- 19
- February
Risk management is the process an organization uses to identify, assess, treat, and monitor events that could affect the achievement of its objectives — covering both threats and opportunities. It is not about eliminating risk entirely, but about keeping risk within a level the organization is willing to accept, and knowing about it before it turns into damage.
Every organization faces risk, whether public or private, large or small. What separates them is which ones actually know what their risks are and can act in time. This article covers the reference frameworks you can build on (ISO 31000, COSO ERM, and Thailand's Ministry of Finance criteria), the process step by step, what a usable risk register looks like, and the role an ERP system plays in making internal control happen automatically every day.
In short: Risk management = know what could break → assess how much it would hurt → put controls in place → monitor whether those controls still work. A risk plan written once a year is not risk management; controls embedded in daily operations are.
What Is Risk — Why Must It Be Managed?
Risk, as defined by ISO 31000, is the effect of uncertainty on objectives — covering both the downside (threats) and the upside (opportunities missed).
A common misconception is that risk management means driving risk to zero. That is impossible, and organizations that try end up paralyzed: unwilling to invest, unwilling to change. The correct goal is to define how much risk the organization is willing to accept and then manage within that boundary.
| Term | Meaning | Practical Example |
|---|---|---|
| Risk Appetite | The overall level of risk the organization is willing to take on to reach its goals — set by senior management | "We accept project delays of up to 10%, but we accept zero budget overrun." |
| Risk Tolerance | The numeric deviation allowed for each specific item — turns risk appetite into a measurable threshold | "Receivables overdue beyond 90 days must stay under 3% of total receivables." |
| Inherent Risk | The risk level naturally present in the activity, before any control is applied | Procurement with no approval step at all = very high fraud exposure |
| Residual Risk | What remains after controls are applied — this is the number to compare against risk appetite | After two-tier approval plus an audit trail = low residual risk, acceptable |
| KRI Key Risk Indicator |
A metric that signals a risk is building — unlike a KPI, which reports on results already delivered | A rising count of purchase orders routed through the urgent channel = controls are being bypassed |
Reference Frameworks — ISO 31000, COSO ERM, and Thai Government Criteria
No organization needs to invent its own risk framework. Proven international standards exist, and for Thai state agencies the Ministry of Finance has laid down explicit criteria.
| Framework | Focus | Best Suited To |
|---|---|---|
| ISO 31000:2018 Risk Management — Guidelines |
Flexible principles and guidance applicable to any organization. A six-stage process: establish scope, context and criteria → identification → analysis → evaluation → treatment → monitoring and reporting | Any organization of any size or sector — it is guidance, not a certifiable standard |
| COSO ERM Enterprise Risk Management |
Governance-driven, tying risk to strategy. Five components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication and Reporting | Organizations with strong governance requirements, regulated industries, or an audit committee |
| Ministry of Finance Criteria B.E. 2562 (2019) |
Standards and practical criteria for risk management in Thai state agencies, built on the COSO framework — appoint a working committee → analyze and identify risk factors → assess → prepare a plan → report and monitor | Thai state agencies — mandatory, not optional |
For Thai state agencies: Section 79 of the State Fiscal and Financial Discipline Act B.E. 2561 (2018) requires state agencies to maintain internal audit, internal control, and risk management in accordance with the standards and criteria set by the Ministry of Finance. This is why every government unit must produce an annual risk management plan and report on its monitoring — it is a legal obligation, not a voluntary exercise. See also our overview of ERP for Thai government agencies.
Seven Risk Areas Organizations Face Today
Traditional frameworks split risk into four or five areas. The 2026 landscape adds two that barely appeared in risk registers a decade ago: personal data risk and AI usage risk.
| Area | Risk Examples | Impact |
|---|---|---|
| Strategic | Market changes, new competitors, policy shifts, budget cuts | Lower revenue, lost competitive advantage, unmet mandate |
| Operational | Process errors, skipped steps, system outages, single-person dependency | Delays, damage, higher costs |
| Financial | Budget overruns, bad debt, low liquidity, reconciliations that do not tie out | Losses, disbursement missed before fiscal year end, audit findings |
| Compliance | Failure to follow procurement regulations, law, or professional standards | Fines, litigation, personal liability, reputational damage |
| Technology | Cyber attacks, systems too old to patch, no tested recovery plan | Data loss, service disruption, loss of trust |
| Privacy | Collecting more data than needed, no lawful basis, over-broad access rights, missing deadlines on data subject requests | Civil, criminal, and administrative penalties under Thailand's PDPA |
| AI & Model Risk | Staff pasting confidential data into external AI tools, acting on AI output with no human review, no record of who used what | Unintentional data leakage, flawed decisions, no traceability |
Those last two belong in the corporate risk register today. For more on building a governance framework around AI use, see AI governance in the enterprise; for preparing systems to honour data subject rights, see PDPA and ERP systems.
The Four-Step Risk Management Process
Effective risk management is a continuous cycle, not a one-time exercise:
Step 1: Risk Identification
Start with the question: "What could happen that would affect our objectives?" Gather input from every department and process — from real experience, historical data, and trend forecasting.
- Review internal and external audit findings, including last year's observations
- Ask the people doing the work — front-line staff know exactly where the weak points are
- Analyze system data — anomalous transactions, implausible balances, documents stuck far longer than normal
- Look at near misses — the times you got through on luck rather than on control
Step 2: Risk Assessment
Once identified, assess along two dimensions:
- Likelihood — how probable is it? (Low / Medium / High)
- Impact — how severe if it occurs? (Minor / Moderate / Major)
Then prioritize using a Risk Matrix:
| Likelihood \ Impact | Minor | Moderate | Major |
|---|---|---|---|
| High | Medium | High | Very High |
| Medium | Low | Medium | High |
| Low | Low | Low | Medium |
A frequent pitfall: assessments come back with everything rated "high," leaving nothing prioritized. The fix is to force a cap of five to seven top risks per year, because the resources available to actually fix them are finite. A register with forty critical risks effectively has none.
Step 3: Risk Response
Once you know which risks matter most, choose a treatment:
- Avoid — change the way you work so the risk never arises, e.g. stop collecting ID card data you have no use for
- Mitigate — add controls to reduce likelihood or severity, e.g. two-tier approval, two-factor authentication, off-site backups
- Transfer — insurance or outsourcing to specialists — but understand that legal accountability cannot be transferred, only the financial burden
- Accept — if the risk sits within tolerance, accept it, but record who made that decision in the register and keep monitoring
Step 4: Monitor & Review
Risks change constantly. What was low risk yesterday can be high risk tomorrow, so you must:
- Track Key Risk Indicators (KRIs) continuously rather than waiting for year end
- Review and update the risk register at least quarterly
- Report to management when something material changes — not only when everything looks fine
- Review immediately after any real incident — an event that actually happened is the most accurate data you will ever get
What a Usable Risk Register Actually Looks Like
The risk register sits at the heart of the whole process. The trouble is that most registers are written so broadly that nothing can be done with them — "financial risk — high — mitigate by exercising greater care." A register that works names an owner, an indicator, and a deadline.
| Field | Unusable Example | Usable Example |
|---|---|---|
| Risk event | "Procurement risk" | "Commitments are raised beyond the allocated budget because no balance check occurs before a purchase order is issued" |
| Root cause | "Staff carelessness" | "Remaining budget is visible only in the month-end report, so no figure is available at the moment the PO is raised" |
| Control | "Exercise more care, train staff" | "Configure the system to check the remaining balance while the PO is being entered and block any line that exceeds it" |
| Risk owner | "All departments" | "Director of Finance" — one named position accountable |
| KRI tracked | "Monitor regularly" | "Count of POs rejected by the system for exceeding budget — reported monthly; more than five is abnormal" |
The advantage of the right-hand column is that the control becomes a system configuration rather than a request for cooperation — which is the difference between a control that still works next year and one that leaves with the person who set it up. This connects directly to the problem of knowledge walking out the door with staff.
Everyday Risks Most People Overlook
Risk management is not solely an executive concern. Most of the risks that cause real damage hide inside routine work that everyone has stopped noticing:
| Situation | Hidden Risk | How to Manage |
|---|---|---|
| Only one person knows how to do a critical task | If they resign or fall ill, work stops | Document procedures, cross-train, record the steps in a shared system |
| Data lives in one person's spreadsheet | Data loss, untraceable edits, broken formulas nobody notices | Move it into a system with an audit trail — see the risks of running your business on Excel |
| No budget check before purchasing | Budget overruns nobody sees coming | Automatic balance checks at entry — see preventing budget overruns |
| One shared password for the whole department | No way to trace who did what; auditors raise findings | Individual accounts with two-factor authentication enabled |
| Approval steps skipped because it was "urgent" | No approval evidence; findings raised after the fact | An urgent lane that still records the trail — see managing regulation against urgency |
| Backups exist but restores are never tested | When it matters, the restore fails — corrupt files, lost keys, nobody knows the procedure | Test restores on a schedule and time them — see disaster recovery planning |
| Executives approve over chat | Approval evidence sits outside the system and cannot be retrieved later | Move approvals into the system — see executive approval in ERP |
Cyber Risk in 2026 — Why It Belongs on the Corporate Risk Register
Cyber risk stopped being an IT department concern long ago. The scale of loss now lands directly on the financial statements and on business continuity.
Figures worth citing in your risk register — from IBM's Cost of a Data Breach Report 2026, which analyzed 602 real breaches across 17 industries between March 2025 and February 2026:
- The global average cost of a breach reached USD 4.99 million, up 12% year on year — the highest in the report's history
- More than one in four organizations hit by a malicious attack said it was AI-driven — a 56% increase over the prior year, adding roughly USD 1 million per breach
- Healthcare recorded the highest average cost at USD 6.6 million, for the thirteenth consecutive year
- 85% of organizations surveyed said they plan to increase security spending in response to frontier AI model threats
For anyone maintaining a risk register, the implication is that cyber risk should almost always be scored in the "major impact" column, and the controls recorded against it must be measurable rather than "conduct awareness training." For a broader view of this year's threat landscape see cybersecurity trends 2026, and for the Thai business perspective see cyber as the top business risk in Thailand.
Why ERP and Risk Management Belong Together
An ERP system is not merely a record-keeping tool — it is the infrastructure of internal control that makes the controls in your risk plan happen every day without relying on anyone's memory or diligence:
1. Segregation of Duties
The system enforces role separation through configured permissions: whoever creates a purchase order is not whoever approves it; whoever receives goods is not whoever raises the payment. That closes the single-person-end-to-end gap that underlies almost every form of fraud.
2. Automated Controls
The system checks at the moment of entry rather than after the fact — remaining budget, duplicate document numbers, whether the vendor is on the approved register. The key distinction: preventive controls stop a transaction before it happens, whereas after-the-fact review can only tell you how much was lost.
3. Real-time Data
Executives see actual status without waiting for month-end close, which matters enormously for KRIs: a risk indicator is only useful if you see it while there is still time to act. A number you learn at period close is history, not a warning.
4. Complete Audit Trail
Every transaction records who did what, when, and what value changed to what. That serves as both a deterrent (people know it can be traced) and a detection tool (you can find the origin when something goes wrong) — and it is the first thing internal and external auditors ask to see.
Saeree ERP and Risk Management in Practice
Saeree ERP capabilities that map directly onto controls in a risk register:
| Risk Area | Capabilities Usable as Controls |
|---|---|
| Strategic | Dashboards comparing performance against plan, and quarterly disbursement progress against targets |
| Operational | Approval routes defined by document type and value, alerts for documents pending by responsible party, and full visibility of document status at every step |
| Financial | Remaining budget checked while a transaction is entered, reserved / committed / accrued statuses kept separate, and funding sources linked to spending items |
| Compliance | Change history recorded on every transaction, role-based permissions, and separation between the person entering and the person approving |
| Technology & Privacy | Two-factor authentication, Active Directory integration, data masking according to user permissions, and an on-premise deployment option that keeps data inside the organization |
It is equally worth stating plainly what an ERP system does not do — it does not identify risks on management's behalf, does not decide what level of risk the organization can accept, and does not write the risk management plan. What it does well is enforce the controls you have already decided on, identically every time, for everyone — which is exactly where a purely document-based process tends to break down.
Where to Start — The First 90 Days
If your organization has never done this systematically, do not start by building a register for the entire enterprise at once. A realistic sequence:
| Period | What to Do | Required Outcome |
|---|---|---|
| Days 1-30 | Pick the single riskiest process (usually procurement or disbursement) and interview front-line staff about their near misses | 10-15 risks drawn from real events, not copied from a template |
| Days 31-60 | Score them on the risk matrix, take the top five, and assign an owner and a KRI to each | A one-page register with a named owner against every line |
| Days 61-90 | Convert as many controls as possible into system configuration — permissions, approval routes, budget checks, alerts | At least half the controls running on their own, with nobody needing to remind anyone |
| Every quarter after | Review the KRIs, close risks now under control, add newly visible ones | A register that genuinely changes each quarter — one that never changes is one nobody uses |
Organizations about to implement a new ERP have an advantage: they can design controls into the process definition rather than bolting them on afterwards. Preparation details are covered in preparing your organization before an ERP implementation.
The best risk management embeds controls in daily operations — not a document prepared once a year, but a system that works every day.
- Sureeraya Limpaibul, Managing Director, Grand Linux Solution Co., Ltd.
Conclusion
Risk management is not an added burden — it is what gives an organization the confidence to move. Three things separate organizations that actually do it from those that merely file paperwork: (1) a register with clearly named owners and KRIs, (2) controls that translate into system configuration rather than appeals for cooperation, and (3) reviews that happen on a real cycle instead of at year end.
When an ERP system is configured with segregation of duties, automatic budget checking, a complete audit trail, and two-factor authentication, the controls in your risk plan happen on every transaction entered, instead of waiting for someone to remember them. That is the difference between a plan that was written and a control that is running.
If you are interested in using Saeree ERP to strengthen internal control and risk management in your organization, please contact our team for more details.
References
- ISO 31000:2018 — Risk management — Guidelines (International Organization for Standardization)
- COSO Enterprise Risk Management — Integrating with Strategy and Performance (Committee of Sponsoring Organizations of the Treadway Commission)
- State Fiscal and Financial Discipline Act B.E. 2561 (2018), Section 79, and the Ministry of Finance Criteria on Standards and Practices for Risk Management for State Agencies B.E. 2562 (2019) — Comptroller General's Department, Ministry of Finance, Thailand
- IBM Cost of a Data Breach Report 2026 — average breach cost and share of AI-driven attacks
- NIST AI Risk Management Framework and ISO/IEC 42001 — for AI usage risk in the enterprise
