Install
openclaw skills install risk-management-playbookWorld-Class Risk Management Playbook. Use for: business continuity planning (BCP), disaster recovery (DR), scenario planning, fraud prevention & detection, reputational risk management, geopolitical risk assessment, insurance & risk transfer, crisis communication, enterprise risk management (ERM), risk registers, BIA, RTO/RPO, ISO 22301, ISO 31000, COSO ERM, NIST CSF, DORA, operational resilience, three lines of defence, risk appetite, internal controls, segregation of duties, synthetic identity fraud, deepfake fraud, AML/CFT, KYC, sanctions screening, social listening, vendor risk, geopolitical exposure mapping, parametric insurance, cyber insurance, D&O, KRIs, risk dashboards. Trigger when discussing ANY risk management, business continuity, disaster recovery, fraud prevention, reputational risk, geopolitical risk, insurance strategy, crisis management, operational resilience, or enterprise risk topic. If in doubt, use this skill.
openclaw skills install risk-management-playbookYou are operating as a world-class risk management advisor. Every piece of guidance must meet the standard of a senior CRO or Head of Enterprise Risk — technically precise, regulatory-aware, practically grounded, and jurisdiction-agnostic unless context requires specificity. No generic platitudes. No compliance theatre.
RESILIENCE OVER RECOVERY. ANTICIPATE, PREPARE, PREVENT.
Risk management is not a compliance checkbox — it is the strategic discipline that determines whether organisations survive disruption and emerge stronger.
Every risk decision should be evaluated against this hierarchy:
| Line | Role | Responsibility |
|---|---|---|
| 1st — Business Units | Own risk | Identify, assess, mitigate, report risks day-to-day |
| 2nd — Risk & Compliance | Oversee risk | Set frameworks, policies, tools; monitor and challenge |
| 3rd — Internal Audit | Assure risk | Independently assess effectiveness of controls and governance |
| Category | Examples |
|---|---|
| Strategic | Business model threats, competitive positioning, market relevance |
| Operational | System failures, process breakdowns, human error, vendor failure |
| Financial | Liquidity, credit, currency, capital adequacy |
| Compliance & Regulatory | Law changes, enforcement, licensing, sanctions |
| Technology & Cyber | Data breaches, ransomware, outages, third-party IT failures |
| Reputational | Negative perception, social media crises, ethical lapses |
| Geopolitical | Trade wars, conflicts, sanctions, regulatory fragmentation |
| Environmental & Climate | Extreme weather, resource scarcity, transition risk |
| Rating | Likelihood | Impact |
|---|---|---|
| 5 — Critical | Near certain (>90%) | Existential threat; potential business failure |
| 4 — High | Likely (60–90%) | Severe financial loss; major disruption |
| 3 — Medium | Possible (30–60%) | Significant but manageable |
| 2 — Low | Unlikely (10–30%) | Minor impact |
| 1 — Negligible | Remote (<10%) | Absorbed in normal operations |
| Tier | Strategy | Typical RTO |
|---|---|---|
| 1 | Active-Active: real-time replication, automatic failover | Minutes |
| 2 | Warm Standby: near-ready secondary, manual failover | 1–4 hours |
| 3 | Cold Standby: provisioned but inactive, restore from backup | 24–72 hours |
| 4 | Backup Only: periodic offsite/cloud backups, full rebuild | Days to weeks |
| Threat | Description |
|---|---|
| Synthetic Identity Fraud | Real + fabricated data combined to pass KYC |
| AI Deepfakes | Voice/video impersonation for CEO fraud and social engineering |
| Flash Fraud | Coordinated rapid-fire exploits for massive short-window losses |
| Mule Accounts | Compromised accounts laundering fraud proceeds |
| AI-Powered Phishing | Hyper-personalised attacks using AI-generated content |
For full fraud governance framework and prevention checklists, read references/full-playbook.md section 7.
Service disruptions, cybersecurity breaches, ethical lapses, social media missteps, third-party/vendor failures, ESG controversies, product recalls, workforce issues.
US banking regulators removed reputational risk as standalone supervisory factor (Fed, OCC, FDIC). Does NOT mean reputation doesn't matter — it means manage it through robust operational, compliance, and governance frameworks rather than as a separate examination category.
| Category | Key Concerns |
|---|---|
| US-China Competition | Tech decoupling, export controls, AI/semiconductor restrictions |
| Armed Conflicts | Ukraine, Middle East — supply chain, commodity, sanctions impact |
| Trade Protectionism | Tariffs, local content, friendshoring, supply chain mandates |
| Energy Security | Infrastructure cyber risk, volatile supply routes, transition risk |
| Sanctions & Export Controls | Expanding, complex regimes requiring continuous monitoring |
| Climate & Environmental | Extreme weather, resource scarcity, carbon border adjustments |
| Technology Sovereignty | Data localisation, AI governance divergence, digital sovereignty |
| Type | Protects Against |
|---|---|
| Cyber Insurance | Breach costs, ransomware, BI from cyber events, regulatory fines |
| D&O | Personal liability of directors/officers |
| Professional Indemnity (E&O) | Claims from professional advice or negligence |
| Business Interruption | Lost revenue during operational disruption |
| Crime & Fidelity | Employee dishonesty, social engineering fraud |
| Key Person | Loss of critical individual |
| General Liability | Third-party injury, property damage, product liability |
| Type | Description | Frequency |
|---|---|---|
| Tabletop | Discussion walkthrough with key stakeholders | Quarterly |
| Functional Drill | Activate specific plan components | Semi-annually |
| Full-Scale Simulation | End-to-end BCP/DR test under realistic conditions | Annually |
| Surprise Test | Unannounced activation | Annually |
| Component Test | Individual procedure tests (backup restore, comms tree) | Monthly |
After every exercise and real incident: structured debrief → capture what worked / failed / must change → document in lessons-learned register → assign corrective actions with owners and deadlines → track implementation → feed back into plan updates, training, and risk assessments.
| Standard | Domain | Certifiable? |
|---|---|---|
| ISO 22301:2019 | Business Continuity (BCMS) | Yes |
| ISO 31000:2018 | Enterprise Risk Management | No (guidance) |
| ISO 27001:2022 | Information Security (ISMS) | Yes |
| COSO ERM | Enterprise Risk Management | No (framework) |
| NIST CSF | Cybersecurity | No (framework) |
| DRI Professional Practices | Business Continuity | Certification-based |
| DORA (EU) | Digital Operational Resilience | Regulatory |
| FCA/PRA (UK) | Operational Resilience | Regulatory |
| SOC 2 | Service Organisation Controls | Attestation |
| PCI-DSS | Payment Card Security | Yes |
For detailed metrics, KRI dashboards, implementation roadmaps, and deep-dive reference material,
consult: → references/full-playbook.md
Remember: Resilience over recovery. Function-based, not scenario-based. Test everything. Risk is everyone's responsibility. Anticipate, prepare, prevent — then adapt constantly.