Enterprise Risk Management Explained | Building a Risk Program from Scratch

Enterprise Risk Management Explained | Building a Risk Program from Scratch

🎙 Prabh Nair 👥 184K 📅 July 28, 2026 ⏱ 53 min 👁 1K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

ERMrisk appetiterisk tolerancerisk assessmentGRC

Summary

In this podcast episode, Prabh Nair interviews David Vohradsky, a cybersecurity risk governance leader, about building an enterprise risk management (ERM) program from scratch. David shares his experience from 2004 at a major Australian bank, emphasizing the importance of understanding business objectives before applying any framework. He discusses the need for a common risk language, agreed definitions, and clear governance levels. The conversation covers setting risk appetite and tolerance, creating essential artifacts like a charter and risk taxonomy, and the importance of scoping and understanding business processes. David also addresses the impact of AI on risk management, noting that most AI risks map to existing controls, with a few new ones like input/output validation and model security. He provides a step-by-step approach to risk assessment, highlighting the need to measure risk at different levels and avoid common mistakes. The episode concludes with advice for aspiring GRC professionals: focus on understanding business processes deeply and working closely with business teams, rather than relying solely on templates and checklists.

167 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners, as it provides practical, experience-based guidance on building an ERM program. David’s arguments are well-structured and supported by real-world examples, such as the telephone system scenario illustrating the need for risk registers at different levels. He emphasizes the importance of aligning risk management with business objectives and decision-making, which is a key strength. The discussion on AI risk is particularly valuable, as it demystifies the topic by mapping AI risks to existing controls. The argumentation is solid, though it relies on anecdotal evidence rather than formal research, which limits its generalizability.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the content is based on expert opinion and practical experience rather than peer-reviewed research. The sources cited are limited to David’s LinkedIn profile and YouTube playlists, which are not academic references. The title accurately reflects the content, and the discussion is coherent and well-structured. The lack of formal citations is a weakness, but the practical insights compensate to some extent. The adéquation between title and content is good, as the episode indeed explains how to build an ERM program from scratch.

201 words

Title / Content Match

The title accurately reflects the content, which focuses on building an ERM program from scratch, with practical steps and insights.

Quality & Reliability

8/10

The content is based on the extensive practical experience of a senior risk practitioner (David Vohradsky) and offers concrete, actionable advice. The discussion is coherent and grounded in real-world scenarios, though it lacks formal citations and is primarily anecdotal.

Chapters

Cited Sources

  • David Vohradsky LinkedIn Profile — Guest's professional profile, providing credibility and background.
  • AAISM Playlist — Related content on risk management from the channel.
  • GRC Interview Playlist — Related interviews on GRC topics.
  • AI Practical Playlist — Practical AI-related content.
  • ISO 27001 Playlist — ISO 27001 related content, relevant to risk management frameworks.

Concurring Sources

  • ISO 31000 Risk Management — International standard for risk management, aligning with the principles discussed.
  • COSO ERM Framework — Framework for enterprise risk management, supporting the concepts of risk appetite and governance.

Contribution & Novelties

The episode provides a practical, experience-based perspective on building an ERM program, emphasizing the importance of understanding business objectives and creating a common risk language. It offers concrete steps and artifacts, such as a charter and risk taxonomy, and addresses the evolving landscape of AI risk management. The discussion on mapping AI risks to existing controls is particularly insightful.

Pour aller plus loin :

  • ISO 31000 Risk Management — International standard for risk management principles and guidelines.
  • NIST AI Risk Management Framework — Framework for managing AI risks.
  • COSO ERM Framework — Enterprise risk management framework integrating strategy and performance.
  • MITER ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems.
  • OWASP AI Security — Guide for AI security and privacy.

119 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with a moderate level of technical depth and reliability. This indicates a content that is rich in practical insights but may lack formal academic rigor, making it more suitable for practitioners seeking actionable advice.

Reliability 7/10

💬 Sur les 0 commentaires analysés, aucune tendance n'a pu être dégagée.