Feature Operational Risk
Enterprise Risk Management After Approval: The Operating Cadence That Keeps ERM Alive
Run an enterprise risk management framework with a practical monthly, quarterly, and annual cadence, named owners, and decision evidence.
Table of Contents
TL;DR
- An approved enterprise risk management framework is only the shell. The operating calendar is what turns it into decisions.
- Run a monthly management cycle, a quarterly board cycle, and an annual framework reset—with event-driven escalation between meetings.
- Preserve the evidence chain: source data → owner explanation → second-line challenge → decision → action → effectiveness check.
The framework was approved six months ago. The risk taxonomy is polished. The committee charter has signatures. Yet the risk register still shows last quarter’s owners, three red KRIs have no decision attached, and the board pack says “monitoring continues.”
That is not an enterprise risk management framework in operation. It is a document set waiting for a meeting cadence.
The OCC’s Corporate and Risk Governance Comptroller’s Handbook describes risk governance as the policies, processes, people, and control systems supporting risk decisions. Its reporting guidance says boards should be able to monitor risk positions against appetite and understand the volume and impact of policy and operating-procedure exceptions. The practical implication is simple: each recurring ERM activity needs an input, an accountable owner, a decision forum, and retained evidence.
What keeps an enterprise risk management framework alive?
Use three linked cycles rather than one giant annual assessment:
| Cycle | Primary purpose | Core output | Decision owner |
|---|---|---|---|
| Monthly | Detect movement and force management action | Exceptions, decisions, and updated actions | Management risk committee |
| Quarterly | Aggregate exposure and oversee appetite | Enterprise risk report and board minutes | Board or board risk committee |
| Annual | Recalibrate the system | Approved appetite, taxonomy, calendar, and assurance plan | Board and senior management |
| Event-driven | Respond before the calendar catches up | Escalation memo and interim decision | Authority named in the escalation matrix |
This is deliberately different from the build sequence in How to Build an Enterprise Risk Management Framework from Scratch. Once the framework exists, the job changes from designing artifacts to moving reliable information through them.
The monthly ERM production line
A monthly risk committee should be the end of a production line, not the moment everyone first sees the numbers.
Business-day 1–5: collect source-linked updates
Each risk owner submits only changes and exceptions. A workable update form contains:
- current residual-risk rating and prior-period rating;
- KRI result, threshold, source system, extraction date, and data owner;
- new incidents, losses, complaints, findings, or control failures;
- open actions that changed status or missed a date;
- risk acceptances or policy exceptions approaching expiry;
- one short explanation of what changed and what decision is needed.
Evidence standard: a number without a source reference is a draft. “Critical vulnerabilities: 17” should link to the scanner export or ticket report, identify the as-of date, and reconcile to the underlying records.
The awkward part is ownership. Operations may own the risk while Security owns the vulnerability feed and Engineering owns remediation. Put all three roles in the record. Assigning the whole item to “Technology” guarantees a circular conversation later.
Business-day 6–8: second-line review and challenge
Risk should challenge submissions before the committee pack is frozen. Focus on inconsistencies:
- a KRI is green while related incidents increased;
- an action is marked complete but no control test exists;
- a residual-risk score fell with no change in control evidence;
- a red threshold was redefined instead of remediated;
- an emerging risk appears in narrative but not in the risk register.
Record the owner’s response and the unresolved point. Do not silently replace the first line’s view with Risk’s preferred score. A visible disagreement is governance evidence; an unexplained final number is not.
A useful challenge note reads:
Risk challenge: Payments Operations retained “moderate” residual risk despite two reconciliation breaks this month. Risk recommends “high” until the automated completeness check passes effectiveness testing. Owner response: rating disputed; manual review covers daily files. Decision requested: committee to set interim rating and control-test due date.
Business-day 9–10: build a decision pack
Organize the pack by decisions, then monitoring. Lead with:
- appetite breaches and requested disposition;
- deteriorating risks and proposed controls;
- overdue high-severity actions;
- acceptances requiring renewal, closure, or escalation;
- emerging risks requiring an owner or assessment;
- stable dashboard items for consent.
The OCC handbook says performance and risk reports should show measures, trends, and variances rather than raw data. Apply that literally. Show the last six observations where available, the threshold, and a plain-language reason for movement.
Committee day: decide, assign, and timestamp
Minutes that say “discussed cyber risk” are weak evidence. Capture:
| Decision-log field | Example |
|---|---|
| Decision | Keep residual risk high pending control validation |
| Rationale | Two breaks; manual review not independently tested |
| Accountable owner | VP Payments Operations |
| Required action | Test automated file-completeness control |
| Due date | September 15 |
| Interim condition | Daily manual reconciliation with supervisor sign-off |
| Escalation trigger | Any additional unreconciled file or missed daily sign-off |
| Evidence for closure | Test script, sample, exceptions, reviewer approval |
The decision log is the bridge between committee governance and issue execution. Without it, the same red box can appear for four months while everyone assumes somebody else accepted it.
The quarterly board cycle should answer four questions
The board does not need the full management pack. It needs a compact answer to:
- Are we operating within appetite? Show every breach, duration, management response, and decision still required.
- What changed materially? Identify movement in top risks, concentrations, incidents, regulatory exposure, and strategic assumptions.
- Is management fixing what it said it would fix? Show overdue high-risk actions, recurrence, and failed effectiveness tests.
- What requires board action? Ask for an appetite change, acceptance above delegated authority, capital/resource decision, or strategic constraint explicitly.
The Federal Reserve’s SR 95-51, as revised, emphasizes active senior-management and board roles, adequate policies and limits, independent risk measurement, and strong controls. Scope and applicability vary by institution, but the operating lesson travels well: oversight requires timely information tied to limits and action—not a retrospective activity list.
A seven-page board pack can be enough
A small or mid-size institution can start with:
- one-page top-risk and decision summary;
- appetite dashboard with trend;
- material incidents and losses;
- regulatory, audit, and compliance issues;
- third-party and concentration exposure;
- emerging-risk watchlist;
- action and acceptance aging.
Seven pages is a design constraint, not a regulatory limit. Expand only when the risk profile requires it. Put detailed inventories in an appendix available on request.
The annual reset: test the machinery, not just the document date
An annual framework review should produce more than a new approval date. Run five checks.
1. Strategy-to-risk reconciliation
Map current objectives, products, markets, funding sources, material vendors, and technology changes to the taxonomy. If the company added instant payments but the operational-risk inventory still assumes batch settlement, the framework is stale even if the policy was approved yesterday.
2. Appetite calibration
Compare thresholds with actual results, near misses, stress outcomes, and management behavior. Repeated amber results followed by no action may mean the threshold is noise. Repeated exceptions may mean the appetite statement conflicts with the business model.
For the mechanics, use the risk appetite statement guide and preserve the rationale for every changed limit.
3. Taxonomy and ownership cleanup
Remove duplicates, resolve risks split across teams, and verify named owners still hold the role. Test ownership with a practical question: could this person approve funding, change the process, or accept the exposure? If not, they may be a coordinator rather than the owner.
4. KRI usefulness review
Retire metrics that never influence a decision. Recalibrate starter thresholds against at least the available internal history and known obligations. Review source lineage and anti-gaming controls—for example, reconcile “closed issues” to reopened items and sample closure evidence.
The KRI guide provides examples, but your annual review should prove which indicators predicted movement in your own risk profile.
5. Governance effectiveness assessment
Sample committee decisions from the year and trace each one forward:
- Was the action entered into a controlled tracker?
- Did the accountable owner accept it?
- Was it completed by the approved date?
- Did someone test effectiveness?
- Did the risk or KRI actually improve?
- If not, was the matter reopened or accepted at the correct authority?
This sample is far more revealing than confirming that every meeting occurred.
Build event-driven triggers between meetings
A calendar is not permission to wait. Define triggers that bypass the normal cycle, such as:
- an appetite limit breach;
- a material customer-impacting incident;
- a critical vendor outage with no tested workaround;
- a regulatory inquiry, significant complaint pattern, or suspected legal violation;
- a control failure affecting financial, regulatory, or customer reporting;
- a strategic change that creates exposure outside the approved risk profile.
For each trigger, predefine who is notified, within what internal timeframe, who can make the interim decision, and what must reach the board. Internal notification targets are management choices unless a law or contract specifies the deadline; label them that way.
A practical RACI for the operating cadence
| Activity | Business risk owner | Risk function | Data/control owner | Management committee | Board |
|---|---|---|---|---|---|
| Monthly risk update | R/A | C | R | I | I |
| Challenge and aggregation | C | R/A | C | I | I |
| Management acceptance within authority | R | C | C | A | I |
| Appetite breach escalation | R | R | C | A | I/A by authority |
| Quarterly enterprise report | C | R | C | A | I/decision |
| Annual appetite approval | C | R | C | C | A |
| Effectiveness testing | C | C or R | R | I | I |
“Responsible” and “accountable” should be adjusted to the institution’s delegations. The important control is that preparation, challenge, approval, and testing are not collapsed into one unnamed owner.
So what should happen this week?
Take the next management risk committee date and work backward ten business days. Create four artifacts: the owner update form, challenge log, decision-oriented agenda, and decision register. Then select one red or amber item from the last board pack and trace it from source data through the latest action and effectiveness evidence.
Where that chain breaks is the real implementation backlog.
The Enterprise Risk Management Framework provides the governance, risk appetite, committee, and board-reporting foundation; use the cadence above to keep those artifacts moving after approval.
Sources
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
How often should an enterprise risk management framework be updated?
What should a monthly ERM meeting cover?
Who owns the ERM operating calendar?
What evidence proves an ERM framework is operating?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Keep reading
Related posts.
Operational Risk
Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map
Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.
Jul 23, 2026
Operational Risk
FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.
On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.
Jul 21, 2026
Operational Risk
3,383 Incidents Later: What DORA's First ICT Data Reveals About Your Operational Risk Program
The ESAs published their first DORA ICT incident report in June 2026 — 3,383 major incidents, nearly one-third from third-party failures, only 10% cyber-related. Here's what the data means for your operational risk program.
Jul 16, 2026