Enterprise Risk Management Engine

Identify and assess enterprise risks using ISO 31000 and COSEM frameworks.

2|1|Updated Feb 13, 2026
One-click install
npx skills add https://github.com/simplefarmer69/ape-claw --skill enterprise-risk-management-engine
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Enterprise Risk Management Engine
Source: https://github.com/simplefarmer69/ape-claw/tree/main/data/forge-skills/clawhub-afrexai-risk-management
Command: npx skills add https://github.com/simplefarmer69/ape-claw --skill enterprise-risk-management-engine

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a comprehensive framework and tools to systematically identify, assess, treat, and monitor risks across an organization, ensuring resilience and strategic alignment.

Core Features & Use Cases

  • Risk Universe Definition: Covers 8 key risk categories (Strategic, Financial, Operational, Compliance, Cyber, Reputational, People, External) with detailed sub-risks.
  • Assessment Tools: Includes a 5x5 Likelihood x Impact matrix, risk velocity assessment, and interconnection mapping.
  • Treatment & Mitigation: Offers a decision framework for risk treatment strategies (Accept, Mitigate, Transfer, Avoid) and control design principles.
  • Monitoring & Reporting: Defines Key Risk Indicators (KRIs) with actionable thresholds and outlines structures for management and board-level risk reporting.
  • Scenario Analysis: Provides templates for designing and analyzing severe risk scenarios and conducting stress tests.
  • Use Case: A company can use this Skill to conduct its annual enterprise-wide risk assessment, identify its top 5 critical risks, define mitigation plans with owners and deadlines, and establish KRIs to monitor their effectiveness.

Quick Start

Use the Enterprise Risk Management Engine skill to identify and assess the top 3 strategic risks for a SaaS startup in the fintech sector.

Frequently Asked Questions about Enterprise Risk Management Engine

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct enterprise risk management based on ISO 31000 and COSO ERM frameworks?

Enterprise risk management based on ISO 31000 and COSO ERM frameworks involves identifying risks across eight categories, assessing them using likelihood-impact matrices, selecting treatment strategies, and defining Key Risk Indicators for monitoring. This Skill provides structured methodologies to execute this entire process.

What is the best way to perform a quantitative risk assessment using a likelihood-impact matrix?

A quantitative risk assessment using a likelihood-impact matrix evaluates risks on a 5x5 scale to determine severity. This Skill facilitates matrix-based assessment, risk velocity evaluation, and interconnection mapping to prioritize mitigation efforts effectively across the organization.

How do I define Key Risk Indicators (KRIs) with actionable thresholds for compliance monitoring?

Defining Key Risk Indicators (KRIs) with actionable thresholds for compliance monitoring requires establishing metrics that signal increasing risk exposure. This Skill provides methodology to establish KRI thresholds and outlines structures for management and board-level risk reporting.

Can I use this ERM framework to conduct scenario analysis and stress tests for business continuity planning?

Yes, you can use this ERM framework for scenario analysis and stress tests to support business continuity planning. It provides templates for designing severe risk scenarios and conducting stress tests, alongside Business Impact Assessments (BIAs) and crisis response frameworks.

Does this risk management methodology cover cyber, financial, and reputational risk categories?

Yes, this risk management methodology covers cyber, financial, and reputational risks. It defines a risk universe across eight key categories including Strategic, Financial, Operational, Compliance, Cyber, Reputational, People, and External risks with detailed sub-risks.

How do I select a risk treatment strategy between accepting, mitigating, transferring, or avoiding a risk?

Selecting a risk treatment strategy involves deciding whether to accept, mitigate, transfer, or avoid a risk based on assessment results. This Skill offers a decision framework for treatment strategy selection and control design principles to guide mitigation planning.