performance, pursue improvement
5. **Information, Communication & Reporting** — Leverage information systems, communicate risk information, report on risk/culture/performance

**ISO 31000:2018 Framework:**
Principles-based approach applicable to any organization:
- **Principles:** Integrated, structured, customized, inclusive, dynamic, best available information, human/cultural factors, continual improvement
- **Framework:** Leadership commitment, integration, design, implementation, evaluation, improvement
- **Process:** Scope/context/criteria, risk assessment (identify, analyze, evaluate), risk treatment, monitoring/review, recording/reporting, communication/consultation

### Framework Selection Decision Tree

```
Is the organization publicly traded or heavily regulated?
├── YES → COSO ERM (aligns with SEC/SOX expectations, board governance)
│   └── Is the organization a financial institution?
│       ├── YES → COSO ERM + Basel III/IV operational risk overlays
│       └── NO → COSO ERM standard implementation
└── NO → ISO 31000 (more flexible, principle-based)
    └── Is the organization operating internationally?
        ├── YES → ISO 31000 (internationally recognized standard)
        └── NO → ISO 31000 or simplified ERM tailored to size
```

### ERM Maturity Assessment

Rate the organization on each dimension (1 = Ad Hoc, 5 = Optimized):

| Dimension | 1 - Ad Hoc | 2 - Initial | 3 - Defined | 4 - Managed | 5 - Optimized |
|---|---|---|---|---|---|
| **Governance** | No formal oversight | Risk discussed informally | Risk committee exists | Board reviews quarterly | Risk integrated into strategy |
| **Risk Identification** | Reactive only | Annual brainstorming | Structured process | Continuous scanning | Predictive analytics |
| **Risk Assessment** | Qualitative only | Basic scoring | Calibrated scales | Quantitative modeling | Monte Carlo / VaR |
| **Risk Response** | Fire-fighting | Basic controls | Defined strategies | Optimized portfolio | Dynamic hedging |
| **Monitoring** | None | Periodic reviews | KRIs defined | Real-time dashboards | Automated alerts |
| **Culture** | Risk-unaware | Risk-averse/siloed | Risk-aware | Risk-informed decisions | Risk-intelligent |
| **Reporting** | None | Ad hoc reports | Standardized reports | Integrated dashboards | Predictive reporting |

**Maturity Scoring:**
- 7-14: **Initial** — Foundational work needed, start with governance and basic identification
- 15-21: **Developing** — Build structured processes and calibrated assessment
- 22-28: **Established** — Advance to quantitative methods and integrated reporting
- 29-35: **Leading** — Optimize with predictive analytics and dynamic risk management

## Risk Identification and Categorization

### Risk Category Taxonomy

**1. Strategic Risks** — Threats to achieving long-term objectives
- Market disruption and technology shifts
- Competitive dynamics (new entrants, substitutes, consolidation)
- M&A execution and integration risk
- Geographic/market expansion risk
- Business model obsolescence
- Strategic misalignment between units

**2. Operational Risks** — Failures in people, processes, systems, or external events
- Supply chain disruption (single-source dependency, logistics failure)
- Quality failures and product defects
- IT system outages and infrastructure failure
- Process breakdowns and human error
- Talent/key person dependency
- Health and safety incidents
- Fraud and internal misconduct

**3. Financial Risks** — Exposure to financial loss
- Credit risk (customer default, counterparty failure)
- Liquidity risk (cash flow timing, access to capital)
- Market risk (interest rates, currency, commodity prices)
- Revenue concentration (customer, product, geography)
- Capital structure and leverage risk
- Financial reporting and accounting errors

**4. Compliance Risks** — Violations of laws, regulations, or internal policies
- Regulatory change and new legislation
- Data privacy (GDPR, CCPA, sector-specific)
- Anti-corruption / anti-bribery (FCPA, UK Bribery Act)
- Environmental regulations and ESG mandates
- Industry-specific compliance (healthcare, finance, energy)
- Contractual and licensing obligations

**5. Reputational Risks** — Damage to brand, stakeholder trust, or social license
- Product safety incidents and recalls
- Data breaches and customer data exposure
- Social media crises and viral negative coverage
- Executive misconduct or ethical failures
- Environmental or social responsibility failures
- Customer experience failures at scale

**6. Technology Risks** — Cyber, digital, and emerging technology threats
- Cybersecurity breaches (ransomware, data exfiltration, DDoS)
- Legacy system failure and technical debt
- AI/ML model risk and algorithmic bias
- Cloud provider outages and vendor lock-in
- Intellectual property theft
- Digital transformation execution failure

**7. External/Macro Risks** — Forces beyond organizational control
- Geopolitical instability and trade restrictions
- Pandemic and public health emergencies
- Natural disasters and climate-related events
- Economic recession and market downturns
- Social unrest and political instability
- Infrastructure failure (power grid, telecom, transportation)

### Risk Identification Methods

Use multiple techniques to ensure comprehensive coverage:

1. **Structured brainstorming workshops** — Cross-functional teams, PESTLE prompts (Political, Economic, Social, Technological, Legal, Environmental)
2. **Process mapping and failure mode analysis** — Walk through key processes and identify failure points
3. **Historical loss analysis** — Review past incidents, near-misses, insurance claims, audit findings
4. **Industry benchmarking** — Study peer company 10-K risk factors, industry loss databases
5. **Scenario analysis** — "What if" exercises for extreme but plausible events
6. **Key stakeholder interviews** — Board members, executives, front-line managers, customers, suppliers
7. **Emerging risk scanning** — Horizon scanning for new/evolving threats (technology, regulation, geopolitics)

## Risk Quantification

### Probability x Impact Scoring

**Probability Scale (calibrated):**

| Level | Label | Probability Range | Calibration Guidance |
|---|---|---|---|
| 1 | Rare | 80% | Expected to occur; has occurred multiple times recently |

**Impact Scale (multi-dimensional):**

| Level | Financial Impact | Operational Impact | Reputational Impact | Safety Impact |
|---|---|---|---|---|
| 1 - Insignificant | $50M or >15% revenue | Extended shutdown, >1 month | Existential brand damage, regulatory action | Fatality |

*Note: Calibrate financial thresholds to the organization's revenue and margin profile. The ranges above suit a mid-market company ($100M-$1B revenue).*

### Expected Loss Modeling

```
Expected Loss = Probability × Financial Impact (midpoint)

Example:
- Risk: Key supplier failure
- Probability: 30% (Level 3)
- Financial Impact: $5M (Level 3 midpoint)
- Expected Loss: 0.30 × $5,000,000 = $1,500,000

Annualized Loss Expectancy (ALE):
ALE = Annual Rate of Occurrence (ARO) × Single Loss Expectancy (SLE)
- ARO: 0.3 events/year
- SLE: $5,000,000
- ALE: $1,500,000
```

### Value at Risk (VaR) Concepts — Simplified

VaR answers: "What is the maximum loss we would expect over a given time period at a specified confidence level?"

- **95% VaR of $10M over 1 year** means: "We are 95% confident our losses will not exceed $10M in the next year."
- In other words, there is a 5% chance losses could be worse than $10M.
- **Limitations:** VaR does not tell you how bad things could get beyond the threshold (use Conditional VaR / Expected Shortfall for that).

For non-financial contexts, express VaR conceptually:
- "In 19 out of 20 years, our total risk losses should be below $X."
- "In the worst 1-in-20 year, we could lose more than $X."

## Risk Appetite and Tolerance

### Definitions

- **Risk Appetite:** The broad level of risk an organization is willing to accept in pursuit of its strategic objectives. Set by the Board. Expressed qualitatively and quantitatively.
- **Risk Tolerance:** The specific, measurable boundaries around individual risk categories or metrics. Operational limits within the appetite.
- **Risk Capacity:** The maximum level of risk the organization can absorb before viability is threatened.

### Risk Appetite Statement Template

```
[Organization Name] Risk Appetite Statement

Overall Appetite: [Organization] accepts [moderate/conservative/aggressive] levels of
risk in pursuit of [strategic objectives]. We will not accept risks that could
[threaten solvency / cause regulatory sanctions / endanger safety / damage brand
beyond recovery].

By Category:
- Strategic Risk: [Appetite level] — We [will/will not] pursue [types of strategic bets]
- Operational Risk: [Appetite level] — We accept up to [X days] of disruption
  with financial impact not exceeding [$Y]
- Financial Risk: [Appetite level] — Maximum acceptable earnings volatility of
  [X%]; minimum liquidity ratio of [Y]
- Compliance Risk: ZERO TOLERANCE for willful regulatory violations
- Reputational Risk: [Appetite level] — We will not accept risks that could
  result in [specific reputational thresholds]
- Technology/Cyber Risk: [Appetite level] — Maximum acceptable downtime of
  [X hours]; zero tolerance for customer data breaches

Approved by: [Board of Directors]
Date: [Date]
Review Frequency: [Annual / Semi-annual]
```

### Tolerance Threshold Examples

| Risk Category | Green (Within Appetite) | Amber (Approaching Limit) | Red (Exceeds Tolerance) |
|---|---|---|---|
| Financial Loss (single event) | $5M |
| Revenue Concentration | Top customer 25% |
| System Downtime | 24 hours/quarter |
| Safety Incidents | 0 lost-time injuries | 1-2 lost-time injuries/year | >2 or any fatality |
| Compliance Violations | 0 material findings | 1-2 minor findings | Any material finding |
| Employee Turnover | 25% annual |

## Risk Register Construction

### Required Fields

Every risk register entry should contain:

| Field | Description |
|---|---|
| Risk ID | Unique identifier (e.g., STR-001, OPS-015) |
| Category | Strategic / Operational / Financial / Compliance / Reputational / Technology / External |
| Risk Description | Clear, specific statement: "Risk that [event] occurs, causing [consequence]" |
| Risk Owner | Named individual accountable for managing the risk |
| Inherent Probability | Score before controls (1-5) |
| Inherent Impact | Score before controls (1-5) |
| Inherent Risk Score | Probability x Impact (1-25) |
| Existing Controls | Current mitigation measures in place |
| Control Effectiveness | Effective / Partially Effective / Ineffective |
| Residual Probability | Score after controls (1-5) |
| Residual Impact | Score after controls (1-5) |
| Residual Risk Score | Probability x Impact (1-25) |
| Risk Response | Accept / Avoid / Transfer / Mitigate |
| Action Plan | Specific actions to further reduce risk |
| Target Risk Score | Desired residual risk level |
| Status | Open / In Progress / Monitoring / Closed |
| Last Review Date | Date of most recent review |
| Next Review Date | Scheduled review date |

### Risk Heat Map (5x5 Matrix)

```
Impact →        1-Insignif.  2-Minor    3-Moderate   4-Major    5-Catastrophic
Probability ↓
5-Almost Certain   [5-MED]    [10-HIGH]  [15-CRIT]   [20-CRIT]   [25-CRIT]
4-Likely           [4-MED]    [8-HIGH]   [12-HIGH]   [16-CRIT]   [20-CRIT]
3-Possible         [3-LOW]    [6-MED]    [9-HIGH]    [12-HIGH]   [15-CRIT]
2-Unlikely         [2-LOW]    [4-MED]    [6-MED]     [8-HIGH]    [10-HIGH]
1-Rare             [1-LOW]    [2-LOW]    [3-LOW]     [4-MED]     [5-MED]

Zone Definitions:
- CRITICAL (15-25): Immediate executive attention, mandatory mitigation plan within 30 days
- HIGH (8-14): Senior management attention, mitigation plan within 60 days
- MEDIUM (4-7): Management monitoring, review quarterly
- LOW (1-3): Accept and monitor, review annually
```

## Risk Mitigation Strategy — Decision Framework

### The 4T Framework

```
Is the risk within our risk appetite?
├── YES → ACCEPT (Tolerate)
│   └── Document acceptance rationale
│   └── Monitor for changes in probability/impact
│   └── Set trigger points for reassessment
│
└── NO → Can we eliminate the risk source entirely?
    ├── YES → AVOID (Terminate)
    │   └── Exit the activity, market, or product line
    │   └── Cost-benefit: Is avoidance worth the opportunity cost?
    │
    └── NO → Can a third party bear the risk more efficiently?
        ├── YES → TRANSFER
        │   └── Insurance (property, liability, cyber, D&O)
        │   └── Contractual transfer (indemnification, limitation of liability)
        │   └── Outsourcing (but retain oversight and residual risk)
        │   └── Hedging (financial instruments for market risk)
        │
        └── NO → MITIGATE (Treat)
            └── Preventive controls (reduce probability)
            │   └── Training, process redesign, automation, redundancy
            └── Detective controls (identify occurrence quickly)
            │   └── Monitoring, alerts, audits, inspections
            └── Corrective controls (reduce impact when it occurs)
                └── Incident response plans, backup systems, crisis comms
```

### Mitigation Cost-Benefit Analysis

```
Should we invest in this mitigation?

Mitigation Value = (Expected Loss Before - Expected Loss After) - Cost of Mitigation

Example:
- Current Expected Loss: $1,500,000/year (30% × $5M)
- After Mitigation: $300,000/year (10% × $3M)
- Annual Risk Reduction: $1,200,000
- Cost of Mitigation: $400,000/year
- Net Value: $800,000/year → INVEST

Rule of thumb: Invest if mitigation cost 12 months)
- EV revenue as % of total (target: >15% by Year 3)
- OEM customer EV transition announcements (track quarterly)

Residual Risk Score (after mitigation): 3 × 4 = 12 (High, but managed)
Target Risk Score (Year 3): 2 × 3 = 6 (Medium)
```

## Reference Materials

For detailed guidance, refer to:
- `references/risk-quantification-guide.md` — Probability estimation, impact scales, VaR, KRI design
- `references/risk-register-templates.md` — Complete register templates, taxonomy, reporting formats, worked examples
- `references/monte-carlo-guide.md` — Simulation setup, Python code, interpretation, executive communication

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [abinauv](https://github.com/abinauv)
- **Source:** [abinauv/business-consulting](https://github.com/abinauv/business-consulting)
- **License:** MIT
- **Homepage:** https://github.com/abinauv/business-consulting/blob/main/README.md

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-abinauv-business-consulting-risk-management
- Seller: https://agentstack.voostack.com/s/abinauv
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
