ICAEW Registered Auditors  ·  90+ UK-Based Experts

Risk Management

Turn risk management from a compliance ritual into a decision-making tool — with a framework your board can actually rely on and evidence to back its assurance statements.

Every organisation manages risk; far fewer do it in a way that changes decisions. The familiar failure pattern is a risk register updated twice a year, scored by habit, reviewed without challenge — right up until one of the risks on it materialises and the board asks why the framework did not help.

Our risk management services build and test frameworks that work: risks identified honestly, appetite defined so managers know what they may accept, mitigation that is real rather than asserted, and reporting that tells boards what is changing rather than restating what they already knew. Delivery is senior partner-led, drawing on more than 20 years of cross-sector risk experience.

Risk Identification and Assessment That Reflects Reality

A framework is only as good as the risks it captures. We facilitate structured risk identification across strategic, financial, operational, technology, people, regulatory and reputational categories — drawing on workshops, data and cross-sector experience of where organisations like yours actually get hurt. Each risk is assessed for likelihood and impact on a consistent scale, distinguishing inherent exposure from the position after controls, so the register shows where you truly stand rather than where policy says you should.

Risk Appetite: Deciding What You Will Accept

Risk appetite is the most under-used tool in governance. Defined well, it tells every manager which risks they may accept, which need escalation and which the organisation will not carry at any price — turning hundreds of daily judgement calls into consistent decisions. We help boards articulate appetite statements that connect to strategy, translate them into practical tolerances and limits, and embed them in the approval processes where decisions are actually made.

Embedding: Ownership, Mitigation and the Three Lines

Risk management fails when it belongs to one manager and a spreadsheet. We embed clear ownership using the three lines model — management owning and managing risk, oversight functions setting frameworks and monitoring, and internal audit providing independent assurance. Mitigation plans get owners, dates and tests of effectiveness, and key risk indicators give early warning while there is still time to act.

Board Reporting and Assurance Mapping

Boards need to know what is changing, what is outside appetite and what management is doing about it — on one page if possible. We design risk reporting that achieves that, and build assurance maps showing which sources of comfort cover which key risks, exposing the gaps and duplications. For companies within reach of the UK Corporate Governance Code, this is also the groundwork for the board's declaration on the effectiveness of material internal controls under Provision 29.

Audit or Advisory — or Both

Engagements run in two modes. Advisory: building or upgrading your framework, from first risk register to full enterprise risk management. Audit: independently testing the framework you already have — whether risks are complete, scoring is honest, mitigation is real and reporting reaches the board intact. Both are available fully outsourced, co-sourced with your team, or as focused ad-hoc reviews, time-bound with budget certainty.

What You Get With Acumon

  • Risk identification and assessment across all major risk categories
  • Risk appetite statements translated into practical tolerances and limits
  • Clear risk ownership embedded through the three lines model
  • Mitigation plans with owners, dates and tests of effectiveness
  • Key risk indicators that give early warning, not late confirmation
  • One-page board risk reporting and assurance mapping
  • Independent audits of existing risk management frameworks

Why Acumon for Risk Management?

  • Senior partner-led engagement
  • 20+ years of cross-sector risk management experience

Get a Fixed-Fee Quote

Tell us what you need and we'll come back within one business day with a clear scope and a fixed price — no hourly-rate surprises. Call 020 8567 3451 or use the form and we'll be in touch.

Common Questions

Frequently Asked Questions

What is a risk appetite statement and why do we need one?
A risk appetite statement records how much risk, of what kinds, the board is willing to accept in pursuit of its objectives. Without one, every manager applies their own instinct — some gambling, some paralysed. With one, escalation triggers are clear and decisions are consistent. We help boards write appetite statements that connect to strategy and then embed them in real approval processes, which is where most appetite work fails.
How often should a risk register be reviewed?
Principal risks should be reviewed by the executive at least quarterly and by the board at least annually — but the better answer is event-driven: registers should move when the business or its environment moves. A register that looks the same all year is usually recording history rather than managing risk. We build review rhythms proportionate to your size and pace of change.
What is the three lines model?
A widely used way of organising risk responsibilities: management owns and manages risk day to day (first line); risk and compliance functions set frameworks, support and monitor (second line); and internal audit provides independent assurance to the board (third line). Applied proportionately — even in small organisations — it stops risk management collapsing into one person's spreadsheet.
We already have a risk framework. What would an audit of it tell us?
Whether it would actually protect you: are the right risks on the register, is scoring honest or habitual, do the claimed mitigations exist and work, does reporting reach the board without being smoothed on the way? An independent framework audit typically takes one to two weeks and gives the audit committee evidence rather than assertion.
How does this connect to the board declarations under the UK Corporate Governance Code?
Directly. For financial years beginning on or after 1 January 2026, Provision 29 asks boards to declare on the effectiveness of their material internal controls. That declaration rests on exactly what this service builds: identified risks, mapped controls, tested mitigation and evidenced monitoring. A sound risk management framework is the foundation of the declaration.
Get in Touch

Ready to Sort Your Risk Management?

Tell us what you need. Within one business day, a qualified accountant will be in touch to talk it through and give you a clear, fixed-fee quote — no obligation.

Visit us1-2 Craven Road, Ealing, London, W5 2UA

Speak to a Specialist

Fill this in and we'll come back to you within one business day.

No obligation. Your details stay private.
Call Now Get in Touch