Risk Governance
What is Risk Governance?
The organizational structures, policies, and processes that direct and control risk management activities across the enterprise.
Terms that appear alongside risk governance
Each of these is named in at least one of the same controls as risk governance. The number is how many controls name both.
- governance 26 shared controls
- risk appetite 11 shared controls
- audit 7 shared controls
- governance framework 7 shared controls
- risk appetite statement 6 shared controls
- internal audit 5 shared controls
- cybersecurity 5 shared controls
- risk assessment 4 shared controls
Frameworks that govern risk governance
What the standards actually require on risk governance
Requirements naming risk governance across 6 standards, quoted from the control text.
Establish and maintain a Risk Governance Framework per 12 CFR Part 30 Appendix D Sections II.A and II.B. The Framework must (a) be a written articulation of the covered banks risk management framework with documented charter and approval by the Board, (b) cove...
OCCHS-2 · Risk Governance Framework: Three Lines of Defense, Scope, and Charter →Govern risk holistically including risk appetite, tolerance, and integration with strategy execution.
ISO37000-5.6 · Risk Governance →Requirement defined in ISO/IEC 38500:2024, clause 5.10 (Risk governance). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.
iso-iec-38500-2024::5.10 · Risk governance →Establish Board oversight of Open Banking risk through Board Audit Committee + Board Risk Committee with quarterly reporting + executive responsibility + Open Banking Manager appointment + risk appetite statements.
NGOB-8 · Board Oversight, Business Continuity, and Open Banking Risk Governance →Per AICPA SOC for Cybersecurity NIST CSF-aligned: Identify function. Requirements include (a) Asset Management + (b) Business Environment + (c) Governance + (d) Risk Assessment + (e) Risk Management Strategy + (f) Supply Chain Risk Management.
SOCCYB-1 · Identify Function: Asset, Risk, Governance, Business Environment →Per MAS Technology Risk Management Guidelines: TRM governance. Requirements include (a) Board + Senior Management oversight + (b) TRM framework + (c) risk appetite + (d) align with MAS Notices.
SGMASTRM-1 · Technology Risk Governance →Questions people ask about risk governance
What is Risk Governance?
Why is Risk Governance important for compliance?
Which compliance frameworks address Risk Governance?
Where can I learn more about Risk Governance?
See how Risk Governance applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.