Framework Library
36+ risk frameworks indexed — global standards and Australian prudential instruments, each with complexity, certification and time-to-implement at a glance.
18 FRAMEWORKS
ISO 31000
Risk Management — Guidelines
The umbrella standard for enterprise risk management. Principles, framework and process applicable to any organisation, any sector.
APRA CPS 234
Information Security
APRA's binding information security standard for banks, insurers and super funds. Board is ultimately accountable for information security.
APRA CPS 230
Operational Risk Management
The consolidated operational risk standard — replaces CPS 231, CPS 232 and SPS 231/232. Critical operations, tolerance levels, service provider management.
Essential Eight
ACSC Mitigation Strategies
Eight prioritised mitigation strategies from the Australian Cyber Security Centre — patching, MFA, application control, backups and more.
Privacy Act 1988
Australian Privacy Principles
Thirteen Australian Privacy Principles governing collection, use, disclosure and security of personal information, plus the Notifiable Data Breaches scheme.
SOCI Act 2018
Security of Critical Infrastructure
Obligations for 11 critical infrastructure sectors — asset registration, mandatory cyber incident reporting, risk management programs.
COSO ERM
Enterprise Risk Management — Integrating with Strategy
Twenty principles across five components tying risk to strategy and performance. The board-and-audit-committee favourite.
ISO/IEC 27001
Information Security Management
The certifiable ISMS standard — 93 Annex A controls in the 2022 edition covering organisational, people, physical and technological domains.
NIST RMF
Risk Management Framework
Seven-step lifecycle: prepare, categorise, select, implement, assess, authorise, monitor. Control catalogue in SP 800-53.
NIST CSF 2.0
Cybersecurity Framework
Six functions — Govern, Identify, Protect, Detect, Respond, Recover. The lingua franca of cyber posture reporting.
Basel III / IV
Banking Capital Standards
Capital adequacy, leverage and liquidity standards for banks — CET1, LCR, NSFR and the FRTB market-risk overhaul.
AASB S2
Climate-related Disclosures
Australia's mandatory climate reporting standard aligned to ISSB IFRS S2 — governance, strategy, risk management, metrics and Scope 1–3 emissions.
COBIT 2019
IT Governance
Forty governance and management objectives linking enterprise goals to IT. The audit-friendly IT governance canon.
SOC 2
AICPA Trust Services Criteria
Attestation over security, availability, processing integrity, confidentiality and privacy. The SaaS procurement passport.
AS/NZS 5050
Business Continuity — Managing Disruption
The Australasian business continuity standard framing disruption-related risk inside the ISO 31000 process.
FMEA
Failure Mode & Effects Analysis
Bottom-up technique scoring failure modes by severity, occurrence and detection into a risk priority number.
Bow-Tie Analysis
Barrier-based Risk Visualisation
Visualises threats, top events, consequences and the preventive/mitigative barriers between them.
Monte Carlo Simulation
Quantitative Risk Modelling
Probabilistic simulation of thousands of scenarios to produce loss distributions, VaR and confidence intervals.