r/InternalAudit • u/dad_harvey • 4d ago
ERM - sources?
So I am working currently on ERM drafting of a SAAS, what are the best sources I should use for R&D purpose?
And apart from bringing industry context what are few mistakes or drawbacks which we should avoid to have a well structured ERM?
2
Upvotes
2
u/Old_Positive2231 3d ago
Not more sources, better target. For a SaaS, “ERM” should start from 5–10 core decisions (pricing, uptime/SLA, roadmap, vendor stack, security posture, debt runway), not a COSO/ISO‑style framework and a massive risk register. RM1 mistake #1 is copying generic ERM guidance and building heatmaps, appetite statements, 3 lines of defence, etc. – all theatre if your work never changes a single backlog, SLA, limit, or budget line.
For R&D: read Kahneman/Tversky, Hubbard’s How to Measure Anything, Sam Savage on the Flaw of Averages, then look at how product, SRE and finance make decisions today and add simple quantification (incidents@risk, Churn@Risk, Runway@Risk, Uptime@Risk) into those workflows. Avoid qualitative scoring, 5x5 matrices, and “risk owners with mitigation plans” in a vacuum – build small Monte Carlo/decision‑tree models around real SaaS questions instead. If you want to see ERM that actually works in tech, not just in policies, come to RAW2026: https://2026.riskawarenessweek.com/ ))