Nearly every mid-sized and large organization runs some form of risk management. Very few get decisions out of it.
The AICPA and North Carolina State University's Enterprise Risk Management Initiative surveyed 273 US CFOs and senior finance leaders in spring 2025 for the 16th annual State of Risk Oversight report. Thirty-two percent rated overall risk oversight as mature or robust. Thirty-five percent had comprehensive enterprise risk management processes in place. Eleven percent considered risk management to deliver competitive advantage, while 64 percent said it delivered no advantage or minimal advantage. Only 30 percent factored risk exposure into capital allocation decisions.
The more revealing detail is that those figures had barely moved from the prior year. The shortfall is not one of awareness. Risk registers exist. Committees meet on schedule. Assessments get completed and filed. The breakdown happens downstream, where the output fails to reach the decisions it was built to inform.
The eight practices below are organized around that specific gap. Each is presented in three parts: what most organizations currently do, what the effective version looks like, and a concrete test for whether it is working.
The Eight Practices at a Glance
- Match the framework to regulatory exposure. Choose COSO or ISO 31000 against your actual reporting obligations, not by reputation.
- Express risk appetite as numeric thresholds. A limit nobody can breach will never trigger an escalation.
- Treat the heat map as a reporting device, never an analysis method. Analyze in currency and probability; communicate in color if you must.
- Assign accountability using the current Three Lines Model. One named owner per risk, distinct from whoever monitors it.
- Pair every lagging indicator with a leading one. An indicator earns its place only if action is still possible when it moves.
- Build one control set and present it through multiple regulatory views. DORA, NIS2, and the EU AI Act demand largely the same capabilities.
- Deliver risk insight where capital is allocated. Business case, planning cycle, and post-investment review.
- Add pre-mortems to the assessment calendar. Annual cycles find only the risks you already named.
Each section below expands one practice and ends with a test you can run this week.
How I Selected These Practices
I screened candidate practices against six criteria, each of which asks whether a practice changes what an organization decides rather than whether it produces documentation.
| Criterion | What it tests |
|---|---|
| Framework fit | Whether the chosen standard matches actual regulatory and reporting obligations |
| Quantification discipline | Whether risk magnitude is expressed in units that permit comparison and trade-off |
| Accountability clarity | Whether named roles own specific risks, controls, and escalation decisions |
| Threshold specificity | Whether appetite and tolerance are stated as measurable limits rather than adjectives |
| Monitoring cadence | Whether indicators refresh fast enough to alter a decision before loss occurs |
| Regulatory efficiency | Whether overlapping obligations draw on a single control inventory |
Practices satisfying fewer than four criteria were excluded. That removed several items appearing routinely in published guidance, including generic calls to build a risk-aware culture and to conduct assessments regularly. Both are sound sentiments and neither is actionable as written.
Source material comprised the 2025 State of Risk Oversight report, the Allianz Risk Barometer 2026 (3,338 risk professionals across 97 countries and territories), ISO 31000:2018, the COSO Enterprise Risk Management framework of 2017, the Institute of Internal Auditors' current Statement of Position on the Three Lines Model, published Factor Analysis of Information Risk material from The Open Group and the FAIR Institute, and the academic literature on risk matrix reliability, principally the work of Louis Anthony Cox and Douglas Hubbard.
Practice One: Match the Framework to Regulatory Exposure
Framework selection usually happens by reputation, or by whichever standard a consultant introduced first. The fit problem surfaces later, when auditors request evidence in a structure the framework does not produce.
The two dominant options differ more sharply than summaries suggest. ISO 31000:2018 runs to roughly 16 pages and concentrates on the risk management process itself and its place in strategic decision-making, supported separately by IEC 31010 for assessment techniques. The COSO framework is oriented toward corporate governance and toward evaluating whether existing risk activity is sound, and its full text extends well past 100 pages. ISO 31000 was developed through a formal international standards process; COSO is the product of a group of professional accounting and audit associations, and the 2017 revision was drafted with PwC.
| Dimension | ISO 31000:2018 | COSO ERM 2017 |
|---|---|---|
| Orientation | The risk process and its role in strategy | Governance, internal control, evaluation of existing practice |
| Length | Approximately 16 pages | Executive summary of similar length, full framework past 100 pages |
| Prescriptiveness | Principles based, no mandated assessment technique | Component and principle structure with detailed guidance |
| Primary audience | General management across sectors and geographies | Accounting, audit, and financial reporting professionals |
| Strongest fit | Multinational footprint, first formal program, integration with existing management systems | SOX or SEC reporting exposure, multi-divisional structures, audit committee evidence needs |
A workable decision rule: organizations carrying US securities reporting obligations should anchor on COSO, because its component structure maps to the documentation regulators expect, and should borrow ISO 31000's process guidance for implementation. Organizations without that exposure generally move faster on ISO 31000 and gain little from COSO's additional volume. Running both in full is a common and expensive error.
Verification test: a risk professional should be able to produce, within a single working day, the evidence an external auditor would request for any one enterprise risk. If assembling it requires reconstruction from multiple sources, the framework is decorative.
Practice Two: Express Risk Appetite as Numeric Thresholds
A typical appetite statement reads that the organization has a low tolerance for regulatory breaches and a moderate appetite for growth risk. Nothing follows from a sentence of that kind. No one can breach it, so no one escalates against it.
An appetite statement becomes operational when it carries three components: a target, a tolerance band around the target, and a named escalation path with a stated timeframe. The structure below is illustrative and the values are placeholders, but the shape is what matters.
| Risk category | Appetite | Tolerance band | Escalation trigger |
|---|---|---|---|
| Customer-facing availability | 99.95 percent monthly | 99.90 to 99.95 percent | Below 99.90 percent notifies the COO within 24 hours |
| Revenue concentration | No client above 8 percent of annual revenue | 8 to 12 percent | Above 12 percent requires board notification at the next scheduled meeting |
| Repeat audit findings | Zero repeat findings per cycle | One non-material repeat | Any material repeat finding goes to the audit committee immediately |
| Critical vendor dependency | Tested alternate provider for every critical process | One gap tolerated for up to two quarters | Longer than two quarters requires documented CFO approval |
Thresholds expressed this way also solve a reporting problem. A board can review exposure against a limit and reach a decision. A board reviewing a color cannot.
Verification test: identify the most recent occasion on which someone escalated a decision because a stated threshold was crossed. Programs with adjectival appetite statements cannot produce an example.
Practice Three: Treat the Heat Map as a Reporting Device, Never an Analysis Method
Heat maps remain the default output of most risk functions, and the objection to them is mathematical rather than aesthetic. Cox documented the range compression problem: because ordinal scales collapse wide value ranges into a small number of cells, exposures differing by orders of magnitude land in the same square and appear equivalent. Related research has shown that rankings can shift when scale labels change, which means the arithmetic performed on those labels does not survive scrutiny. Cox and Hubbard have both argued that the resulting guidance can push decision-makers toward choices that violate established principles of sound decision analysis.
The practical resolution is a division of responsibility that the FAIR community states plainly: a heat map is a way to communicate the results of an analysis, not a way to perform one. Analysis needs a model that decomposes risk into frequency of loss events and magnitude of loss, expressed in currency and in probability.
Full quantification across an entire register is unnecessary and rarely achievable. Selective quantification works better. Identify the three to five exposures driving the largest share of potential loss, model those in monetary terms using calibrated ranges rather than point estimates, and leave the remainder in qualitative form. Even sparse data produces a more defensible picture than a subjective high, medium, or low rating, because the assumptions become visible and can be challenged.
Verification test: ask what a top-three risk would cost, expressed as a loss range with an associated annual likelihood. A program answering with a color or a score out of 25 has not analyzed the risk.
Practice Four: Assign Accountability Using the Current Three Lines Model
Two versions of this model are now out of date, and most organizations are running one of them.
The 2013 Three Lines of Defense model was replaced by the IIA's Three Lines Model in July 2020, itself refreshed in September 2024 to align terminology with the Global Internal Audit Standards. That 2020 paper has since been formally superseded. The IIA now issues its guidance on this subject as a Statement of Position, Assurance and Advice in Support of Effective Governance: Three Lines Model, available from the IIA's Statements of Position page. If your governance documentation cites the 2020 position paper, it is citing a document the IIA itself labels a historical reference.
Four changes carry practical weight.
The word defense was dropped, on the reasoning that risk-based decision-making concerns pursuing opportunity as much as preventing loss. The second line is no longer defined by a list of named functions such as compliance, quality, or IT security, and is instead defined by the support it provides to management, which removes an artificial boundary between first and second line activity. The lines are understood to operate concurrently rather than in sequence, which changes how assurance is planned. And the current statement shifts the primary audience to the board, emphasizing accountability and the distinct contribution of each organizational role - a reframing that matters if your board pack still presents the three lines as an org chart.
The current statement also addresses a situation the older paper handled loosely: where the chief audit executive takes on second-line responsibilities, safeguards must be in place to protect the independence of the internal audit function and support auditor objectivity. Combining those roles is not prohibited. Doing it without documented safeguards is.
Worth reading alongside it is the IIA's companion Statement of Position on the role of internal audit in enterprise risk management, which defines ERM as a coordinated set of activities rather than a single function, and identifies five categories: identify, assess, manage, monitor, and report. That definition is useful ammunition against the common assumption that ERM is whatever the risk team does.
The failure mode all of this addresses is familiar. A compliance team labeled second line believes it owns a risk, the business unit assumes the risk is covered, and no one holds the decision. Under the current model, accountability for the risk stays with management in the first line, while second line roles supply expertise, challenge, and monitoring. Internal audit provides independent assurance and does not absorb management responsibility.
Verification test: for each of the top ten enterprise risks, a single named individual should be identifiable as accountable for the decision, distinct from whoever monitors or reports it. Ambiguity at this step is where risk programs fail quietly.
Practice Five: Pair Every Lagging Indicator With a Leading One
Most risk dashboards count events that have already happened. Incidents last quarter. Fines paid. Vendor failures recorded. These are useful for accountability and useless for prevention, because by the time the number moves the loss has occurred.
A key risk indicator earns its place only if a change in its value can trigger action while action still helps. The discipline is to pair each lagging measure with a forward-looking counterpart drawn from the same causal chain.
| Risk area | Common lagging indicator | Leading indicator to pair with it |
|---|---|---|
| Cyber | Security incidents recorded in the quarter | Share of critical assets carrying high-severity vulnerabilities past remediation SLA |
| Third party | Vendor service failures | Proportion of critical vendors with lapsed assessments or missing recovery attestations |
| Talent | Voluntary attrition rate | Count of single-point-of-failure roles without a documented successor |
| Compliance | Enforcement actions and penalties | Backlog of overdue control tests and past-due remediation items |
| Financial | Covenant breaches | Forecast headroom against the tightest covenant under a downside scenario |
Indicator count matters as much as indicator quality. A board-level set of eight to twelve paired indicators gets reviewed. A set of sixty gets skimmed.
Verification test: review the last four board risk packs and count how many indicators reported a state that could still be changed. A pack composed entirely of historical counts is a scorecard, not a risk report.
Practice Six: Build One Control Set and Present It Through Multiple Regulatory Views
Organizations facing several overlapping regulations commonly stand up a separate program for each, producing duplicated evidence, contradictory definitions, and three answers to the question of who owns incident response.
The overlap is substantial, because these instruments regulate largely the same underlying capabilities: risk management, incident handling, third-party oversight, governance, and logging. The efficient structure is a single control inventory with a mapping layer, so each regulation becomes a view onto shared evidence rather than a parallel project. Practitioners commonly use an ISO 27001 control structure as the backbone, extended with ISO 42001 where an AI management system is needed, though ISO 42001 is voluntary and confers no presumption of conformity under EU law.
| Instrument | Status as of 25 July 2026 | Shared capability demanded |
|---|---|---|
| DORA | Applicable since 17 January 2025 | ICT risk management, incident classification and reporting, resilience testing, third-party ICT oversight, information sharing |
| NIS2 | Member state transposition was due 17 October 2024, with national enforcement continuing to roll out | Cybersecurity risk measures, incident notification, management accountability |
| EU AI Act | Phased. Prohibitions and AI literacy since February 2025, general-purpose AI obligations since August 2025, high-risk obligations deferred (see below) | Risk management system for high-risk systems, event logging, technical documentation, human oversight |
The AI Act timeline moved in 2026
The detail here is worth stating precisely, because a great deal of 2026 compliance planning was built on a date that no longer applies.
The Digital Omnibus on AI reached provisional political agreement on 7 May 2026, was endorsed by the European Parliament on 16 June, and was cleared by the Council on 29 June. It defers high-risk obligations for standalone Annex III systems to 2 December 2027, and for AI embedded in regulated Annex I products to 2 August 2028. See the summaries from Gibson Dunn and White & Case for the mechanics.
The deferral does not empty the calendar. 2 August 2026 remains live for transparency obligations, general-purpose AI enforcement powers, and market surveillance authority. The Omnibus also introduces a new Article 5 prohibition on AI systems generating non-consensual intimate imagery and child sexual abuse material.
Anyone planning against these dates should confirm current status directly, since publication in the Official Journal and entry into force were completing as this was written.
Cross-mapping is explicitly sensible here. The AI Act's risk management requirement for high-risk systems overlaps materially with DORA's ICT risk management provisions, and financial entities deploying AI can document once against both rather than twice against each.
Verification test: count the control inventories in use. More than one indicates duplicated evidence and, more importantly, the likelihood that the versions have already diverged.
Practice Seven: Deliver Risk Insight Where Capital Is Allocated
The single most diagnostic statistic in the 2025 State of Risk Oversight data is that 30 percent of organizations integrate risk exposure into capital allocation decisions. Risk management that never touches the capital plan is an administrative function regardless of how well it is documented.
Integration is mechanical rather than cultural. It requires the risk function to appear at three specific decision points:
- The business case template, where material risks must be quantified alongside projected returns.
- The annual planning cycle, where aggregate exposure is compared against stated appetite before budgets are set.
- Post-investment review, where realized losses are compared against the estimates that supported approval.
That third step is the one most often omitted, and it is the only one that improves estimate quality over time.
Reporting format follows from this. A useful board paper presents exposure next to the decision it bears on, not as a standalone register appendix reviewed after the strategy discussion has concluded.
Verification test: examine the last three approved business cases above the capital threshold. Each should show a quantified risk adjustment that materially influenced the numbers. Cases carrying a generic risk section that did not alter any figure indicate the integration is presentational.
Practice Eight: Add Pre-Mortems to the Assessment Calendar
Annual assessment cycles identify risks the organization already recognizes. They perform poorly on risks that arrive quickly, and the current landscape supplies a clear example.
The Allianz Risk Barometer 2026 recorded artificial intelligence rising from tenth position to second, at 32 percent of responses - the largest single move in the survey's ranking history. Cyber incidents held first place for a fifth consecutive year at 42 percent, the highest score the survey has recorded, and by its widest ever margin. An organization assessing risk once a year would have registered the AI shift roughly twelve months late.
A pre-mortem addresses the timing problem at the point of decision rather than on the calendar. Before a strategic initiative is approved, the team assumes the initiative has failed eighteen months out and works backward to explain why. The exercise surfaces assumptions that a probability-weighted assessment tends to suppress, and it costs an hour.
Two supporting mechanisms matter. Emerging risk review should sit on a quarterly cadence with an explicit remit to consider exposures absent from the register, since a register review by definition cannot find what is not in the register. Interconnection should also be mapped, because the barometer's top ten includes several risks functioning as consequences of the others - business interruption most obviously, which dropped to third place for the first time while remaining a downstream effect of nearly everything above it.
Verification test: identify the most recent risk added to the register that no one had named twelve months earlier. If none exists, the process is reviewing rather than identifying.
Sequencing the First Ninety Days
Attempting all eight practices simultaneously reliably stalls. Ordering matters, because thresholds cannot be set before ownership is clear, and instrumentation cannot be designed before thresholds exist.
| Phase | Focus | Output |
|---|---|---|
| Days 1 to 30 | Consolidation and framework decision | One merged risk inventory with a named accountable owner per risk, plus a documented framework selection rationale |
| Days 31 to 60 | Threshold definition | Appetite and tolerance statements with numeric bands for the top ten enterprise risks, approved at executive level |
| Days 61 to 90 | Instrumentation and reporting redesign | Paired leading and lagging indicators for each top risk, and a board reporting format presenting exposure beside the decision it affects |
Selective quantification, regulatory mapping, and pre-mortems belong to the following quarter. They depend on the foundations above and produce poor results without them.
Conclusion
The practices separating the 32 percent from everyone else are not more numerous or more sophisticated. They are more consequential:
- A framework chosen against actual reporting obligations.
- Appetite expressed as limits someone can breach.
- Analysis performed in currency rather than color.
- A single accountable owner per risk, under the current Three Lines guidance rather than a superseded version of it.
- Indicators that report changeable states.
- One control inventory serving several regulators.
- Risk output arriving before capital is committed rather than after.
- Pre-mortems at the point of decision rather than assessments on the calendar.
What connects them is that each creates a point at which risk information can alter a decision. Programs producing documentation without producing those points will keep scoring well on process maturity assessments while continuing to deliver, in the language of the survey data, no advantage or minimal advantage. The distinction is worth acting on, because the figures suggest most organizations have not yet made it.