The framework atlas

Framework Library

36+ risk frameworks indexed — global standards and Australian prudential instruments, each with complexity, certification and time-to-implement at a glance.

18 FRAMEWORKS

Enterprise RiskInternational

ISO 31000

Risk Management — Guidelines

The umbrella standard for enterprise risk management. Principles, framework and process applicable to any organisation, any sector.

Complexity · MediumOpen
Cyber / PrudentialAustralia

APRA CPS 234

Information Security

APRA's binding information security standard for banks, insurers and super funds. Board is ultimately accountable for information security.

Complexity · HighOpen
Operational ResilienceAustralia

APRA CPS 230

Operational Risk Management

The consolidated operational risk standard — replaces CPS 231, CPS 232 and SPS 231/232. Critical operations, tolerance levels, service provider management.

Complexity · HighOpen
CyberAustralia

Essential Eight

ACSC Mitigation Strategies

Eight prioritised mitigation strategies from the Australian Cyber Security Centre — patching, MFA, application control, backups and more.

Complexity · MediumOpen
PrivacyAustralia

Privacy Act 1988

Australian Privacy Principles

Thirteen Australian Privacy Principles governing collection, use, disclosure and security of personal information, plus the Notifiable Data Breaches scheme.

Complexity · MediumOpen
Critical InfrastructureAustralia

SOCI Act 2018

Security of Critical Infrastructure

Obligations for 11 critical infrastructure sectors — asset registration, mandatory cyber incident reporting, risk management programs.

Complexity · HighOpen
Enterprise RiskUnited States

COSO ERM

Enterprise Risk Management — Integrating with Strategy

Twenty principles across five components tying risk to strategy and performance. The board-and-audit-committee favourite.

Complexity · HighOpen
CyberInternational

ISO/IEC 27001

Information Security Management

The certifiable ISMS standard — 93 Annex A controls in the 2022 edition covering organisational, people, physical and technological domains.

Complexity · HighOpen
CyberUnited States

NIST RMF

Risk Management Framework

Seven-step lifecycle: prepare, categorise, select, implement, assess, authorise, monitor. Control catalogue in SP 800-53.

Complexity · HighOpen
CyberUnited States

NIST CSF 2.0

Cybersecurity Framework

Six functions — Govern, Identify, Protect, Detect, Respond, Recover. The lingua franca of cyber posture reporting.

Complexity · MediumOpen
FinancialInternational

Basel III / IV

Banking Capital Standards

Capital adequacy, leverage and liquidity standards for banks — CET1, LCR, NSFR and the FRTB market-risk overhaul.

Complexity · Very HighOpen
ESGAustralia

AASB S2

Climate-related Disclosures

Australia's mandatory climate reporting standard aligned to ISSB IFRS S2 — governance, strategy, risk management, metrics and Scope 1–3 emissions.

Complexity · HighOpen
IT GovernanceInternational

COBIT 2019

IT Governance

Forty governance and management objectives linking enterprise goals to IT. The audit-friendly IT governance canon.

Complexity · HighOpen
AssuranceUnited States

SOC 2

AICPA Trust Services Criteria

Attestation over security, availability, processing integrity, confidentiality and privacy. The SaaS procurement passport.

Complexity · MediumOpen
ResilienceAustralia / NZ

AS/NZS 5050

Business Continuity — Managing Disruption

The Australasian business continuity standard framing disruption-related risk inside the ISO 31000 process.

Complexity · MediumOpen
OperationalInternational

FMEA

Failure Mode & Effects Analysis

Bottom-up technique scoring failure modes by severity, occurrence and detection into a risk priority number.

Complexity · LowOpen
OperationalInternational

Bow-Tie Analysis

Barrier-based Risk Visualisation

Visualises threats, top events, consequences and the preventive/mitigative barriers between them.

Complexity · LowOpen
FinancialInternational

Monte Carlo Simulation

Quantitative Risk Modelling

Probabilistic simulation of thousands of scenarios to produce loss distributions, VaR and confidence intervals.

Complexity · HighOpen