# Enterprise Risk Management Methodology Overview

**Clearspeed, Inc.**

---

## Framework Foundation

This ERM methodology is built on established, internationally recognized risk management frameworks — not invented from scratch. The approach synthesizes proven practices from:

| Framework | Source | How We Apply It |
|-----------|--------|-----------------|
| **ISO 31000:2018** | International Organization for Standardization | Core risk management process, principles, and terminology |
| **COSO ERM (2017)** | Committee of Sponsoring Organizations | Governance structure, risk appetite integration with strategy |
| **NIST SP 800-39** | National Institute of Standards and Technology | Tiered risk management, organizational risk framing |
| **NIST CSF 2.0** | NIST Cybersecurity Framework | Govern function, risk-informed decision making |
| **FAIR** | Factor Analysis of Information Risk | Impact categorization approach (financial, operational) |

---

## ISO 31000:2018 Alignment

ISO 31000 is the international standard for risk management. Our methodology directly implements its core process:

### ISO 31000 Risk Management Process → Our Implementation

| ISO 31000 Element | Our Implementation |
|-------------------|-------------------|
| **Scope, Context, Criteria** | Risk categories (Strategic, Operational, Financial, Compliance, Reputational); defined scoring criteria |
| **Risk Identification** | Departmental walkthroughs, incident analysis, external intelligence gathering |
| **Risk Analysis** | Likelihood × Impact scoring with defined rubrics |
| **Risk Evaluation** | Comparison against risk appetite thresholds |
| **Risk Treatment** | Four options: Mitigate, Transfer, Accept, Avoid |
| **Monitoring & Review** | Monthly owner updates, quarterly ERC review, annual framework review |
| **Communication & Consultation** | ERC governance, escalation paths, stakeholder reporting |

**ISO 31000 Principle Applied:** *"Risk management is part of decision making"* — Our appetite thresholds create clear decision triggers, not just awareness.

---

## COSO ERM Framework Alignment

COSO's 2017 *Enterprise Risk Management—Integrating with Strategy and Performance* provides our governance foundation:

### COSO Components → Our Implementation

| COSO Component | Our Implementation |
|----------------|-------------------|
| **Governance & Culture** | ERC charter, defined roles (Risk Owners), escalation accountability |
| **Strategy & Objective-Setting** | Risk appetite statement tied to strategic objectives (e.g., $100M ARR path) |
| **Performance** | Risk scoring integrated with operational decisions; treatment tracking |
| **Review & Revision** | Quarterly ERC reviews, annual appetite recalibration |
| **Information, Communication & Reporting** | Dashboard, monthly/quarterly reporting cadence, Board summaries |

**COSO Principle Applied:** *"Risk appetite guides resource allocation"* — Our thresholds (Critical: 0, High: 3, Medium: 10) drive where mitigation investment goes.

---

## NIST Risk Management Alignment

### NIST SP 800-39: Managing Information Security Risk

Our three-tier approach mirrors NIST's organizational risk management hierarchy:

| NIST Tier | Scope | Our Implementation |
|-----------|-------|-------------------|
| **Tier 1: Organization** | Enterprise-wide governance | ERC oversight, risk appetite statement, policy |
| **Tier 2: Mission/Business** | Departmental risk ownership | Risk owners by function, category-specific treatment |
| **Tier 3: System** | Operational controls | Specific mitigations, control implementation |

### NIST SP 800-30: Risk Assessment Guidance

Our scoring rubric derives from NIST 800-30's qualitative assessment approach:

| NIST 800-30 Concept | Our Implementation |
|--------------------|-------------------|
| Threat likelihood assessment | 5-level likelihood scale with probability ranges |
| Impact magnitude | 5-level impact scale across multiple dimensions |
| Semi-quantitative risk matrix | Likelihood × Impact = Risk Score (1-25) |
| Risk level determination | Four risk levels with defined response requirements |

**Why 5×5 Matrix?** NIST 800-30 recommends scales that balance granularity with usability. A 5×5 matrix (25 possible scores) provides sufficient differentiation without false precision.

---

## NIST CSF 2.0: Govern Function

The 2024 update to NIST Cybersecurity Framework added "Govern" as a core function. Our methodology implements key Govern subcategories:

| CSF 2.0 Subcategory | Our Implementation |
|--------------------|-------------------|
| **GV.RM-01** | Risk management objectives established by ERC |
| **GV.RM-02** | Risk appetite and tolerance statements documented |
| **GV.RM-03** | Risk management activities integrated into strategy discussions |
| **GV.RM-05** | Risk communication lines established (owners → ERC → Board) |
| **GV.RM-06** | Standardized risk assessment methodology |

---

---

## Dashboard Implementation

The Clearspeed ERM Dashboard (https://clearspeed-app.com) is the operational embodiment of this methodology. Every framework principle maps to a specific platform capability:

### Framework → Dashboard Feature Mapping

| Framework Principle | Dashboard Implementation |
|--------------------|-------------------------|
| **Risk Identification** (ISO 31000) | AI-powered transcript extraction from ERC meetings; manual risk entry form |
| **Risk Analysis** (NIST 800-30) | Likelihood (1-5) and Impact (1-5) dropdowns with defined criteria |
| **Risk Scoring** (NIST 800-30) | Automatic calculation: Score = Likelihood × Impact |
| **Risk Evaluation** (ISO 31000) | Heat map visualization; color-coded risk levels |
| **Risk Appetite** (COSO) | Real-time appetite status banner; threshold indicators on each metric |
| **Risk Treatment** (ISO 31000) | Treatment status field (Mitigate/Transfer/Accept/Avoid) per risk |
| **Risk Ownership** (COSO) | Assigned owner field with accountability tracking |
| **Monitoring** (ISO 31000) | Dashboard metrics update in real-time; trend tracking |
| **Communication** (COSO) | Department filters; exportable risk register; stakeholder views |

### Dashboard Views & Their Purpose

| View | Framework Basis | Business Use |
|------|-----------------|--------------|
| **Risk Heat Map** | NIST 800-30 risk matrix | Visual risk distribution; identify clustering |
| **By Department Chart** | COSO organizational alignment | Departmental accountability; resource allocation |
| **By Category Chart** | ISO 31000 risk categorization | Portfolio view; identify systemic risks |
| **Risk Register Table** | ISO 31000 documentation | Detailed risk information; audit evidence |
| **Appetite Status Banner** | COSO risk appetite | Real-time threshold compliance; escalation trigger |

### Appetite Thresholds in Dashboard

The dashboard enforces COSO's risk appetite principle through visual indicators:

| Metric Card | Threshold | Dashboard Behavior |
|-------------|:---------:|-------------------|
| Critical (20-25) | 0 | Red indicator if count > 0 |
| High (15-19) | 3 | Red indicator if count > 3 |
| Medium (8-14) | 10 | Red indicator if count > 10 |

**Appetite Banner States:**
- 🟢 **Within Tolerance** — All risk counts below thresholds
- 🔴 **Exceeded** — One or more thresholds breached; displays which levels exceeded

### Risk Entry Workflow

The dashboard enforces methodology compliance through structured data entry:

```
1. IDENTIFY → Enter risk title, description, department, category
2. ANALYZE  → Select Likelihood (1-5) and Impact (1-5) from defined criteria
3. SCORE    → System calculates Risk Score automatically
4. ASSIGN   → Designate Risk Owner
5. TREAT    → Select treatment approach (Mitigate/Transfer/Accept/Avoid)
6. TRACK    → Risk appears in register; updates reflected in real-time metrics
```

### AI-Assisted Risk Extraction

The dashboard includes AI-powered risk identification from ERC meeting transcripts:

| Capability | Framework Alignment |
|------------|---------------------|
| Upload meeting transcript | ISO 31000: Risk identification through consultation |
| AI extracts risk statements | Structured capture of unstructured discussions |
| Pre-populated risk fields | Consistent application of scoring criteria |
| Human review before save | Governance oversight; quality control |

This accelerates the ISO 31000 identification process while maintaining human judgment in final risk assessment.

### Audit Trail & Evidence

The dashboard maintains documentation required for audit defensibility:

- **Risk creation timestamps** — When each risk was identified
- **Source tracking** — Manual entry vs. AI-extracted (with source file reference)
- **Score history** — Supports trend analysis over time
- **Treatment documentation** — What decision was made and by whom

---

## Impact Assessment Depth: FAIR Principles

While we use qualitative scoring (not full quantitative FAIR analysis), our impact categories reflect FAIR's loss magnitude taxonomy:

| FAIR Loss Form | Our Impact Dimension |
|----------------|---------------------|
| Productivity Loss | Operational Impact (disruption duration) |
| Response Cost | Financial Impact (remediation costs) |
| Replacement Cost | Financial Impact (asset replacement) |
| Competitive Advantage | Strategic Impact |
| Reputation Damage | Reputational Impact |
| Fines & Judgments | Compliance Impact |

**Scaling Path:** As the program matures, high-priority risks can be assessed using full FAIR quantitative analysis for investment justification.

---

## Why This Matters: Defensibility

This methodology is defensible because:

1. **Auditor Recognition** — ISO 31000 and COSO are the frameworks auditors expect. SOC 2, ISO 27001, and regulatory audits recognize this lineage.

2. **Board Credibility** — COSO ERM is the standard for board-level risk reporting. Directors understand this language.

3. **Regulatory Alignment** — NIST frameworks are referenced in CMMC, FedRAMP, and federal contracting requirements.

4. **Scalability** — The framework supports growth from qualitative assessment to quantitative (FAIR) as needed.

5. **Consistency** — Standardized criteria eliminate "gut feel" scoring and enable trend analysis over time.

---

## Risk Assessment Methodology

### Scoring Approach

**Likelihood (1-5):** Probability of occurrence within 12 months

| Score | Label | Probability | Criteria |
|:-----:|-------|:-----------:|----------|
| 1 | Rare | <5% | Has never occurred; exceptional circumstances required |
| 2 | Unlikely | 5-25% | Occurred once in industry; requires multiple failures |
| 3 | Possible | 25-50% | Occurred occasionally; could happen under certain conditions |
| 4 | Likely | 50-75% | Has occurred before; conditions present for recurrence |
| 5 | Almost Certain | >75% | Occurring regularly or expected without intervention |

**Impact (1-5):** Severity across multiple dimensions (use highest applicable)

| Score | Financial | Operational | Reputational | Compliance |
|:-----:|:---------:|:-----------:|:------------:|:----------:|
| 1 | <$10K | <1 day | Internal only | Minor finding |
| 2 | $10K-$50K | 1-3 days | Trade press | Non-conformity |
| 3 | $50K-$250K | 3-7 days | Industry coverage | Regulatory inquiry |
| 4 | $250K-$1M | 1-4 weeks | National media | Investigation |
| 5 | >$1M | >1 month | Sustained negative | Fines/sanctions |

### Risk Score & Response

```
Risk Score = Likelihood × Impact
```

| Score | Level | Response Requirement | Framework Basis |
|:-----:|-------|---------------------|-----------------|
| 20-25 | 🔴 Critical | Immediate escalation; unacceptable | COSO: Exceeds appetite |
| 15-19 | 🟠 High | Mitigation plan in 7 days | ISO 31000: Treatment required |
| 8-14 | 🟡 Medium | Document treatment decision; 90-day action | NIST: Risk-informed decision |
| 1-7 | 🟢 Low | Accept and monitor quarterly | ISO 31000: Acceptable risk |

---

## Risk Appetite Framework

Based on COSO's principle that risk appetite should align with strategic objectives:

| Risk Level | Threshold | Strategic Rationale |
|------------|:---------:|---------------------|
| Critical | **0** | No risk at this level is acceptable given growth objectives |
| High | **3** | Limited high risks acceptable if actively managed |
| Medium | **10** | Normal operational risk; monitored but not alarming |
| Low | No limit | Accepted as cost of doing business |

**Annual Calibration:** Appetite thresholds are reviewed annually by the ERC and adjusted based on:
- Strategic plan changes
- Actual loss experience
- Industry benchmarks
- Stakeholder expectations

---

## Governance Structure

### Enterprise Risk Committee (ERC)

Per COSO guidance on governance and culture:

**Composition:**
- Chief of Staff (Chair)
- VP of IT, Security & Compliance
- VP of GDS Operations
- VP of Revenue Operations  
- VP of Finance
- General Counsel

**Charter:**
- Set and monitor risk appetite
- Review enterprise risk register quarterly
- Approve mitigation plans for High/Critical risks
- Escalate to Board as needed
- Champion risk-aware culture

### Risk Ownership Model

Per ISO 31000's accountability principle:

| Role | Responsibility |
|------|---------------|
| **Risk Owner** | Monitor, mitigate, report on assigned risks |
| **ERC** | Oversight, appetite management, escalation decisions |
| **Executive Team** | Strategic risk decisions, resource allocation |
| **Board** | Risk appetite approval, critical risk oversight |

---

## Continuous Improvement

| Activity | Frequency | Framework Basis |
|----------|-----------|-----------------|
| Risk owner updates | Monthly | ISO 31000: Monitoring |
| ERC register review | Quarterly | COSO: Review & Revision |
| Appetite threshold review | Annually | COSO: Strategy alignment |
| Full methodology review | Annually | ISO 31000: Continual improvement |
| Post-incident risk reassessment | As needed | NIST: Lessons learned |

---

## Summary

This methodology provides:

✅ **Framework Lineage** — Built on ISO 31000, COSO ERM, and NIST guidance  
✅ **Audit Defensibility** — Recognized standards that auditors expect  
✅ **Strategic Integration** — Risk appetite tied to business objectives  
✅ **Scalable Depth** — Qualitative now, quantitative (FAIR) when needed  
✅ **Governance Rigor** — Clear accountability from owner to Board  

---

## References

- ISO 31000:2018 — Risk Management Guidelines
- COSO (2017) — Enterprise Risk Management: Integrating with Strategy and Performance
- NIST SP 800-39 — Managing Information Security Risk
- NIST SP 800-30 Rev 1 — Guide for Conducting Risk Assessments
- NIST Cybersecurity Framework 2.0 (2024)
- FAIR Institute — Factor Analysis of Information Risk

---

*Document Version: 2.0 | Effective: July 2026*
