Prabh Nair
Avsnitt

Enterprise Risk Management Explained | Building a Risk Program from Scratch

Dela

In this podcast episode, Prabh speaks with David, a cybersecurity risk governance leader, about Enterprise Risk Management, GRC, risk appetite, risk tolerance, executive reporting, AI risk, and how to build a risk management program from scratch.David shares his first experience of building a risk management program in 2004 at a major Australian bank using ISO 17799, and explains why risk professionals must understand business objectives before applying any framework.Many organizations struggle with risk management because different teams use different definitions, different scoring methods, different language, and different assumptions.That is why David emphasizes the importance of building:Common risk languageAgreed definitionsClear governance levelsDecision-making authorityRisk ownershipBusiness-aligned impact and likelihood matricesOne-page executive risk summariesLinkedin Profilehttps://www.linkedin.com/in/vohradsky/In this episode, we discuss:How to build a risk management program from scratchWhy risk management must start with business objectivesWhy common language and agreed definitions matterHow risk appetite and risk tolerance should be explained to business teamsWhy scoping is critical before risk assessmentHow to understand business processes before identifying risksHow to collect relevant data about assets, processes, systems, and peopleHow to design impact and likelihood matrices for different organizational levelsWhy risk assessment should support decision-making, not only documentationHow to present risk to executives in language they understandWhy CFOs care about financial exposureWhy CEOs and boards care about strategic impactHow one-page summaries help executives take clear decisionsWhy accountability and decision points must be visibleWhat first artifacts can help when starting a risk programWhy a charter, risk taxonomy, and control profile are usefulHow AI risk management is changing GRC thinkingWhy cultural adoption is one of the hardest parts of risk managementWhat young GRC professionals should focus on to grow in this fieldDavid also shares an important career lesson for young GRC professionals:Do not remain limited to templates and control checklists.Understand one business process deeply.Work closely with business teams.Learn how they think, how they make decisions, and what uncertainty means for them.The key takeaway from this session is simple:Risk management is not only about documenting risk. It is about helping the business make better decisions in uncertainty.This episode is useful for:AAISM Playlisthttps://www.youtube.com/playlist?list=PL0hT6hgexlYwHFcnBpXG2zuM7inotM0z3GRC Interview Playlisthttps://www.youtube.com/playlist?list=PL0hT6hgexlYxM5P9v7aEYBTJl7iJyK2uKAI Practicalhttps://www.youtube.com/playlist?list=PL0hT6hgexlYwHLdZR_oHvEKN_8IiAMBcUISO 27001 Playlisthttps://www.youtube.com/watch?v=tvd1MUf3aHE&list=PL0hT6hgexlYys_9UWhal1kr9Gkz0ms0sM&pp=sAgC#EnterpriseRiskManagement #GRC #RiskManagement #CyberRisk #CISO #CyberSecurity #Governance #Compliance #AI Governance #CoffeeWithPrabh

Podden och tillhörande omslagsbild på den här sidan tillhör Prabh Nair. Innehållet i podden är skapat av Prabh Nair och inte av, eller tillsammans med, Poddtoppen.