Skip to content
deveca GRC
Risk management4 min read

ERM in practice: ISO 31000, the German Stock Corporation Act and KonTraG

ISO 31000, the AktG and KonTraG sound like a pile of duties. Day to day the questions are simple: which risks do we know, who owns them, are we inside appetite, and what must management see?

Author:
  • ERM
  • ISO 31000
  • KonTraG
  • AktG
  • Business risks

Enterprise risk management is often introduced as a standards project. In daily work it is a short set of questions: which business risks do we actually know, who owns them, are we inside appetite, and what does the management body need to see before the next meeting?

The legal frame, briefly

ISO 31000 describes risk management as a continuous process: context, identification, analysis, evaluation, treatment, and monitoring. The German Stock Corporation Act and KonTraG add a duty for the management board of a stock corporation to run a monitoring system that detects developments threatening the company’s existence early. The standard does not replace the statute. It gives the early-warning duty a workable method.

Business risks, not only IT risks

An ISMS risk register that only lists technical threats misses the decisions the board actually takes: customers, supply, liquidity, people, regulation, and product. Those risks belong in the same register, with an owner and a link to controls where a control exists.

A normal working day

  • A risk owner updates likelihood or impact because a supplier failed.
  • The change is visible against appetite, not only as a new score.
  • Treatment actions have a date and a status.
  • The next board pack is generated from that register, not rebuilt in slides the night before.

KonTraG and early warning in one place

Early warning fails when the signal lives in a mailbox. A threshold on a business risk, an owner, and a dated note to management is the operating version of the KonTraG duty.

Reporting to management: board packs

The pack should show movement, decisions, and risks outside appetite. A full export of every control is material for the audit file, not the first page for the board.

Conclusion

Treat risk management as ongoing operations. That reduces the stress before meetings and gives management something to steer with.

Run business risks, appetite, and board packs in deveca GRC

GRC in practice

See how deveca supports your ISMS and compliance programme.