Klimmer, risico beheerst in beeld
Pillar · Risk Management

Risk in control that connects to strategy and decisions

Risk management in a dynamic context

From risk identification to decision-making

Organisations operate in a continuously changing environment. Strategic choices, operational dependencies, digitalisation and regulation all introduce new risks and opportunities. In that context it is essential that risk management is not a standalone process, but an integral part of regular decision-making.

Risk management supports boards and management in making well-considered choices, with insight into potential consequences and appropriate control measures.

// 03Intake

A good conversation first. Then a proposal.

A first conversation is quickly arranged. You tell us where you stand, we show how we work and what we can do for you. That way you soon discover whether we are a good match.

Schedule a conversation on Risk Management

Frequently asked questions

Which risk management framework fits our risk profile?

For financial institutions: COSO ERM 2017 with a DORA overlay. For industry: ISO 31000 with ISO 27005 for ICT. For the public sector: COSO ERM with government-wide guidance. We do not design proprietary frameworks; we apply recognised frameworks proportionally.

What does DORA change for my risk management?

DORA requires financial entities to have an ICT risk-management framework across five pillars, incident reporting within 24 hours, a third-party register and regular resilience testing. Effective since 17 January 2025.

What is risk appetite and how does the board define it?

Risk appetite is the amount of risk the board is willing to accept in realising its strategy. We use a 4D framework: financial, operational, regulatory and reputational. Per dimension the board defines acceptable, tolerable and unacceptable.

Is a Risk Health Check the same as an audit?

No. The Risk Health Check is a thematic review of your organisation on current risk themes such as cyber, AI governance and continuity, in three packages with a lead time of two to six weeks. Not an assurance opinion, but a scorecard with a roadmap you can act on immediately.

How does Risk Management connect to Internal Audit?

Risk Management is the second line of defence (control), Internal Audit the third (assurance). We serve both from the same methodological clarity and safeguard their coherence, without compromising the independence of Internal Audit.