Hi David, i want to ask something about managing risk project, hopefully you are willing to answer it :) How to integrate the ERM and project risk management in risk register document? Are they need to documented in same or different document? because in my company we have separate risk assessment of that and consequencely the corporate risk profile didn't reflect the projects condition (because in risk profile only represented the ERM, which is most of them are operational risk). As an internal auditor, i think it is wrong. Thanks (sorry for my bad english)
@Risk-Doctor2 жыл бұрын
HI, thanks for your question. I'll just give a brief answer here. You need to keep these two risk registers separate, because they relate to different levels within the organisation, with different objectives and different scales of impact severity. But it is also important to communicate about risk from lower levels into higher levels, so that corporate leaders are aware of lower-level risks in projects and operations. Part of the ERM function is to synthesise or collate risk information from across the organisation, and to presnt a single picture of risk exposure to senior leaders and decision-makers. i hope this is helpful.