Archetype 3
ERM program and ESG readiness
Enterprise Risk Assessment plus ESG disclosure controlsScenario
The board wants a defensible view of the enterprise risk landscape and the company is approaching new ESG reporting obligations. The pieces exist in silos: risk register in one place, ESG data in another, controls undocumented.
Action taken
CFGI runs an Enterprise Risk Assessment using surveys, stakeholder interviews, and CFGI’s scoring methodology. In parallel, the ESG team runs a materiality assessment, maps Scope 1, 2, and 3 emissions data, drafts disclosure controls, and aligns to the relevant framework. The two workstreams share governance and reporting cadence.
Outcomes
- Top enterprise risks with quantitative scores, owners, and KRI dashboards.
- ERM governance policies, SOPs, and validation plan tied to the audit committee.
- ESG materiality assessment and roadmap to compliance with named frameworks.
- Disclosure controls and Scope 1, 2, 3 data mapping ready for external assurance.