# XGRC® Enterprise Risk Management

_Enterprise Risk Intelligence_

**Risk managed at enterprise scale, not spreadsheet scale.**

A structured, auditable approach to enterprise, operational, and project risk — aligned to ISO 31000 and COSO ERM — with board-level dashboards, risk appetite monitoring, and corrective action tracking built in.

## What it is

Enterprise risk management software helps organisations identify, assess, treat, monitor and report on risks across business units, projects, strategic objectives and operational environments.

## Overview

XGRC® ERM provides a complete enterprise risk management platform — from risk identification and appetite-setting through treatment planning, KRI monitoring, and board-level reporting — with every element linked to governance, controls, and assurance.

## When organisations use it

Organisations typically adopt XGRC® ERM when risk registers are maintained annually in spreadsheets, risk appetite thresholds are set but not enforced, and the board has no real-time view of residual risk. The XGRC® ERM solution connects enterprise risk to controls, assurance, compliance obligations, incidents and actions within the same secure data foundation used across XGRC® Software.

## What it is not

ERM is not a static annual risk register exercise. It is a live risk management system with board dashboards, KRI monitoring and appetite-breach alerts — designed to stay current between review cycles, not just at them.

## Challenges it addresses

- **Risk registers nobody maintains** — Annual reviews produce impressive registers that are outdated before they are presented. Residual risk is never re-assessed.
- **Risk appetite defined, but not enforced** — The board sets appetite thresholds. Operational decisions ignore them. There is no mechanism to detect or escalate breaches.
- **KRIs reported in isolation** — Key risk indicators tracked separately from the risks they monitor. Early warning signals go unnoticed until they become incidents.
- **Risk and assurance disconnected** — The audit plan bears no relationship to the risk register. High-risk areas go unaudited. Low-risk areas receive excess coverage.

## Modules

- **Risk Identification:** Risk Register, Risk Categorisation, Emerging Risk Tracking, Risk Event Capture
- **Assessment & Appetite:** Likelihood & Impact Scoring, Risk Appetite Thresholds, Tolerance Monitoring, Heat Map Visualisation
- **Treatment & Action:** Treatment Plans, Action Accountability, Escalation & Breach Alerts, Residual Risk Tracking
- **Monitoring & Reporting:** KRI Monitoring, Board Dashboards, Management Reporting, Trend Analysis

## Standards & frameworks

- ISO 31000
- COSO ERM
- King V
- IFRS

## Frequently asked questions

### Is XGRC® ERM aligned to ISO 31000?

Yes. ERM is aligned to ISO 31000 and COSO ERM, with King V and IFRS-aligned reporting for South African organisations.

### Can ERM link to our internal audit function?

Yes. ERM connects directly to Integrated Assurance, so the audit plan reflects the current risk landscape rather than last year's assumptions.

### Does ERM support board-level reporting?

Yes. ERM includes real-time board dashboards, risk appetite monitoring and trend analysis built for board and audit committee reporting.

### How is ERM different from a risk spreadsheet?

ERM keeps risk data live and linked — appetite breaches, KRI thresholds and treatment plans are monitored continuously, with full audit trails, rather than reconciled manually once a year.

## Related solutions

- [Integrated Assurance](https://xgrcsoftware.com/integrated-assurance)
- [MSX®](https://xgrcsoftware.com/msx)
- [MSXCyber®](https://xgrcsoftware.com/msxcyber)

---

Source: https://xgrcsoftware.com/erm
