From cps-risk
Enterprise Risk Management skills — erm framework, risk appetite, control mapping, bcp / dr plan, and more. Apply when the engagement scope includes enterprise risk management work or the consultant references risk, ERM, COSO.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cps-risk:riskThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
**Code:** RISK
Code: RISK Full name: Enterprise Risk Management Description: Enterprise risk management — ERM frameworks (COSO, ISO 31000), risk appetite, control mapping, BCP/DR, operational resilience.
| # | Skill | Command | Purpose |
|---|---|---|---|
| 1 | ERM Framework | /cps-risk:erm-framework | Design or refresh enterprise risk framework aligned to COSO ERM 2017 / ISO 31000. |
| 2 | Risk Appetite | /cps-risk:risk-appetite | Define risk appetite statement and quantitative tolerance thresholds per category. |
| 3 | Control Mapping | /cps-risk:control-map | Map risks to controls; identify orphan risks and over-controlled areas. |
| 4 | BCP / DR Plan | /cps-risk:bcp-dr | Develop business continuity and disaster recovery plans with RTO/RPO targets. |
| 5 | Operational Resilience | /cps-risk:op-resilience | Stress-test critical business services against severe-but-plausible scenarios (per BoE / DORA). |
| 6 | Risk Register Build | /cps-risk:risk-register | Build / refresh enterprise risk register with risk owners, residual scoring. |
/cps-risk:erm-frameworkDesign or refresh enterprise risk framework aligned to COSO ERM 2017 / ISO 31000.
client:
name: "Client Name"
industry: "Industry"
context:
scope: "in-scope description"
constraints: ["constraint 1", "constraint 2"]
references:
- "Prior deliverable / document name"
- "External benchmark / source"
/cps:verify-quality and pass through Every risk has a named owner, inherent score, residual score, and ≥1 mapped control.A CPS-branded ERM Framework deliverable in 05_Deliverables_Final/. Pyramid-Principle structured, sourced, and reviewed.
/cps-risk:risk-appetiteDefine risk appetite statement and quantitative tolerance thresholds per category.
client:
name: "Client Name"
industry: "Industry"
context:
scope: "in-scope description"
constraints: ["constraint 1", "constraint 2"]
references:
- "Prior deliverable / document name"
- "External benchmark / source"
/cps:verify-quality and pass through Every risk has a named owner, inherent score, residual score, and ≥1 mapped control.A CPS-branded Risk Appetite deliverable in 05_Deliverables_Final/. Pyramid-Principle structured, sourced, and reviewed.
/cps-risk:control-mapMap risks to controls; identify orphan risks and over-controlled areas.
client:
name: "Client Name"
industry: "Industry"
context:
scope: "in-scope description"
constraints: ["constraint 1", "constraint 2"]
references:
- "Prior deliverable / document name"
- "External benchmark / source"
/cps:verify-quality and pass through Every risk has a named owner, inherent score, residual score, and ≥1 mapped control.A CPS-branded Control Mapping deliverable in 05_Deliverables_Final/. Pyramid-Principle structured, sourced, and reviewed.
/cps-risk:bcp-drDevelop business continuity and disaster recovery plans with RTO/RPO targets.
client:
name: "Client Name"
industry: "Industry"
context:
scope: "in-scope description"
constraints: ["constraint 1", "constraint 2"]
references:
- "Prior deliverable / document name"
- "External benchmark / source"
/cps:verify-quality and pass through Every risk has a named owner, inherent score, residual score, and ≥1 mapped control.A CPS-branded BCP / DR Plan deliverable in 05_Deliverables_Final/. Pyramid-Principle structured, sourced, and reviewed.
/cps-risk:op-resilienceStress-test critical business services against severe-but-plausible scenarios (per BoE / DORA).
client:
name: "Client Name"
industry: "Industry"
context:
scope: "in-scope description"
constraints: ["constraint 1", "constraint 2"]
references:
- "Prior deliverable / document name"
- "External benchmark / source"
/cps:verify-quality and pass through Every risk has a named owner, inherent score, residual score, and ≥1 mapped control.A CPS-branded Operational Resilience deliverable in 05_Deliverables_Final/. Pyramid-Principle structured, sourced, and reviewed.
/cps-risk:risk-registerBuild / refresh enterprise risk register with risk owners, residual scoring.
client:
name: "Client Name"
industry: "Industry"
context:
scope: "in-scope description"
constraints: ["constraint 1", "constraint 2"]
references:
- "Prior deliverable / document name"
- "External benchmark / source"
/cps:verify-quality and pass through Every risk has a named owner, inherent score, residual score, and ≥1 mapped control.A CPS-branded Risk Register Build deliverable in 05_Deliverables_Final/. Pyramid-Principle structured, sourced, and reviewed.
Discovery → /cps-risk:erm-framework → /cps-risk:risk-appetite → Recommendations
| Plugin | Integration point |
|---|---|
cps-cyber | Cyber risks feed into the enterprise risk register |
cps-pmo | RAID logs roll up to enterprise risk view |
cps-iso | ISO 22301 (BCM) certification readiness |
All deliverables use standard CPS branding via:
/doc-gen for document generationassets/cps-branding.json for stylingscripts/cps-document-generator.js for automation| Skill | Primary artifact | Format |
|---|---|---|
/cps-risk:erm-framework | ERM Framework Report | DOCX/PDF |
/cps-risk:risk-appetite | Risk Appetite Report | DOCX/PDF |
/cps-risk:control-map | Control Mapping Report | DOCX/PDF |
/cps-risk:bcp-dr | BCP / DR Plan Report | DOCX/PDF |
/cps-risk:op-resilience | Operational Resilience Report | DOCX/PDF |
/cps-risk:risk-register | Risk Register Build Report | DOCX/PDF |
Creates, edits, and optimizes skills for Claude Code, including drafting, evaluating with test prompts, iterating on performance, and improving skill descriptions for better triggering accuracy.
npx claudepluginhub hossamdaoud83/cps-plugins-official --plugin cps-risk