Enterprise risk on one taxonomy, from the register to the board.
This page is for the chief risk officer and the enterprise and operational risk managers at a bank or credit union. At many credit unions the same person also owns vendor management, continuity or compliance, so a member can hold several families at once.
- My work
- Open
- Risk
- Open
- Exams & regulatory change
- Open
- Every other group
- Folded
What opens first.
My work comes first, then the groups below, and only those groups start open. The All sections switch brings back the full order. A job family only arranges the sidebar, and your permissions still decide which items you see.
- 01Risk. Risk register · Assessments · KRIs · Appetite · Exceptions · Loss events · Emerging risks · Decision register
- 02Exams & regulatory change. Exam prep · Supervisory actions · Reg updates · Enforcement radar · Enforcement tracker · Launch delta
The dashboard shows Needs your attention, Overdue & at-risk, Approvals queue, Findings tracker, Framework health and Recent activity. Your role still caps that set, and a panel you do not get is left out rather than shown as a zero.
Where the work lives.
The feature pages and documentation this family uses most.
Enterprise risk management
One taxonomy runs from the risk register to KRIs, appetite, and loss events, with exceptions and emerging-risk horizon scanning.
ExploreControls & continuous coverage
One control library shows live per-framework coverage and evidence-backed attestations.
ExploreThird-party risk management
Tier, question, monitor, and map every vendor to the controls and rules it touches.
ExploreBoard reporting
Directors get a committee-scoped, read-optimized oversight surface with lineage back to the source.
ExploreExam & supervisory management
Split the first-day letter into requests mapped to evidence you already hold, and hand back one package.
ExploreWhat your role can approve.
A job family never grants a permission, and it never changes the price. What you can approve comes from your role, and people in this family usually hold one of the roles below.
- 01Risk Approver. The Risk Approver role approves risk acceptances, control effectiveness, finding closures, policies, mappings and routing decisions. It does not hold the owner’s write set, settings or examiner grants.
- 02Compliance Analyst. The Compliance Analyst role writes drafts, findings, risk, controls and third-party records, but it approves nothing.
Whatever the role, the person who submits a decision cannot approve it. The only exception is a decision that no one else in your institution can approve. The submitter may then approve it with a recorded justification, and that override is audited. See Roles and permissions for the full model.
See Zovos the way your role will.
Bring your controls, a policy, and the work this family owns. We target two-week onboarding.