Governance, risk and compliance

SmartSuite for the Enterprise Risk Director

The Enterprise Risk Director runs the ERM programme day to day: the methodology, the assessment cycles, the risk register and the reporting that keeps the organisation within its risk appetite. They enforce standards, consolidate data and produce the heat maps leadership relies on.

What you own

  • Design and maintain the ERM methodology, templates and scoring scales
  • Run enterprise-wide risk assessment cycles and keep scoring consistent
  • Maintain the enterprise risk register, ownership and KRIs
  • Automate mitigation routing, escalation and review cadences
  • Link risks to controls, audits and compliance results
  • Produce risk summaries, heat maps and executive dashboards
  • Enforce ERM standards and documentation requirements across business units

Where the role sits

Each name opens that role's page.

Reports to

Chief Risk Officer

Chief Risk Officer

See the role

Direct reports

Risk Manager

Risk Manager

See the role
Risk Analyst

Risk Analyst

See the role
Operational Risk Manager

Operational Risk Manager

See the role

Works closely with

Compliance Director

Compliance Director

See the role
Audit Director

Audit Director

See the role
IT Risk Manager

IT Risk Manager

See the role
Head of Operational Resilience

Head of Operational Resilience

See the role
Risk Committee Member

Risk Committee Member

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

risk

Touches

contributes or approves

issues-actions, reporting, audit, compliance, resilience

Depends on

consumes its output

third-party, privacy, esg, ai-governance

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use the Enterprise Risk Management suite

Assessment coordination

Manages enterprise-wide risk assessment cycles and scoring consistency.

Reporting & analytics

Produces risk summaries, heat maps, and executive dashboards.

Program governance

Enforces ERM standards, review cadences, and documentation requirements.

How they use SmartSuite

Dynamic risk register

Maintains a live, centralized risk inventory with scoring and ownership assignments.

Mitigation Workflow Management

Automates task routing, escalation, and review cycles for mitigation actions.

Integrated insights

Links risk data to controls, audits, and compliance results for comprehensive oversight.

Suites that serve this role

How SmartSuite supports this role

Risk management. Maintains a live, centralised risk inventory with scoring, ownership and KRIs, and manages enterprise-wide assessment cycles with standardised templates.

Issues and actions. Automates task routing, escalation and review cycles for mitigation actions so treatment plans do not stall.

Internal audit. Links risk data to controls and audit findings for unified risk and assurance visibility.

Compliance management. Connects compliance obligations to enterprise risks so the register and the obligations library share one model.

Reporting. Produces heat maps, trend analytics and executive dashboards from the register without manual consolidation.

Industry reference

ISO 31000:2018 and COSO ERM (2017) set the method the director operates: a consistent scoring scale, documented assessment cycles, defined ownership and reporting that links risk to objectives. GAO's Green Book and OMB Circular A-123 apply the same discipline to US federal programmes.

Regulated sectors add specifics. Banks and insurers evidence the programme in Basel-based supervisory reviews and the Solvency II or NAIC ORSA; healthcare systems follow ASHRM's enterprise risk management guidance alongside HIPAA's required risk analysis; technology companies typically fold information security risk in through ISO/IEC 27005.

In their words

Related roles

Chief Risk Officer

Chief Risk Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.