JANELA AMBICIOSA

Risk management

What can go wrong,
written down first.

A corporate risk matrix with controls and owners, and a continuity plan that exists before it is needed.

How risk is managed

Risks are recorded in a matrix with five fields: description, likelihood, impact, existing controls and owner. The matrix is reviewed at least annually and whenever there is a material change in the business.

A risk with no named owner is not managed — it is listed. That is the distinction the matrix forces.

Categories considered

Operational risk. Key-person dependency, supplier failure, execution error. In a small structure, concentration of knowledge is the dominant risk, mitigated by documentation and by partner agreements.

Compliance risk. Incorrect framing of an activity, failure to identify a client, breach of a reporting duty. Mitigated by the onboarding procedure and by declining work we cannot frame.

Information risk. Unauthorised access, data loss, unavailability. Mitigated by the controls described in Information security.

Financial risk. Revenue concentration in one client, late payment, currency variation in contracts outside the euro area.

Reputational risk. Association with a problematic counterparty. Mitigated by onboarding screening and by the right to decline work.

Risk appetite

The company accepts no risk in three areas: regulatory breach, exposure to sanctioned counterparties, and compromise of client information. In these, control prevails over commercial opportunity, even where that means losing the work.

Business continuity

The continuity plan covers systems unavailability, key-person unavailability and critical supplier failure. For each scenario it sets a recovery time objective and a resumption procedure.

Data and working tools are reachable from any location, which reduces premises unavailability to a logistics problem rather than an operational one.

Controls

The real status of each control in this area. A control "being implemented" is defined and pending approval; "planned" has a target date but is not yet written.

  • Corporate risk matrix

    Risks, controls and owners recorded.

    Being implemented
  • Risk appetite defined

    Three zero-tolerance areas declared.

    In force
  • Annual matrix review

    First review scheduled.

    Being implemented
  • Business continuity plan

    Scenarios identified; plan to be formalised.

    Planned

Documents in this area

  • Corporate Risk Matrix

    Being implemented

    Identified risks, likelihood, impact, existing controls and an owner for each. Reviewed at least annually.

    Version
    1.0
    Available once approved
  • Business Continuity Plan

    Planned

    Disruption scenarios, recovery time objectives, critical dependencies and resumption procedure.

    Version
    1.0
    Not yet drafted

Need documentation for a process?

We send the due diligence pack within 24 business hours, with the registry certificate, beneficial ownership, corporate structure and the applicable policies.

Request documentation