#58 – RISK BASED THINKING IS JUST GOOD BUSINESS SENSE – T. DAN NELSON

T. Dan NelsonRisk-based thinking (RBT) has been getting a lot of attention lately.  It’s a concept expected to be introduced as a requirement in the upcoming revision of ISO 9001 (due in late 2015).  Many in the ISO 9000 community are abuzz about what RBT is and what it means to a quality management system (QMS). Continue reading

#58 – ENTERPRISE ARCHITECTURE AND BUSINESS RISK MANAGEMENT – HOWARD WIENER

Howard Wiener PixEnterprise Architecture (EA) is a discipline focused on aligning an Enterprise’s execution capabilities with its strategy.  In this article, I show how the EA function is actually a tool for risk management at the Enterprise level. Continue reading

#57 – USING ISO 31000 WITH ISO 9001:2015 – GREG HUTCHINS

Greg Hutchins pixISO 31000 risk management principles and guidelines are the preferred standard to use with ISO 9001:2015.  ISO 31000 is ERM light.  We advocate the use of ISO 31000 with ISO 9001:2015 for smaller organizations because it:

  • Is a risk management framework.  ISO 31000 has all the critical elements of a framework, including a focus on culture, risk philosophy, risk definitions, common risk approach, common risk processes, defined roles and responsibilities, importance of accountability, risk competencies, risk appetite, and risk tolerance of the organization. Continue reading

#57 – 5 PRINCIPLES THAT CONNECT CSR TO THE CORPORATE RISK PROFILE – KELLY EISENHARDT

Kelly EisenhardtOne of the most difficult tasks that companies face today is the struggle to get their CSR, sustainability, compliance, and enterprise risk management teams to work together to identify threats that affect the corporate risk profile.

My prediction is that in the coming years, we will see these disciplines interacting more and more. One way to find a common language for risk that each discipline can relate to and share is to reference standards created by the International Standards Organization (ISO). Continue reading