Enterprise risk management is often introduced as a standards project. In daily work it is a short set of questions: which business risks do we actually know, who owns them, are we inside appetite, and what does the management body need to see before the next meeting?
The legal frame, briefly
ISO 31000 describes risk management as a continuous process: context, identification, analysis, evaluation, treatment, and monitoring. The German Stock Corporation Act and KonTraG add a duty for the management board of a stock corporation to run a monitoring system that detects developments threatening the company’s existence early. The standard does not replace the statute. It gives the early-warning duty a workable method.
Business risks, not only IT risks
An ISMS risk register that only lists technical threats misses the decisions the board actually takes: customers, supply, liquidity, people, regulation, and product. Those risks belong in the same register, with an owner and a link to controls where a control exists.
A normal working day
- A risk owner updates likelihood or impact because a supplier failed.
- The change is visible against appetite, not only as a new score.
- Treatment actions have a date and a status.
- The next board pack is generated from that register, not rebuilt in slides the night before.
KonTraG and early warning in one place
Early warning fails when the signal lives in a mailbox. A threshold on a business risk, an owner, and a dated note to management is the operating version of the KonTraG duty.
Reporting to management: board packs
The pack should show movement, decisions, and risks outside appetite. A full export of every control is material for the audit file, not the first page for the board.
Conclusion
Treat risk management as ongoing operations. That reduces the stress before meetings and gives management something to steer with.