Enterprise Risk Management
BC-120
Level 1
Cross-Industry
4 providers
11 API surfaces
2 rated strong or better
Identifying, assessing, mitigating, and monitoring risks at enterprise level.
Enterprise Risk Management (BC-120) is a level-1 business capability in the Cross-Industry model. The catalog holds 11 API surface(s) from 4 provider(s) that can perform some part of it, 2 of them rated strong or better. Reach is the vendor surface that lands on this capability — it is not a claim about what any particular organisation has deployed.
Where this capability definition comes from.
This capability is part of a published business-architecture model that API Evangelist
did not author. It is redistributed here under
CC-BY-4.0.
Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0
Changes: Consolidated from 333 per-L1 YAML files into one JSON; English only (upstream i18n/ omitted); descriptions whitespace-normalised. No capability was added, removed, renamed or re-parented.
Source repository · NOTICE and third-party framework attributions
Sub-capabilities
Risk Framework & Appetite Management BC-120.10
Risk taxonomy, framework, appetite, and tolerance.
no catalog coverage
Risk discovery, assessment, scoring, prioritisation.
4 providers,
6 API surfaces
Mitigation, transfer, avoidance, acceptance decisions.
1 provider,
1 API surface
Risk Monitoring & Reporting BC-120.40
Risk indicators, dashboards, reporting to governance bodies.
no catalog coverage
Corporate Insurance Management BC-120.50
Buying and managing corporate insurance programmes.
no catalog coverage
Providers that reach this capability
Ordered by rating band. Reach means a provider publishes an API surface that can perform
some part of this capability — it is not a claim that any particular
organisation has deployed it.
Exemplar
1
Complete, well-documented, and agent-ready
Strong
1
Solid coverage with minor gaps
Developing
2
Usable, with meaningful gaps to close
This page carries no rating. Capabilities are not rated. A capability is a description of what a business does, not a thing a company publishes, so a Kin Score would have nothing to measure.
The edge table is a Pro feature.
This page shows
which providers and tags reach Enterprise Risk Management. The underlying
tag → capability edges — each with the quoted fragment of the provider's own
OpenAPI that evidences it, a calibrated confidence score, and the contract-provenance gate
it passed — are available through the API, along with company-level capability maps.
Only edges at confidence ≥ 0.7 with evidence found verbatim in
the source contract are published at all.
See plans →
·
How the edges are graded →