02-347-7730  |  Saeree ERP - Complete ERP Solution for Thai Organizations Contact Us

Enterprise Risk Management 2026

Enterprise risk management 2026 under the ISO 31000 and COSO ERM frameworks
  • 19
  • February

Risk management is the process an organization uses to identify, assess, treat, and monitor events that could affect the achievement of its objectives — covering both threats and opportunities. It is not about eliminating risk entirely, but about keeping risk within a level the organization is willing to accept, and knowing about it before it turns into damage.

Every organization faces risk, whether public or private, large or small. What separates them is which ones actually know what their risks are and can act in time. This article covers the reference frameworks you can build on (ISO 31000, COSO ERM, and Thailand's Ministry of Finance criteria), the process step by step, what a usable risk register looks like, and the role an ERP system plays in making internal control happen automatically every day.

In short: Risk management = know what could break → assess how much it would hurt → put controls in place → monitor whether those controls still work. A risk plan written once a year is not risk management; controls embedded in daily operations are.

What Is Risk — Why Must It Be Managed?

Risk, as defined by ISO 31000, is the effect of uncertainty on objectives — covering both the downside (threats) and the upside (opportunities missed).

A common misconception is that risk management means driving risk to zero. That is impossible, and organizations that try end up paralyzed: unwilling to invest, unwilling to change. The correct goal is to define how much risk the organization is willing to accept and then manage within that boundary.

Term Meaning Practical Example
Risk Appetite The overall level of risk the organization is willing to take on to reach its goals — set by senior management "We accept project delays of up to 10%, but we accept zero budget overrun."
Risk Tolerance The numeric deviation allowed for each specific item — turns risk appetite into a measurable threshold "Receivables overdue beyond 90 days must stay under 3% of total receivables."
Inherent Risk The risk level naturally present in the activity, before any control is applied Procurement with no approval step at all = very high fraud exposure
Residual Risk What remains after controls are applied — this is the number to compare against risk appetite After two-tier approval plus an audit trail = low residual risk, acceptable
KRI
Key Risk Indicator
A metric that signals a risk is building — unlike a KPI, which reports on results already delivered A rising count of purchase orders routed through the urgent channel = controls are being bypassed

Reference Frameworks — ISO 31000, COSO ERM, and Thai Government Criteria

No organization needs to invent its own risk framework. Proven international standards exist, and for Thai state agencies the Ministry of Finance has laid down explicit criteria.

Framework Focus Best Suited To
ISO 31000:2018
Risk Management — Guidelines
Flexible principles and guidance applicable to any organization. A six-stage process: establish scope, context and criteria → identification → analysis → evaluation → treatment → monitoring and reporting Any organization of any size or sector — it is guidance, not a certifiable standard
COSO ERM
Enterprise Risk Management
Governance-driven, tying risk to strategy. Five components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication and Reporting Organizations with strong governance requirements, regulated industries, or an audit committee
Ministry of Finance Criteria
B.E. 2562 (2019)
Standards and practical criteria for risk management in Thai state agencies, built on the COSO framework — appoint a working committee → analyze and identify risk factors → assess → prepare a plan → report and monitor Thai state agencies — mandatory, not optional

For Thai state agencies: Section 79 of the State Fiscal and Financial Discipline Act B.E. 2561 (2018) requires state agencies to maintain internal audit, internal control, and risk management in accordance with the standards and criteria set by the Ministry of Finance. This is why every government unit must produce an annual risk management plan and report on its monitoring — it is a legal obligation, not a voluntary exercise. See also our overview of ERP for Thai government agencies.

Seven Risk Areas Organizations Face Today

Traditional frameworks split risk into four or five areas. The 2026 landscape adds two that barely appeared in risk registers a decade ago: personal data risk and AI usage risk.

Area Risk Examples Impact
Strategic Market changes, new competitors, policy shifts, budget cuts Lower revenue, lost competitive advantage, unmet mandate
Operational Process errors, skipped steps, system outages, single-person dependency Delays, damage, higher costs
Financial Budget overruns, bad debt, low liquidity, reconciliations that do not tie out Losses, disbursement missed before fiscal year end, audit findings
Compliance Failure to follow procurement regulations, law, or professional standards Fines, litigation, personal liability, reputational damage
Technology Cyber attacks, systems too old to patch, no tested recovery plan Data loss, service disruption, loss of trust
Privacy Collecting more data than needed, no lawful basis, over-broad access rights, missing deadlines on data subject requests Civil, criminal, and administrative penalties under Thailand's PDPA
AI & Model Risk Staff pasting confidential data into external AI tools, acting on AI output with no human review, no record of who used what Unintentional data leakage, flawed decisions, no traceability

Those last two belong in the corporate risk register today. For more on building a governance framework around AI use, see AI governance in the enterprise; for preparing systems to honour data subject rights, see PDPA and ERP systems.

The Four-Step Risk Management Process

Effective risk management is a continuous cycle, not a one-time exercise:

Step 1: Risk Identification

Start with the question: "What could happen that would affect our objectives?" Gather input from every department and process — from real experience, historical data, and trend forecasting.

  • Review internal and external audit findings, including last year's observations
  • Ask the people doing the work — front-line staff know exactly where the weak points are
  • Analyze system data — anomalous transactions, implausible balances, documents stuck far longer than normal
  • Look at near misses — the times you got through on luck rather than on control

Step 2: Risk Assessment

Once identified, assess along two dimensions:

  • Likelihood — how probable is it? (Low / Medium / High)
  • Impact — how severe if it occurs? (Minor / Moderate / Major)

Then prioritize using a Risk Matrix:

Likelihood \ Impact Minor Moderate Major
High Medium High Very High
Medium Low Medium High
Low Low Low Medium

A frequent pitfall: assessments come back with everything rated "high," leaving nothing prioritized. The fix is to force a cap of five to seven top risks per year, because the resources available to actually fix them are finite. A register with forty critical risks effectively has none.

Step 3: Risk Response

Once you know which risks matter most, choose a treatment:

  • Avoid — change the way you work so the risk never arises, e.g. stop collecting ID card data you have no use for
  • Mitigate — add controls to reduce likelihood or severity, e.g. two-tier approval, two-factor authentication, off-site backups
  • Transfer — insurance or outsourcing to specialists — but understand that legal accountability cannot be transferred, only the financial burden
  • Accept — if the risk sits within tolerance, accept it, but record who made that decision in the register and keep monitoring

Step 4: Monitor & Review

Risks change constantly. What was low risk yesterday can be high risk tomorrow, so you must:

  • Track Key Risk Indicators (KRIs) continuously rather than waiting for year end
  • Review and update the risk register at least quarterly
  • Report to management when something material changes — not only when everything looks fine
  • Review immediately after any real incident — an event that actually happened is the most accurate data you will ever get

What a Usable Risk Register Actually Looks Like

The risk register sits at the heart of the whole process. The trouble is that most registers are written so broadly that nothing can be done with them — "financial risk — high — mitigate by exercising greater care." A register that works names an owner, an indicator, and a deadline.

Field Unusable Example Usable Example
Risk event "Procurement risk" "Commitments are raised beyond the allocated budget because no balance check occurs before a purchase order is issued"
Root cause "Staff carelessness" "Remaining budget is visible only in the month-end report, so no figure is available at the moment the PO is raised"
Control "Exercise more care, train staff" "Configure the system to check the remaining balance while the PO is being entered and block any line that exceeds it"
Risk owner "All departments" "Director of Finance" — one named position accountable
KRI tracked "Monitor regularly" "Count of POs rejected by the system for exceeding budget — reported monthly; more than five is abnormal"

The advantage of the right-hand column is that the control becomes a system configuration rather than a request for cooperation — which is the difference between a control that still works next year and one that leaves with the person who set it up. This connects directly to the problem of knowledge walking out the door with staff.

Everyday Risks Most People Overlook

Risk management is not solely an executive concern. Most of the risks that cause real damage hide inside routine work that everyone has stopped noticing:

Situation Hidden Risk How to Manage
Only one person knows how to do a critical task If they resign or fall ill, work stops Document procedures, cross-train, record the steps in a shared system
Data lives in one person's spreadsheet Data loss, untraceable edits, broken formulas nobody notices Move it into a system with an audit trail — see the risks of running your business on Excel
No budget check before purchasing Budget overruns nobody sees coming Automatic balance checks at entry — see preventing budget overruns
One shared password for the whole department No way to trace who did what; auditors raise findings Individual accounts with two-factor authentication enabled
Approval steps skipped because it was "urgent" No approval evidence; findings raised after the fact An urgent lane that still records the trail — see managing regulation against urgency
Backups exist but restores are never tested When it matters, the restore fails — corrupt files, lost keys, nobody knows the procedure Test restores on a schedule and time them — see disaster recovery planning
Executives approve over chat Approval evidence sits outside the system and cannot be retrieved later Move approvals into the system — see executive approval in ERP

Cyber Risk in 2026 — Why It Belongs on the Corporate Risk Register

Cyber risk stopped being an IT department concern long ago. The scale of loss now lands directly on the financial statements and on business continuity.

Figures worth citing in your risk register — from IBM's Cost of a Data Breach Report 2026, which analyzed 602 real breaches across 17 industries between March 2025 and February 2026:

  • The global average cost of a breach reached USD 4.99 million, up 12% year on year — the highest in the report's history
  • More than one in four organizations hit by a malicious attack said it was AI-driven — a 56% increase over the prior year, adding roughly USD 1 million per breach
  • Healthcare recorded the highest average cost at USD 6.6 million, for the thirteenth consecutive year
  • 85% of organizations surveyed said they plan to increase security spending in response to frontier AI model threats

For anyone maintaining a risk register, the implication is that cyber risk should almost always be scored in the "major impact" column, and the controls recorded against it must be measurable rather than "conduct awareness training." For a broader view of this year's threat landscape see cybersecurity trends 2026, and for the Thai business perspective see cyber as the top business risk in Thailand.

Why ERP and Risk Management Belong Together

An ERP system is not merely a record-keeping tool — it is the infrastructure of internal control that makes the controls in your risk plan happen every day without relying on anyone's memory or diligence:

1. Segregation of Duties

The system enforces role separation through configured permissions: whoever creates a purchase order is not whoever approves it; whoever receives goods is not whoever raises the payment. That closes the single-person-end-to-end gap that underlies almost every form of fraud.

2. Automated Controls

The system checks at the moment of entry rather than after the fact — remaining budget, duplicate document numbers, whether the vendor is on the approved register. The key distinction: preventive controls stop a transaction before it happens, whereas after-the-fact review can only tell you how much was lost.

3. Real-time Data

Executives see actual status without waiting for month-end close, which matters enormously for KRIs: a risk indicator is only useful if you see it while there is still time to act. A number you learn at period close is history, not a warning.

4. Complete Audit Trail

Every transaction records who did what, when, and what value changed to what. That serves as both a deterrent (people know it can be traced) and a detection tool (you can find the origin when something goes wrong) — and it is the first thing internal and external auditors ask to see.

Saeree ERP and Risk Management in Practice

Saeree ERP capabilities that map directly onto controls in a risk register:

Risk Area Capabilities Usable as Controls
Strategic Dashboards comparing performance against plan, and quarterly disbursement progress against targets
Operational Approval routes defined by document type and value, alerts for documents pending by responsible party, and full visibility of document status at every step
Financial Remaining budget checked while a transaction is entered, reserved / committed / accrued statuses kept separate, and funding sources linked to spending items
Compliance Change history recorded on every transaction, role-based permissions, and separation between the person entering and the person approving
Technology & Privacy Two-factor authentication, Active Directory integration, data masking according to user permissions, and an on-premise deployment option that keeps data inside the organization

It is equally worth stating plainly what an ERP system does not do — it does not identify risks on management's behalf, does not decide what level of risk the organization can accept, and does not write the risk management plan. What it does well is enforce the controls you have already decided on, identically every time, for everyone — which is exactly where a purely document-based process tends to break down.

Where to Start — The First 90 Days

If your organization has never done this systematically, do not start by building a register for the entire enterprise at once. A realistic sequence:

Period What to Do Required Outcome
Days 1-30 Pick the single riskiest process (usually procurement or disbursement) and interview front-line staff about their near misses 10-15 risks drawn from real events, not copied from a template
Days 31-60 Score them on the risk matrix, take the top five, and assign an owner and a KRI to each A one-page register with a named owner against every line
Days 61-90 Convert as many controls as possible into system configuration — permissions, approval routes, budget checks, alerts At least half the controls running on their own, with nobody needing to remind anyone
Every quarter after Review the KRIs, close risks now under control, add newly visible ones A register that genuinely changes each quarter — one that never changes is one nobody uses

Organizations about to implement a new ERP have an advantage: they can design controls into the process definition rather than bolting them on afterwards. Preparation details are covered in preparing your organization before an ERP implementation.

The best risk management embeds controls in daily operations — not a document prepared once a year, but a system that works every day.

- Sureeraya Limpaibul, Managing Director, Grand Linux Solution Co., Ltd.

Conclusion

Risk management is not an added burden — it is what gives an organization the confidence to move. Three things separate organizations that actually do it from those that merely file paperwork: (1) a register with clearly named owners and KRIs, (2) controls that translate into system configuration rather than appeals for cooperation, and (3) reviews that happen on a real cycle instead of at year end.

When an ERP system is configured with segregation of duties, automatic budget checking, a complete audit trail, and two-factor authentication, the controls in your risk plan happen on every transaction entered, instead of waiting for someone to remember them. That is the difference between a plan that was written and a control that is running.

If you are interested in using Saeree ERP to strengthen internal control and risk management in your organization, please contact our team for more details.

References

Interested in an ERP System for Your Organization?

Consult with experts from Grand Linux Solution

Request More Information

Call 02-347-7730 | sale@grandlinux.com

Saeree ERP Team

About the Author

Sureeraya Limpaibul

Managing Director, Grand Linux Solution Co., Ltd. & Founder of Saeree ERP — providing comprehensive ERP consulting and services.