Risk management
What can go wrong,
written down first.
A corporate risk matrix with controls and owners, and a continuity plan that exists before it is needed.
How risk is managed
Risks are recorded in a matrix with five fields: description, likelihood, impact, existing controls and owner. The matrix is reviewed at least annually and whenever there is a material change in the business.
A risk with no named owner is not managed — it is listed. That is the distinction the matrix forces.
Categories considered
Operational risk. Key-person dependency, supplier failure, execution error. In a small structure, concentration of knowledge is the dominant risk, mitigated by documentation and by partner agreements.
Compliance risk. Incorrect framing of an activity, failure to identify a client, breach of a reporting duty. Mitigated by the onboarding procedure and by declining work we cannot frame.
Information risk. Unauthorised access, data loss, unavailability. Mitigated by the controls described in Information security.
Financial risk. Revenue concentration in one client, late payment, currency variation in contracts outside the euro area.
Reputational risk. Association with a problematic counterparty. Mitigated by onboarding screening and by the right to decline work.
Risk appetite
The company accepts no risk in three areas: regulatory breach, exposure to sanctioned counterparties, and compromise of client information. In these, control prevails over commercial opportunity, even where that means losing the work.
Business continuity
The continuity plan covers systems unavailability, key-person unavailability and critical supplier failure. For each scenario it sets a recovery time objective and a resumption procedure.
Data and working tools are reachable from any location, which reduces premises unavailability to a logistics problem rather than an operational one.
Controls
The real status of each control in this area. A control "being implemented" is defined and pending approval; "planned" has a target date but is not yet written.
- Being implemented
Corporate risk matrix
Risks, controls and owners recorded.
- In force
Risk appetite defined
Three zero-tolerance areas declared.
- Being implemented
Annual matrix review
First review scheduled.
- Planned
Business continuity plan
Scenarios identified; plan to be formalised.
Documents in this area
-
Corporate Risk Matrix
Being implementedIdentified risks, likelihood, impact, existing controls and an owner for each. Reviewed at least annually.
-
Business Continuity Plan
PlannedDisruption scenarios, recovery time objectives, critical dependencies and resumption procedure.
Need documentation for a process?
We send the due diligence pack within 24 business hours, with the registry certificate, beneficial ownership, corporate structure and the applicable policies.