Why most risk management frameworks fail supervisors

risk

A risk management framework is often treated as a single, purchasable thing. In reality, the phrase splits into two distinct categories: frameworks an organisation can adopt off the shelf, such as ISO 31000, COSO ERM or NIST RMF, and the one framework it must write itself.

According to Copla, when a supervisor or board asks for a risk management framework, it is almost always the latter they mean, and no RegTech platform can produce it on an organisation’s behalf.

Copla recently delved into how the risk management process is only as good as step one in the full process. 

Every credible framework, regardless of which standard’s vocabulary it borrows, rests on five components: governance, identification, assessment and scoring, treatment, and monitoring and reporting.

Governance sits first, not last, because someone must own risk appetite, sign-off on acceptance and answer to a board before a single risk is logged. Identification must be built from an organisation’s actual assets, vendors and dependencies rather than a generic workshop, spanning financial, operational, compliance and technical risk categories continuously rather than annually.

Scoring only holds value if applied consistently, favouring a simple scale used the same way every time over an elaborate model that shifts with whoever is in the room. Treatment then splits into four legitimate responses: mitigation, transfer, avoidance or acceptance, with controls sitting downstream of that decision rather than ahead of it. Monitoring closes the loop, tracking treatment to completion and reporting exposure in terms a board can act on.

Among adoptable frameworks, ISO 31000 offers structure and shared vocabulary without a certification scheme behind it. COSO ERM connects risk to strategy at board level, suiting larger institutions more than compliance teams needing a finished register.

NIST RMF’s seven-step process exists specifically to authorise US federal information systems, while NIST CSF 2.0 offers outcome-based cybersecurity guidance across six functions, including the newly formalised Govern function. FAIR replaces qualitative scoring with financial quantification, though it demands calibrated data few teams maintain.

None of these substitutes for the framework DORA and NIS2 actually require. Article 6 of DORA obliges financial entities to maintain a sound, documented ICT risk framework reviewed annually, with Article 5 placing ultimate responsibility on the management body.

NIS2’s Article 21 imposes comparable obligations on essential and important entities. A supervisor reading that document expects to recognise the organisation in it, not a template with its logo attached.

Building a framework that survives scrutiny means starting with an asset inventory, running a business impact analysis before scoring anything, setting appetite at leadership level, and establishing review triggers rather than fixed review dates. The adopted standards can supply structure. They cannot supply the document itself.

Read Copla’s full post here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.