Skip to main content

Risk Management Framework

Last updated: January 15, 2026

Enterprise Risk Management Policy

Document owner: Chief Information Security Officer (CISO), with CFO as co-owner Version: 3.0 Effective date: January 1, 2026 Last updated: January 15, 2026 Classification: Public — Trust Center Review cadence: Annual comprehensive review; quarterly risk register updates Company: Acme Cloud, Inc. Address: 1200 Market Street, Suite 400, San Francisco, CA 94103, USA Primary contacts: trust@acmecloud.com | security@acmecloud.com | privacy@acmecloud.com


Definitions and Key Terms

TermDefinition
RiskThe effect of uncertainty on objectives, measured as a combination of the probability of occurrence and the magnitude of impact
Enterprise Risk Management (ERM)A process applied across the enterprise designed to identify, assess, manage, and monitor potential events that may affect the organization
Risk AppetiteThe broad-based amount of risk an organization is willing to accept in pursuit of its mission and strategic objectives
Risk ToleranceThe specific maximum risk level acceptable for individual risk categories or activities
Risk RegisterA centralized repository documenting identified risks, their assessments, controls, and treatment status
Inherent RiskThe level of risk that exists before any risk treatment or control measures are applied
Residual RiskThe level of risk remaining after risk treatment measures have been applied
ControlA measure that modifies risk, including policies, procedures, guidelines, practices, or organizational structures
Risk TreatmentThe selection and implementation of options for addressing risk (accept, avoid, transfer, mitigate)
Risk OwnerAn individual or entity with accountability and authority to manage a specific risk
Control OwnerAn individual responsible for implementing and maintaining a specific control
Key Risk Indicator (KRI)A metric used to provide an early signal of increasing risk exposures in various areas of the enterprise
Risk AssessmentThe overall process of risk identification, risk analysis, and risk evaluation
ThreatA potential cause of an unwanted incident that may result in harm to a system, organization, or asset
VulnerabilityA weakness in an asset or control that can be exploited by one or more threats
ImpactThe result or effect of a risk event occurring
LikelihoodThe chance of a risk event occurring, expressed qualitatively or quantitatively
Business Impact Analysis (BIA)Process of analyzing business functions and the effect a disruption might have upon them
Control Self-AssessmentA management tool to assess and monitor the adequacy and effectiveness of internal controls
Three Lines ModelA model for organizing risk governance: first line (operational), second line (risk/compliance), third line (audit)
Risk Heat MapA visual representation of risks plotted by likelihood and impact to facilitate prioritization

Scope and Purpose

This Enterprise Risk Management Policy establishes Acme Cloud, Inc.'s framework for systematically identifying, assessing, treating, monitoring, and reporting risks across all business operations, technology systems, and strategic initiatives. The policy scope encompasses all risk categories affecting the organization including strategic, operational, financial, compliance, security, privacy, and reputational risks. The purpose is to enable informed risk-taking aligned with the organization's risk appetite, protect stakeholder value, ensure regulatory compliance, and support achievement of business objectives while maintaining appropriate controls.

Policy Applicability

Scope ElementIncludedExamples
Business OperationsYesRevenue operations, customer success, marketing, sales
Technology & SecurityYesInfrastructure, applications, data, security controls
FinancialYesRevenue, expenses, treasury, accounting, tax
Legal & ComplianceYesRegulatory compliance, contracts, litigation
Human ResourcesYesEmployment, workplace safety, talent management
StrategicYesMarket position, competition, M&A, partnerships
Third-PartyYesVendors, suppliers, business partners, customers
ReputationalYesBrand, public relations, stakeholder perception

Risk Governance Structure

Three Lines Model Implementation

LineFunctionResponsibilitiesKey Personnel
First LineOperational ManagementDay-to-day risk identification and control execution; process ownership; operational risk managementDepartment heads, team leads, individual contributors
Second LineRisk & Compliance FunctionsRisk framework development; policy oversight; compliance monitoring; risk aggregation and reportingCISO, General Counsel, Compliance team
Third LineInternal AuditIndependent assurance; control effectiveness testing; audit findings and recommendationsInternal Audit (outsourced), external auditors

Risk Governance Bodies

BodyCompositionRisk ResponsibilitiesMeeting Frequency
Board of Directors5 directors (3 independent)Risk oversight; risk appetite approval; strategic risk reviewQuarterly
Audit Committee3 independent directorsRisk management oversight; internal control assessment; audit coordinationQuarterly
Executive Risk CommitteeCEO, CFO, CISO, General CounselRisk appetite implementation; risk treatment decisions; escalation resolutionMonthly
Security Risk CommitteeCISO, VP Engineering, SRE Lead, Privacy OfficerSecurity and privacy risk assessment; control prioritization; incident reviewBi-weekly
Third-Party Risk CommitteeCISO, CFO, General Counsel, VP OperationsVendor risk assessment; contract risk review; supplier managementMonthly

Risk Management Roles

RoleResponsibilitiesAccountability
Board of DirectorsApprove risk appetite; provide risk oversight; ensure adequate resourcesUltimate governance accountability
CEOEnterprise risk strategy; risk culture; resource allocationExecutive accountability
CFOFinancial risk management; insurance; business continuity fundingFinancial risk ownership
CISOSecurity risk management; privacy risk; technology risk; ERM coordinationSecurity and technology risk
General CounselLegal risk; regulatory risk; compliance risk; contract riskLegal and compliance risk
Risk OwnersIndividual risk assessment; control implementation; risk monitoringAssigned risk categories
Control OwnersControl operation; control testing; gap remediationAssigned controls
Internal AuditIndependent assurance; control testing; findings reportingAudit assurance

Risk Appetite and Tolerance

Risk Appetite Statement

Acme Cloud, Inc. maintains a moderate overall risk appetite that supports innovation and growth while ensuring the security of customer data, compliance with regulatory obligations, and protection of organizational reputation. We accept calculated risks where the potential benefits to customers and the business justify the risk exposure and where effective controls can reduce residual risk to acceptable levels.

Risk Appetite by Category

Risk CategoryAppetite LevelAppetite DescriptionRationale
StrategicModerate-HighAccept measured strategic risks to pursue growth and market positionGrowth-stage company; competitive market
OperationalModerateAccept operational risks with strong controls and recovery capabilitiesBalanced efficiency and resilience
SecurityLowMinimal tolerance for security compromises; aggressive risk mitigationCustomer trust; regulatory requirements
PrivacyLowMinimal tolerance for privacy violations; strong data protectionCustomer trust; GDPR/CCPA compliance
FinancialModerateAccept financial risks within defined parameters and forecastingSustainable growth focus
ComplianceVery LowZero tolerance for intentional non-compliance; minimal residual exposureLegal obligations; certification requirements
ReputationalLowLimited tolerance for actions that could damage reputationBrand value; customer relationships
Third-PartyModerateAccept vendor risks with appropriate due diligence and monitoringOperational efficiency; managed outsourcing

Risk Tolerance Thresholds

Risk LevelLikelihood × Impact ScoreTreatment RequiredApproval Authority
Critical>20Immediate action required; cannot be acceptedBoard Audit Committee
High13-20Active treatment required; senior management approval to acceptExecutive Risk Committee
Medium7-12Treatment plan required; management monitoringDepartment head
Low1-6Accept with monitoring; standard controls sufficientRisk owner

Risk Assessment Methodology

Risk Identification Methods

MethodDescriptionFrequencyOwner
Annual Risk AssessmentComprehensive enterprise-wide risk identificationAnnualCISO
Departmental AssessmentsFunction-specific risk identification by business unitAnnualDepartment heads
Project Risk ReviewsRisk assessment for significant projects and initiativesPer projectProject lead
Vendor AssessmentsThird-party risk identification during onboarding and reviewPer vendor + annualThird-Party Risk Committee
Incident AnalysisRisk identification from security incidents and near-missesPer incidentSecurity team
Threat IntelligenceEmerging threat identification from external sourcesContinuousSecurity team
Compliance ScanningRegulatory and standards gap identificationQuarterlyCompliance team
Control Self-AssessmentFirst-line identification of control gapsAnnualControl owners
External AuditIndependent risk and control identificationAnnualInternal Audit

Likelihood Assessment Scale

RatingScoreDefinitionProbabilityTime Horizon
Rare1Extremely unlikely to occur<5%Would not occur within 5 years
Unlikely2Could occur in exceptional circumstances5-15%May occur once in 5 years
Possible3May occur at some point16-50%May occur once in 3 years
Likely4Will probably occur in most circumstances51-85%Will likely occur within 1 year
Almost Certain5Expected to occur; may have already occurred>85%Expected within 6 months

Impact Assessment Scale

RatingScoreFinancial ImpactOperational ImpactReputational ImpactCompliance Impact
Negligible1<$10KNo service disruptionNo media attentionDocumentation gap
Minor2$10K-$100K<1 hour disruptionMinor social mediaInternal audit finding
Moderate3$100K-$500K1-4 hours disruptionIndustry press coverageExternal audit finding
Major4$500K-$2M4-24 hours disruptionNational mediaRegulatory notice
Severe5>$2M>24 hours disruptionInternational media; customer lossRegulatory action; litigation

Risk Scoring Matrix

Negligible (1)Minor (2)Moderate (3)Major (4)Severe (5)
Almost Certain (5)5 (Medium)10 (Medium)15 (High)20 (High)25 (Critical)
Likely (4)4 (Low)8 (Medium)12 (Medium)16 (High)20 (High)
Possible (3)3 (Low)6 (Low)9 (Medium)12 (Medium)15 (High)
Unlikely (2)2 (Low)4 (Low)6 (Low)8 (Medium)10 (Medium)
Rare (1)1 (Low)2 (Low)3 (Low)4 (Low)5 (Medium)

Risk Register

Enterprise Risk Register Summary (FY2025)

Risk IDRisk DescriptionCategoryInherent RiskControlsResidual RiskOwnerTreatment
R-001Data breach exposing customer PIISecurityCritical (25)Encryption, access controls, monitoring, DLPHigh (12)CISOMitigate
R-002Ransomware attack disrupting operationsSecurityCritical (20)Endpoint protection, backups, segmentation, trainingMedium (8)CISOMitigate
R-003Third-party vendor breach affecting our dataThird-PartyHigh (16)Vendor assessment, contractual controls, monitoringMedium (9)CISOMitigate
R-004Regulatory compliance violation (GDPR/CCPA)ComplianceHigh (15)Privacy program, DPIAs, consent managementMedium (6)General CounselMitigate
R-005Service availability failure (>SLA)OperationalHigh (16)Redundancy, DR plan, monitoring, auto-scalingMedium (8)VP EngineeringMitigate
R-006Key personnel departureOperationalMedium (12)Documentation, cross-training, succession planningMedium (8)CPOMitigate
R-007Cloud provider outage or failureThird-PartyMedium (12)Multi-region deployment, DR plan, vendor SLALow (6)VP EngineeringAccept
R-008Insider threat (malicious or negligent)SecurityHigh (15)Access controls, monitoring, background checks, trainingMedium (9)CISOMitigate
R-009Economic downturn affecting revenueFinancialMedium (12)Diversified customer base, cost managementMedium (9)CFOAccept
R-010Competitor disruptionStrategicMedium (9)Product innovation, customer success focusMedium (9)CEOAccept

Top 10 Risks by Residual Score

RankRisk IDRisk DescriptionResidual ScoreTrendPrimary Control
1R-001Customer data breach12 (High)StableDefense-in-depth security
2R-008Insider threat9 (Medium)StableLeast privilege access
3R-003Vendor data breach9 (Medium)ImprovingThird-party risk management
4R-009Economic downturn9 (Medium)WorseningFinancial planning
5R-010Competitor disruption9 (Medium)StableProduct innovation
6R-002Ransomware attack8 (Medium)ImprovingEndpoint protection
7R-005Service availability8 (Medium)StableMulti-region redundancy
8R-006Key personnel loss8 (Medium)StableSuccession planning
9R-004Compliance violation6 (Low)ImprovingPrivacy program
10R-007Cloud provider failure6 (Low)StableMulti-region architecture

Risk Treatment

Treatment Options

TreatmentDescriptionWhen to ApplyExample
AcceptAcknowledge and retain the risk without additional actionRisk within tolerance; treatment cost exceeds benefitMinor operational inefficiencies
AvoidEliminate the risk by not engaging in the activityRisk exceeds appetite; no viable mitigationDeclining high-risk business opportunities
TransferShift risk impact to third partyInsurance available; contractual indemnification possibleCyber insurance; vendor SLAs
MitigateReduce likelihood or impact through controlsRisk above tolerance; effective controls availableSecurity controls; redundancy

Control Categories

CategoryDescriptionExamples
PreventiveControls that prevent risk events from occurringAccess controls, input validation, approval workflows
DetectiveControls that identify risk events when they occurMonitoring, alerting, anomaly detection, log analysis
CorrectiveControls that address the effects of risk eventsIncident response, backup restoration, disaster recovery
CompensatingAlternative controls when primary controls are infeasibleManual review when automation unavailable

Key Controls Summary

Control IDControl DescriptionRisk AddressedTypeOwnerTesting Frequency
C-001Multi-factor authenticationR-001, R-008PreventiveSecurityQuarterly
C-002Data encryption (at-rest and in-transit)R-001PreventiveSecurityAnnual
C-003Endpoint detection and responseR-002Preventive/DetectiveSecurityContinuous
C-004Security monitoring and SIEMR-001, R-002, R-008DetectiveSecurityContinuous
C-005Backup and disaster recoveryR-002, R-005CorrectiveSREQuarterly
C-006Vendor security assessmentR-003PreventiveSecurityAnnual per vendor
C-007Privacy impact assessmentsR-004PreventivePrivacyPer project
C-008Security awareness trainingR-001, R-002, R-008PreventiveSecurityAnnual
C-009Access reviewsR-001, R-008DetectiveSecurityQuarterly
C-010Incident response planR-001, R-002, R-003CorrectiveSecurityAnnual

Key Risk Indicators

Security KRIs

KRIDescriptionTargetAlert ThresholdFY2025 Q4 Actual
KRI-S01Security incidents (SEV1-2)0 per quarter>10
KRI-S02Mean time to detect (MTTD)<1 hour>4 hours47 minutes
KRI-S03Mean time to contain (MTTC)<4 hours>8 hours2.3 hours
KRI-S04Phishing click rate<5%>10%4.2%
KRI-S05Critical vulnerabilities (unpatched >30 days)0>50
KRI-S06Security training completion>95%<90%98.2%
KRI-S07Privileged access reviews current100%<95%100%

Operational KRIs

KRIDescriptionTargetAlert ThresholdFY2025 Q4 Actual
KRI-O01Service availability99.9%<99.5%99.95%
KRI-O02Change success rate>98%<95%99.2%
KRI-O03Backup success rate100%<99%100%
KRI-O04DR test successPassFailPass
KRI-O05Critical on-call response time<15 min>30 min8 minutes

Compliance KRIs

KRIDescriptionTargetAlert ThresholdFY2025 Q4 Actual
KRI-C01Open audit findings (critical)0>00
KRI-C02Policy attestation completion100%<95%100%
KRI-C03DSR response within SLA100%<95%100%
KRI-C04Vendor assessments current100%<90%97%

Third-Party KRIs

KRIDescriptionTargetAlert ThresholdFY2025 Q4 Actual
KRI-T01Critical vendor SLA compliance100%<99%99.8%
KRI-T02Vendor security incidents0>10
KRI-T03Vendor risk assessments overdue0>52

Risk Monitoring and Reporting

Reporting Cadence

ReportAudienceFrequencyContentOwner
KRI DashboardExecutive Risk CommitteeReal-timeKRI status, alerts, trendsCISO
Risk Register UpdateExecutive Risk CommitteeMonthlyRisk changes, new risks, treatment progressCISO
Executive Risk SummaryBoard Audit CommitteeQuarterlyTop risks, KRI trends, significant eventsCEO/CISO
Detailed Risk AssessmentBoard of DirectorsAnnualComprehensive risk landscape, strategic risksCEO
Third-Party Risk ReportThird-Party Risk CommitteeMonthlyVendor risks, assessment status, incidentsCISO
Compliance Risk ReportExecutive Risk CommitteeQuarterlyRegulatory risks, audit findings, compliance gapsGeneral Counsel

Risk Dashboard Metrics

Metric CategoryMetrics DisplayedUpdate Frequency
Overall Risk PostureRisk score trend, critical/high count, risk appetite adherenceDaily
Top RisksTop 10 by residual score with trend indicatorsWeekly
Control EffectivenessControl testing results, failure rates, remediation statusMonthly
KRI StatusAll KRIs with RAG status and trendReal-time where automated
Incident CorrelationSecurity incidents linked to risk registerPer incident
Treatment ProgressOpen treatments by status and due dateWeekly

Numbered Policy Statements

  1. Risk Management Mandate: Acme Cloud, Inc. shall maintain a comprehensive enterprise risk management program that identifies, assesses, treats, monitors, and reports risks across all business functions.

  2. Board Oversight: The Board of Directors, through the Audit Committee, shall provide oversight of the enterprise risk management program and approve the organizational risk appetite statement.

  3. Risk Appetite Compliance: All business decisions with material risk implications shall be evaluated against the approved risk appetite and tolerance thresholds.

  4. Risk Assessment Requirement: Formal risk assessments shall be conducted annually for the enterprise, for each significant project, and for each third-party relationship.

  5. Risk Register Maintenance: A centralized risk register shall be maintained documenting all identified risks, assessments, controls, and treatment status, with updates at least quarterly.

  6. Risk Ownership: Every identified risk shall have an assigned risk owner accountable for monitoring the risk and implementing approved treatments.

  7. Control Effectiveness: Controls shall be tested for effectiveness at frequencies appropriate to the risk level they address, with results documented and reported.

  8. KRI Monitoring: Key risk indicators shall be defined for critical risk categories and monitored continuously or at frequencies that enable timely detection of increasing risk exposure.

  9. Escalation Requirement: Risks exceeding tolerance thresholds shall be escalated to the appropriate governance body within 24 hours of identification.

  10. Treatment Accountability: Risk treatment plans shall include specific actions, responsible owners, target dates, and success criteria, with progress tracked and reported.

  11. Third-Party Risk: Third-party risks shall be assessed during vendor selection, at contract renewal, and when material changes occur, with findings integrated into the enterprise risk register.

  12. Incident Integration: Security and operational incidents shall be analyzed for risk register implications, with new risks added and existing risk assessments updated as appropriate.

  13. Training Requirement: Personnel with risk management responsibilities shall receive training appropriate to their role at onboarding and annually thereafter.

  14. Continuous Improvement: The risk management program shall be reviewed annually for effectiveness, with improvements implemented based on lessons learned, industry developments, and regulatory changes.


Framework Appendix

Compliance and Standards Mapping

RequirementSOC 2 CriteriaISO 27001 ControlNIST CSFImplementation
Risk assessmentCC3.1, CC3.26.1.2, A.5.1ID.RAAnnual enterprise assessment
Risk treatmentCC3.36.1.3ID.RMTreatment planning process
Risk monitoringCC4.19.1ID.RA-5KRI program
Risk reportingCC4.29.3ID.RM-2Governance reporting
Control assessmentCC4.19.2DE.DPControl testing program
Management reviewCC1.29.3ID.GVGovernance meetings

ISO 27001 Risk Management Alignment

ISO 27001 ClauseRequirementPolicy Implementation
6.1.1Actions to address risks and opportunitiesRisk identification methods
6.1.2Information security risk assessmentRisk assessment methodology
6.1.3Information security risk treatmentTreatment options and plans
8.2Information security risk assessmentPeriodic assessments
8.3Information security risk treatmentTreatment implementation
A.5.1Policies for information securityThis policy document

NIST Cybersecurity Framework Mapping

CSF FunctionCategoryPolicy Implementation
IdentifyID.GVGovernance structure
IdentifyID.RARisk assessment methodology
IdentifyID.RMRisk management strategy
IdentifyID.SCSupply chain risk
ProtectPRControl implementation
DetectDEKRI monitoring
RespondRSIncident integration
RecoverRCBusiness continuity

Related Trust Center documents

security overview, third party risk, incident response, business continuity, compliance frameworks, vendor code of conduct, access control


Document revision history

VersionDateAuthorSummary of changes
1.02024-06-01Legal & ComplianceInitial Trust Center publication
2.02025-03-15GRC ProgramSOC 2 Type II alignment refresh; expanded subprocessors
2.52025-09-01Security EngineeringEncryption standards update; ISO 27001 mapping
3.02026-01-15Trust Center ProgramFull procurement-grade expansion; 34-document set

Contact

Acme Cloud, Inc. 1200 Market Street, Suite 400 San Francisco, CA 94103, USA

ChannelEmailUse case
Trust & procurementtrust@acmecloud.comSecurity questionnaires, trust reviews
Securitysecurity@acmecloud.comIncidents, vulnerabilities, control questions
Privacyprivacy@acmecloud.comDSRs, privacy assessments
Legallegal@acmecloud.comContractual, DPA, legal notices

Risk Management Program Contacts

ContactRoleResponsibility
security@acmecloud.comCISO OfficeERM program coordination; risk questions
trust@acmecloud.comTrust TeamCustomer risk inquiries; audit support
legal@acmecloud.comLegal DepartmentCompliance risk; contract risk
risk@acmecloud.comRisk TeamRisk register; assessment support

Appendix: Risk Management Calendar

ActivityFrequencyQ1Q2Q3Q4
Enterprise Risk AssessmentAnnual
Departmental AssessmentsAnnual
Risk Register UpdateQuarterly
Board Risk ReportQuarterly
KRI ReviewMonthly
Control TestingPer scheduleOngoingOngoingOngoingOngoing
Third-Party AssessmentsAnnual per vendorOngoingOngoingOngoingOngoing
Policy ReviewAnnual

Document Version: 3.0 Last Updated: January 15, 2026

Last updated: January 15, 2026
EthicPages logoEthicPages