Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Operational Risk

Enterprise Risk Management After Approval: The Operating Cadence That Keeps ERM Alive

Run an enterprise risk management framework with a practical monthly, quarterly, and annual cadence, named owners, and decision evidence.

Table of Contents

TL;DR

  • An approved enterprise risk management framework is only the shell. The operating calendar is what turns it into decisions.
  • Run a monthly management cycle, a quarterly board cycle, and an annual framework reset—with event-driven escalation between meetings.
  • Preserve the evidence chain: source data → owner explanation → second-line challenge → decision → action → effectiveness check.

The framework was approved six months ago. The risk taxonomy is polished. The committee charter has signatures. Yet the risk register still shows last quarter’s owners, three red KRIs have no decision attached, and the board pack says “monitoring continues.”

That is not an enterprise risk management framework in operation. It is a document set waiting for a meeting cadence.

The OCC’s Corporate and Risk Governance Comptroller’s Handbook describes risk governance as the policies, processes, people, and control systems supporting risk decisions. Its reporting guidance says boards should be able to monitor risk positions against appetite and understand the volume and impact of policy and operating-procedure exceptions. The practical implication is simple: each recurring ERM activity needs an input, an accountable owner, a decision forum, and retained evidence.

What keeps an enterprise risk management framework alive?

Use three linked cycles rather than one giant annual assessment:

CyclePrimary purposeCore outputDecision owner
MonthlyDetect movement and force management actionExceptions, decisions, and updated actionsManagement risk committee
QuarterlyAggregate exposure and oversee appetiteEnterprise risk report and board minutesBoard or board risk committee
AnnualRecalibrate the systemApproved appetite, taxonomy, calendar, and assurance planBoard and senior management
Event-drivenRespond before the calendar catches upEscalation memo and interim decisionAuthority named in the escalation matrix

This is deliberately different from the build sequence in How to Build an Enterprise Risk Management Framework from Scratch. Once the framework exists, the job changes from designing artifacts to moving reliable information through them.

The monthly ERM production line

A monthly risk committee should be the end of a production line, not the moment everyone first sees the numbers.

Business-day 1–5: collect source-linked updates

Each risk owner submits only changes and exceptions. A workable update form contains:

  • current residual-risk rating and prior-period rating;
  • KRI result, threshold, source system, extraction date, and data owner;
  • new incidents, losses, complaints, findings, or control failures;
  • open actions that changed status or missed a date;
  • risk acceptances or policy exceptions approaching expiry;
  • one short explanation of what changed and what decision is needed.

Evidence standard: a number without a source reference is a draft. “Critical vulnerabilities: 17” should link to the scanner export or ticket report, identify the as-of date, and reconcile to the underlying records.

The awkward part is ownership. Operations may own the risk while Security owns the vulnerability feed and Engineering owns remediation. Put all three roles in the record. Assigning the whole item to “Technology” guarantees a circular conversation later.

Business-day 6–8: second-line review and challenge

Risk should challenge submissions before the committee pack is frozen. Focus on inconsistencies:

  • a KRI is green while related incidents increased;
  • an action is marked complete but no control test exists;
  • a residual-risk score fell with no change in control evidence;
  • a red threshold was redefined instead of remediated;
  • an emerging risk appears in narrative but not in the risk register.

Record the owner’s response and the unresolved point. Do not silently replace the first line’s view with Risk’s preferred score. A visible disagreement is governance evidence; an unexplained final number is not.

A useful challenge note reads:

Risk challenge: Payments Operations retained “moderate” residual risk despite two reconciliation breaks this month. Risk recommends “high” until the automated completeness check passes effectiveness testing. Owner response: rating disputed; manual review covers daily files. Decision requested: committee to set interim rating and control-test due date.

Business-day 9–10: build a decision pack

Organize the pack by decisions, then monitoring. Lead with:

  1. appetite breaches and requested disposition;
  2. deteriorating risks and proposed controls;
  3. overdue high-severity actions;
  4. acceptances requiring renewal, closure, or escalation;
  5. emerging risks requiring an owner or assessment;
  6. stable dashboard items for consent.

The OCC handbook says performance and risk reports should show measures, trends, and variances rather than raw data. Apply that literally. Show the last six observations where available, the threshold, and a plain-language reason for movement.

Committee day: decide, assign, and timestamp

Minutes that say “discussed cyber risk” are weak evidence. Capture:

Decision-log fieldExample
DecisionKeep residual risk high pending control validation
RationaleTwo breaks; manual review not independently tested
Accountable ownerVP Payments Operations
Required actionTest automated file-completeness control
Due dateSeptember 15
Interim conditionDaily manual reconciliation with supervisor sign-off
Escalation triggerAny additional unreconciled file or missed daily sign-off
Evidence for closureTest script, sample, exceptions, reviewer approval

The decision log is the bridge between committee governance and issue execution. Without it, the same red box can appear for four months while everyone assumes somebody else accepted it.

The quarterly board cycle should answer four questions

The board does not need the full management pack. It needs a compact answer to:

  1. Are we operating within appetite? Show every breach, duration, management response, and decision still required.
  2. What changed materially? Identify movement in top risks, concentrations, incidents, regulatory exposure, and strategic assumptions.
  3. Is management fixing what it said it would fix? Show overdue high-risk actions, recurrence, and failed effectiveness tests.
  4. What requires board action? Ask for an appetite change, acceptance above delegated authority, capital/resource decision, or strategic constraint explicitly.

The Federal Reserve’s SR 95-51, as revised, emphasizes active senior-management and board roles, adequate policies and limits, independent risk measurement, and strong controls. Scope and applicability vary by institution, but the operating lesson travels well: oversight requires timely information tied to limits and action—not a retrospective activity list.

A seven-page board pack can be enough

A small or mid-size institution can start with:

  1. one-page top-risk and decision summary;
  2. appetite dashboard with trend;
  3. material incidents and losses;
  4. regulatory, audit, and compliance issues;
  5. third-party and concentration exposure;
  6. emerging-risk watchlist;
  7. action and acceptance aging.

Seven pages is a design constraint, not a regulatory limit. Expand only when the risk profile requires it. Put detailed inventories in an appendix available on request.

The annual reset: test the machinery, not just the document date

An annual framework review should produce more than a new approval date. Run five checks.

1. Strategy-to-risk reconciliation

Map current objectives, products, markets, funding sources, material vendors, and technology changes to the taxonomy. If the company added instant payments but the operational-risk inventory still assumes batch settlement, the framework is stale even if the policy was approved yesterday.

2. Appetite calibration

Compare thresholds with actual results, near misses, stress outcomes, and management behavior. Repeated amber results followed by no action may mean the threshold is noise. Repeated exceptions may mean the appetite statement conflicts with the business model.

For the mechanics, use the risk appetite statement guide and preserve the rationale for every changed limit.

3. Taxonomy and ownership cleanup

Remove duplicates, resolve risks split across teams, and verify named owners still hold the role. Test ownership with a practical question: could this person approve funding, change the process, or accept the exposure? If not, they may be a coordinator rather than the owner.

4. KRI usefulness review

Retire metrics that never influence a decision. Recalibrate starter thresholds against at least the available internal history and known obligations. Review source lineage and anti-gaming controls—for example, reconcile “closed issues” to reopened items and sample closure evidence.

The KRI guide provides examples, but your annual review should prove which indicators predicted movement in your own risk profile.

5. Governance effectiveness assessment

Sample committee decisions from the year and trace each one forward:

  • Was the action entered into a controlled tracker?
  • Did the accountable owner accept it?
  • Was it completed by the approved date?
  • Did someone test effectiveness?
  • Did the risk or KRI actually improve?
  • If not, was the matter reopened or accepted at the correct authority?

This sample is far more revealing than confirming that every meeting occurred.

Build event-driven triggers between meetings

A calendar is not permission to wait. Define triggers that bypass the normal cycle, such as:

  • an appetite limit breach;
  • a material customer-impacting incident;
  • a critical vendor outage with no tested workaround;
  • a regulatory inquiry, significant complaint pattern, or suspected legal violation;
  • a control failure affecting financial, regulatory, or customer reporting;
  • a strategic change that creates exposure outside the approved risk profile.

For each trigger, predefine who is notified, within what internal timeframe, who can make the interim decision, and what must reach the board. Internal notification targets are management choices unless a law or contract specifies the deadline; label them that way.

A practical RACI for the operating cadence

ActivityBusiness risk ownerRisk functionData/control ownerManagement committeeBoard
Monthly risk updateR/ACRII
Challenge and aggregationCR/ACII
Management acceptance within authorityRCCAI
Appetite breach escalationRRCAI/A by authority
Quarterly enterprise reportCRCAI/decision
Annual appetite approvalCRCCA
Effectiveness testingCC or RRII

“Responsible” and “accountable” should be adjusted to the institution’s delegations. The important control is that preparation, challenge, approval, and testing are not collapsed into one unnamed owner.

So what should happen this week?

Take the next management risk committee date and work backward ten business days. Create four artifacts: the owner update form, challenge log, decision-oriented agenda, and decision register. Then select one red or amber item from the last board pack and trace it from source data through the latest action and effectiveness evidence.

Where that chain breaks is the real implementation backlog.

The Enterprise Risk Management Framework provides the governance, risk appetite, committee, and board-reporting foundation; use the cadence above to keep those artifacts moving after approval.

Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

How often should an enterprise risk management framework be updated?
Update risk data on the cadence that matches the risk: volatile KRIs may need weekly monitoring, management risk decisions usually need a monthly forum, and the board typically needs a quarterly enterprise view. Review the framework, taxonomy, appetite, and committee mandates at least annually and whenever strategy, products, regulation, or the operating model changes materially.
What should a monthly ERM meeting cover?
Cover breached or deteriorating KRIs, new loss events, overdue high-risk actions, risk acceptances nearing expiry, emerging risks, and decisions that require management authority. The packet should show changes since the prior meeting and identify the decision requested, owner, due date, and escalation path.
Who owns the ERM operating calendar?
The CRO or Head of Risk should own the calendar and evidence standard. Business risk owners supply updates and execute actions; Finance, Compliance, Security, and Operations provide source data; the management risk committee makes cross-functional decisions; and the board oversees appetite, material exposure, and management performance.
What evidence proves an ERM framework is operating?
Useful evidence includes dated risk-owner certifications, source-linked KRI results, challenge notes, committee packs, decision logs, approved risk acceptances, action trackers, board minutes, and proof that escalations changed a limit, control, product decision, or remediation plan.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Enterprise Risk Management Framework (ERMF)

Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.