Skip to content
slide-deck.io
BlogGet started free

August 15, 2026

Free Risk Management Presentation Template

Enterprise risk management (ERM) is how mature organizations systematically identify, assess, prioritize, and manage the risks that could prevent them from achieving their objectives. It replaces ad hoc, departmental risk identification — where every function manages its own risks in isolation — with a structured, organization-wide view that surfaces interdependencies, concentrations, and emerging threats that siloed approaches miss.

This template is for Chief Risk Officers, CFOs, and General Counsels presenting the ERM program and top risks to the board of directors. Boards have governance responsibility for risk oversight — they need a clear picture of what the company's material risks are, how they're being managed, and what risk appetite the board has authorized management to operate within.


ERM Framework Selection

Two dominant frameworks provide the conceptual architecture for enterprise risk management:

COSO ERM 2017 (Committee of Sponsoring Organizations): The most widely adopted ERM framework in the US, especially among public companies. Five interconnected components: Governance and Culture (board oversight, risk culture, core values), Strategy and Objective-Setting (how risk appetite informs strategy), Performance (identifying, assessing, prioritizing, and responding to risk), Review and Revision (monitoring ERM performance), Information, Communication, and Reporting. COSO ERM aligns naturally with COSO Internal Control framework (the basis for SOX compliance), making it attractive for companies with mature internal control environments.

ISO 31000:2018: The international standard for risk management principles and guidelines. More flexible and principles-based than COSO — applicable to any organization regardless of size, sector, or type. Focuses on: the risk management process (communication → scope/context/criteria → risk assessment → risk treatment → monitoring → recording/reporting), integration of risk management into organizational decision-making, and continuous improvement. More commonly used outside the US and in non-profit/government contexts.

Practical guidance: for a US public company or one subject to SOX, COSO ERM is the natural choice — it aligns with your existing internal control framework and is familiar to external auditors. For a private company or international organization, ISO 31000 provides more flexibility.


Risk Universe and Taxonomy

A risk taxonomy gives the organization a shared language for describing risk. Without taxonomy, every function calls the same risk by a different name, and risk aggregation becomes impossible.

Strategic Risks

Risks that affect the organization's ability to achieve its strategic objectives.

  • Market disruption: New entrants, disruptive technology, or business model innovation that undermines your competitive position
  • Customer concentration: Excessive revenue dependence on a small number of customers — losing one or two could be existential
  • M&A execution: Integration failures, cultural clashes, or failure to achieve deal thesis after acquisition
  • Reputation: Brand damage from product failure, executive misconduct, social media events, or third-party association
  • Strategic planning failure: Strategy that is wrong for the market, or right strategy executed too slowly

Operational Risks

Risks arising from failures of internal processes, people, systems, or external events.

  • Process failure: Breakdowns in core operating processes — manufacturing quality, service delivery, financial reporting
  • Supply chain disruption: Supplier failure, geographic concentration, logistics failure, raw material availability
  • Technology and cybersecurity: System outages, data breaches, ransomware, and technology obsolescence
  • Third-party failure: Key vendor, outsourcing partner, or distribution partner failure
  • People: Key person dependency, talent shortage, succession failure, labor relations

Financial Risks

Risks to financial performance and position.

  • Liquidity: Inability to meet financial obligations — especially material for capital-intensive businesses and companies with near-term debt maturities
  • Credit: Customer non-payment, counterparty default on financial instruments
  • FX and interest rate: Exposure to currency movements and interest rate changes on variable-rate debt
  • Capital allocation: Poor investment decisions that destroy value

Compliance and Legal Risks

  • Regulatory change: New laws or regulations that change cost structure or business model viability
  • Litigation: Material pending litigation or litigation arising from product, employment, or IP disputes
  • Data privacy and security: GDPR, CCPA, and emerging state/federal privacy regulation
  • Trade and sanctions: OFAC sanctions exposure, export control violations, import compliance

Environmental and Social Risks

  • Physical climate risk: Flooding, extreme weather, water scarcity affecting operations or assets
  • Transition climate risk: Carbon pricing, stranded assets, customer demand shift to low-carbon alternatives
  • ESG regulatory risk: Growing mandatory ESG disclosure requirements and potential liability for greenwashing
  • Social license: Community opposition to operations, labor rights issues in supply chain

Risk Assessment Methodology

Inherent vs. Residual Risk

Inherent risk: The risk level before any controls or mitigation actions. Measures the raw exposure.

Residual risk: The risk level after controls and mitigation are applied. This is the risk the organization is actually carrying.

The gap between inherent and residual risk measures the effectiveness of your risk management program. A risk with high inherent risk and low residual risk reflects strong controls. A risk with high inherent and high residual risk is a gap — you're exposed and not adequately managing it.

Likelihood × Impact Heat Map

Assess each risk on two dimensions:

  • Likelihood: How probable is this risk materializing in the next 12–24 months? Scale of 1 (rare, <5%) to 5 (almost certain, >80%)
  • Impact: If this risk materializes, what is the consequence? Scale of 1 (negligible — manageable within normal operations) to 5 (catastrophic — threatens organizational survival)

The product of likelihood × impact gives a risk score (1–25). Plot on a 5×5 heat map. Risks in the upper-right quadrant (high likelihood × high impact) require immediate management attention.

Risk velocity: An underused dimension. How fast could this risk materialize from signal to impact? A liquidity crisis (velocity: days) is categorically different from a demographic shift reducing your market (velocity: years) even if both score similarly on likelihood × impact.

Key Risk Indicators (KRIs)

For each material risk, define leading indicators that signal the risk is increasing before it materializes. KRIs are the early warning system.

Examples:

  • Customer concentration risk KRI: % of revenue from top 3 customers (threshold: trigger review if >40%)
  • Liquidity risk KRI: months of cash runway at current burn (threshold: escalate if <12 months)
  • Cybersecurity KRI: number of phishing attempts reaching employee inboxes, number of unpatched critical vulnerabilities
  • Talent KRI: voluntary attrition rate in critical roles (threshold: escalate if >15% annualized)
  • Supply chain KRI: single-source dependencies >10% of spend with no qualified backup

Top 10 Enterprise Risk Slide Format

For each of your top 10 risks, present:

| Field | Content | |---|---| | Risk name | Brief, specific description | | Risk category | Strategic / Operational / Financial / Compliance / ESG | | Risk owner | Named executive accountable for managing this risk | | Inherent likelihood | 1–5 | | Inherent impact | 1–5 | | Key controls | 2–3 most important mitigation actions in place | | Residual likelihood | 1–5 | | Residual impact | 1–5 | | KRIs | Leading indicators being monitored | | Trend vs. last quarter | ↑ (increasing) / → (stable) / ↓ (decreasing) | | Board action required | Yes / No — if yes, specify |

The trend column is the most important for board engagement. Risks that are stable or decreasing confirm management is in control. Risks with an upward trend demand explanation and response.


Risk Appetite Statement

The board's risk appetite statement is one of the most important governance documents an organization can have — and one of the most commonly absent or meaninglessly vague.

Risk appetite is the amount and type of risk the board is willing to accept in pursuit of the organization's objectives. It is not zero risk (that's called "not operating") and it is not unlimited risk (that's called "recklessness").

Effective risk appetite statements are:

  • Category-specific: The organization may have a high appetite for product innovation risk (trying new things, accepting that some will fail), a moderate appetite for operational risk (process improvements carry some uncertainty), and near-zero appetite for compliance risk (we do not accept legal violations).
  • Quantified where possible: "We maintain minimum cash liquidity of 6 months of operating expenses" is a quantified appetite. "We are comfortable with moderate liquidity risk" is not.
  • Linked to strategy: Risk appetite should explicitly connect to your strategic objectives — the risks you accept should be the risks associated with the things you're trying to accomplish.

The Three Lines of Defense Model

The three lines model (updated by IIA in 2020) clarifies governance roles in risk management and control:

First Line — Business Ownership: Front-line managers and employees own and manage risks in their operations day-to-day. They implement controls, identify risks in their area, and escalate when risk exceeds appetite.

Second Line — Risk and Compliance Oversight: Risk management, compliance, legal, and finance functions provide expertise, frameworks, and oversight. They set policy, monitor adherence, and provide independent assessment of risk and control quality. They do not own the risk — the first line does — but they provide the architecture and oversight.

Third Line — Independent Assurance: Internal audit provides independent, objective assurance to the board and senior management that the first and second lines are working. External auditors and regulators provide additional external assurance.

The most common failure: the second line doing work that belongs to the first line (risk management doing compliance monitoring that the business should own), leaving the second line unable to provide genuine oversight.


Emerging Risk Horizon Scanning

The top 10 risk register captures known, currently material risks. Horizon scanning identifies risks that are not yet material but require monitoring over the next 12–24 months.

Emerging risk categories to assess annually:

  • AI and automation risk: AI-enabled competitive disruption, AI liability and regulatory risk (EU AI Act, US executive orders), talent displacement and retraining needs
  • Geopolitical risk: Trade policy shifts, sanctions risk in new markets, supply chain decoupling between US and China
  • Climate physical risk: Long-term asset exposure to flooding, heat stress, water scarcity — especially relevant for real estate, agriculture, and manufacturing
  • Cybersecurity evolution: Quantum computing threat to current encryption standards, AI-enabled attacks
  • Regulatory expansion: Growing scope of ESG regulation, digital markets regulation (EU DMA/DSA), privacy law proliferation

Present emerging risks with: current likelihood (low), potential impact if materialized (medium to high), recommended monitoring actions, and trigger conditions that would promote a risk from emerging to current top-10.

Build your next presentation with AI

Generate editable .pptx decks in minutes. Free to start — no card required.

Try it free →