Roshan Kumar & Associates (RKACA)

Chartered Accountants

/ Services / Enterprise Risk Management (ERM)
Risk Advisory & Governance

Enterprise Risk Management (ERM)

Design and implement a structured Enterprise Risk Management framework. Identify, assess, prioritize, and manage risks aligned to your strategic objectives.

Who This Is For:

  • Boards wanting structured oversight of organizational risk
  • Companies scaling up from informal risk management
  • Financial institutions with regulatory risk management requirements
  • NGOs and INGOs with donor-mandated risk management frameworks
  • Companies planning major expansion or transformation

What We Deliver:

  • Risk Governance Framework (roles, responsibilities, escalation)
  • Enterprise-wide Risk Assessment (qualitative and quantitative)
  • Risk Register (with scoring, ownership, and response plans)
  • Risk Appetite Statement (Board-level)
  • Key Risk Indicators (KRIs) dashboard
  • Risk Reporting pack for Board and Management
  • Quarterly risk review facilitation
  • Annual risk reassessment

Our ERM Process:

Step 1 — Risk Governance Framework:

  • Define risk management roles (Board, Risk Committee, Management, Process Owners)
  • Establish risk governance policies
  • Set risk appetite and tolerance levels
  • Define escalation and reporting procedures

Step 2 — Risk Identification:

  • Strategic risks (threats to business model and objectives)
  • Operational risks (process failures, people, systems)
  • Financial risks (liquidity, credit, market)
  • Compliance risks (regulatory, legal, contractual)
  • Reputational risks
  • External risks (economic, political, environmental)

Step 3 — Risk Assessment:

  • Likelihood scoring (1–5 scale)
  • Impact scoring (1–5 scale: financial, operational, reputational)
  • Inherent risk rating (likelihood x impact)
  • Residual risk rating (after existing controls)
  • Risk heat map development

Step 4 — Risk Response:

  • Tolerate (accept and monitor)
  • Treat (implement controls to reduce)
  • Transfer (insurance or contractual)
  • Terminate (exit the risk-generating activity)


Step 5 — Risk Register:

  • Risk owner assignment
  • Control description
  • Action plan for risk reduction
  • Target residual risk level
  • Review date

Step 6 — KRI Development:

  • Leading indicators for top 10 risks
  • Early warning thresholds (amber/red triggers)
  • KRI data source and collection frequency
  • KRI dashboard for management


Step 7 — Ongoing Risk Monitoring:

  • Quarterly risk review meetings
  • KRI monitoring and escalation
  • Annual risk reassessment

FAQ:

Q: What's the difference between risk management and internal audit?

A: Risk management designs the system to prevent things from going wrong. Internal audit independently tests whether that system is working. Both are necessary.

Q: How long does an ERM implementation take?

A: Typically 4–8 weeks for initial implementation. Ongoing quarterly facilitation keeps it alive.

Ready to Elevate Your Business?

Contact us today to learn how Enterprise Risk Management (ERM) can drive your success.

Get in Touch

Ready to discuss your business needs? Fill out the form below and one of our experts will get back to you within 24 hours.

Email format is valid!
Phone number format is valid!

Main Office - Biratnagar

Address:Biratnagar, Nepal

Phone: +977-9860675996

Email: info@rkaca.com.np

Business Hours

  • Monday - Friday: 9:00 AM - 6:00 PM
  • Saturday: 9:00 AM - 2:00 PM
  • Sunday: Closed

Follow Us

Enhanced Footer