RiskPedia
SG
Risk Frameworks

The Encyclopedia.

32+ risk frameworks indexed with complexity, certification status and time-to-implement — searchable, filterable, comparable.

Universal
ISO 31000
Risk Management Guidelines

International standard providing principles and generic guidelines on risk management applicable to any organisation regardless of size, activity or sector.

Low · 3-6 monthsNo cert
Enterprise
COSO ERM
Enterprise Risk Management — Integrating with Strategy and Performance

Globally recognized framework for enterprise risk management, internal control and fraud deterrence.

Medium · 6-12 monthsNo cert
Cyber
NIST RMF
Risk Management Framework (SP 800-37)

Structured process to integrate security, privacy and cyber supply-chain risk management activities into the system development life cycle.

High · 9-18 monthsNo cert
Cyber
ISO/IEC 27001:2022
Information Security Management Systems

Specification for an information security management system (ISMS) — covering people, processes and technology.

Medium · 6-12 monthsCert. track
Banking
Basel III / IV
Banking capital and liquidity standards

Global regulatory framework on bank capital adequacy, stress testing and market liquidity risk, finalized by BCBS.

High · 12-24 monthsNo cert
Singapore
MAS TRM
Technology Risk Management Guidelines 2021

MAS Technology Risk Management Guidelines for financial institutions in Singapore. Covers IT governance, third-party risk, cyber resilience and cloud.

High · 6-12 monthsNo cert
Singapore
MAS Notice 655
Cyber Hygiene

Mandatory minimum cyber hygiene measures for banks and FIs in Singapore — admin accounts, security patches, malware, multi-factor.

Medium · 3-6 monthsNo cert
Singapore
PDPA 2012 (Singapore)
Personal Data Protection Act

Singapore's baseline data protection law governing collection, use and disclosure of personal data, with mandatory breach notification (since 2021).

Medium · 4-8 monthsNo cert
Insurance
Solvency II
EU insurance prudential regime

EU directive that codifies and harmonises insurance regulation, focusing on capital adequacy and risk-based supervision.

High · 12-24 monthsNo cert
IT Governance
COBIT 2019
IT Governance Framework

ISACA framework for the governance and management of enterprise IT, with focus on stakeholder value.

Medium · 6-9 monthsCert. track
Enterprise
FERMA RMS
Federation of European Risk Management Associations Standard

European risk management standard providing a common terminology and process for risk management.

Low · 3-6 monthsNo cert
Project
PMBOK / PMI
Project Management Body of Knowledge

Standard for project management with detailed risk management knowledge area (PMI).

Medium · ongoingCert. track
Project
PRINCE2
Projects in Controlled Environments

Process-based method for effective project management, widely used in UK government and globally.

Medium · ongoingCert. track
Enterprise
M_o_R
Management of Risk

AXELOS framework for the management of risk across strategy, programme, project and operational levels.

Medium · 6-9 monthsCert. track
Agile
SAFe
Scaled Agile Framework

Framework for applying lean and agile practices at enterprise scale.

High · 12+ monthsCert. track
Quality
Six Sigma
DMAIC / DMADV process improvement

Set of techniques and tools for process improvement, reducing defects to 3.4 per million opportunities.

Medium · ongoingCert. track
Quality
Lean Six Sigma
Lean + Six Sigma combined

Method that combines lean manufacturing/lean enterprise with Six Sigma to eliminate waste and reduce variation.

Medium · ongoingCert. track
Quality
FMEA
Failure Mode and Effects Analysis

Step-by-step approach for identifying all possible failures in a design, manufacturing process, product or service.

Low · 1-3 monthsNo cert
Quality
ISO 9001:2015
Quality Management Systems

International standard for quality management systems with risk-based thinking.

Medium · 6-9 monthsCert. track
Operational
Bow-Tie Analysis
Risk barrier visualisation

Visual risk assessment tool combining fault tree and event tree analyses on a single diagram.

Low · 1-2 monthsNo cert
Quantitative
Monte Carlo Simulation
Probabilistic risk modelling

Computational technique for understanding the impact of risk and uncertainty using random sampling.

Medium · 1-3 monthsNo cert
Operational
FTA
Fault Tree Analysis

Top-down, deductive failure analysis using boolean logic to combine lower-level events.

Medium · 2-4 monthsNo cert
Operational
HAZOP
Hazard and Operability Study

Structured and systematic examination of a complex process to identify hazards and operability problems.

Medium · 2-4 monthsNo cert
Operational
RCA
Root Cause Analysis

Method of problem solving used for identifying the root causes of faults or problems.

Low · 1-2 monthsNo cert
Strategic
SWOT & PESTLE
Strategic risk scans

Strategic risk scanning frameworks for environmental analysis and internal capability mapping.

Low · 1 monthNo cert
IT Governance
ITIL 4
IT Service Management

Best practices for delivering IT services aligned to business needs, with risk and continuity practices.

Medium · 6-12 monthsCert. track
Cyber
NIS2 Directive
EU Cybersecurity Directive (2023)

EU directive on measures for a high common level of cybersecurity across the Union, replacing NIS Directive.

High · 9-15 monthsNo cert
Cyber
DORA
Digital Operational Resilience Act

EU regulation creating a binding ICT risk management framework for the financial services sector.

High · 12-18 monthsNo cert
Cyber
SOC 2
AICPA Trust Services Criteria

Auditing procedure ensuring service providers securely manage data to protect interests of organisation and clients.

Medium · 6-12 monthsCert. track
Operational
ISO 22301
Business Continuity Management

Specifies requirements to plan, establish, implement and maintain a business continuity management system.

Medium · 6-9 monthsCert. track
ESG
TCFD / ISSB
Climate-related financial disclosures

Framework for disclosing the financial impacts of climate-related risks and opportunities — now folded into ISSB IFRS S2.

Medium · 6-12 monthsNo cert
Compliance
ISO 37301
Compliance Management Systems

Specifies requirements and provides guidelines for establishing, developing, implementing a compliance management system.

Medium · 6-9 monthsCert. track

Made with Emergent