An enterprise risk register your board actually reads.
One taxonomy runs from the risk register to KRIs, appetite, and loss events, with exceptions and emerging-risk horizon scanning.
| Risk | Inherent | Residual | Appetite |
|---|---|---|---|
| Third-party concentration | High | Medium | Watch |
| AML/CFT program | High | Low | In appetite |
| Consumer: overdraft UDAAP | High | High | Breach |
| IT access management | Medium | Low | In appetite |
One risk taxonomy, register to residual
The risk register scores inherent and residual risk on a shared taxonomy, with causal links between risks, the controls that mitigate them, and the events that realize them.
- 01Inherent and residual risk are scored on a shared taxonomy.
- 02Causal links connect risks, controls, and events.
- 03Control-to-risk linkage makes mitigation visible on the register.
RCSA assessments and KRIs
Risk-and-control self-assessment campaigns are built from assessment templates. Owners rate risk, and the results feed key risk indicators tracked over time.
- 01RCSA campaigns start from a library of assessment templates.
- 02KRIs are derived from the register and assessments.
- 03Results roll up to the taxonomy instead of a spreadsheet.
Risk appetite with breach signaling
Appetite statements and thresholds sit on the same graph as the register, so a metric crossing its limit is signalled as a breach rather than noticed after the fact.
- 01Appetite statements are tied to measurable thresholds.
- 02Breaches are signalled against the register and KRIs.
Exceptions that expire and loss events that link back
Exceptions carry an expiry date and a root cause and re-surface as they approach expiry. Loss events are captured and linked to the controls and risks they touched.
- 01Exceptions carry expiry tracking and a root cause.
- 02Loss events link to controls and risks.
Emerging risks and scenario capture
An emerging-risk agent suggests horizon items for human review and promotion into the register. Scenario capture records a scenario, its assumptions, and its impacts. Zovos does not run Monte Carlo or statistical simulation.
- 01An agent suggests emerging risks, and a human promotes them.
- 02Scenario capture records the narrative, assumptions, and impacts.
- 03There is no Monte Carlo and no statistical simulation.
Business continuity, on the same graph
Business continuity is run in Continuity (BCM), in the Cybersecurity group of the sidebar. Continuity plans sit on the same graph as the risks and controls they protect, so continuity is part of the risk picture rather than a separate binder.
- 01Continuity plans can be linked to the risks they mitigate.
- 02ERM and continuity share one graph.
Grounded in shipped behaviour.
- 23 assessment templates sit behind RCSA campaigns.
- Control-to-risk linkage means residual risk and control effectiveness move together.
- The shared corpus holds 54 frameworks and 754 citations.
Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.
Questions, answered first.
- Does Zovos run Monte Carlo or scenario simulation?
- No. Zovos captures scenarios with their narrative, assumptions, and impacts, and links them to risks and controls. It does not run Monte Carlo or statistical simulation.
- How do risks connect to controls?
- Every risk can link to the controls that mitigate it and the loss events that realized it, so residual risk and control effectiveness move together on one graph.
- What is an RCSA in Zovos?
- It is a risk-and-control self-assessment campaign built from assessment templates. Owners rate inherent and residual risk, and the results feed the register and KRIs.
- Do risk exceptions expire?
- Yes. Exceptions carry an expiry date and a root cause, and the platform re-surfaces them as they approach expiry so nothing lapses silently.
See enterprise risk management on your library.
Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.