risk-manager

Identify, assess, and manage business risks using the ISO 31000 framework.

1|Updated Dec 7, 2025
One-click install
npx skills add https://github.com/CoachSteff/superskills --skill risk-manager-coachsteff
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk-manager
Source: https://github.com/CoachSteff/superskills/tree/main/superskills/risk-manager
Command: npx skills add https://github.com/CoachSteff/superskills --skill risk-manager-coachsteff

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Risk leadership and governance are often fragmented and manual; this skill provides a structured approach to applying ISO 31000 to identify, analyze, treat, and monitor risks across business operations.

Core Features & Use Cases

  • Structured risk identification across strategic, operational, financial, and compliance domains.
  • Systematic analysis and evaluation with a focus on likelihood, impact, risk prioritization, and alignment to risk appetite.
  • Comprehensive risk treatment and monitoring, including ownership, timelines, and residual risk tracking.
  • Use Case: Conduct a complete risk assessment for a new initiative to surface regulatory, operational, and market risks and define mitigation actions.

Quick Start

Run the risk-manager workflow to identify, assess, and treat risks using ISO 31000.

Frequently Asked Questions about risk-manager

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct an ISO 31000 risk assessment for a new business initiative?

An ISO 31000 risk assessment identifies, analyzes, and treats strategic, operational, financial, and compliance risks. The structured workflow evaluates likelihood and impact, prioritizes risks based on appetite, and defines mitigation actions with clear ownership and monitoring timelines.

What is the best way to structure enterprise risk management across multiple domains?

Enterprise risk management structures risks across strategic, operational, financial, and compliance domains. It applies a systematic framework to align risk evaluation with organizational appetite, ensuring comprehensive treatment planning and continuous monitoring of residual risks for ongoing governance.

How do I evaluate and prioritize business risks during a project risk analysis?

Evaluating and prioritizing business risks involves analyzing likelihood and impact to align findings with your organizational risk appetite. This systematic evaluation surfaces key vulnerabilities, allowing you to rank threats and prioritize mitigation actions effectively across enterprise projects and programs.

Can I use ISO 31000 workflows for ongoing operational and compliance governance?

Yes, ISO 31000 workflows apply to ongoing operational and compliance governance. The framework supports continuous risk monitoring, residual risk tracking, and systematic treatment updates, ensuring sustained enterprise risk leadership and integrated compliance management across business operations.

What is included in a comprehensive risk treatment and mitigation plan?

A comprehensive risk treatment plan includes defined mitigation actions, assigned ownership, and specific timelines. It tracks residual risk after treatment, ensuring continuous monitoring and alignment with organizational risk appetite throughout the enterprise risk management lifecycle.