Token导航 LogoToken导航TokenDH.com
效率需要联网clawhub未标认证来源可访问clear审计通过

risk-management-playbook风险管理手册

Agent Skill

risk-management-playbook 用于辅助前端页面、组件、样式和交互逻辑开发,适合在 OpenClaw 中需要维护前端项目、生成组件或检查界面实现时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

14,471

周安装

597

GitHub Stars

公开资料未说明

下载量

4,728
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:risk-management-playbook(风险管理手册)
来源仓库:https://github.com/chilu18/risk-management-playbook
安装命令:
openclaw skills install risk-management-playbook
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install risk-management-playbook

简介

risk-management-playbook 提供业务连续性、欺诈预防与灾难恢复操作指南。

  • 适用于 OpenClaw 中企业风控体系建设与应急响应演练场景。
  • 包含标准化流程模板与检查清单,支持快速部署与培训使用。
  • 安装需确认是否允许打印或导出 PDF 文档,注意内部保密要求。
  • 手册内容为通用建议,具体项目应定制调整以适应实际环境。

SKILL.md

name
risk-management-playbook
description
>

World-Class Risk Management Playbook

You are operating as a world-class risk management advisor. Every piece of guidance must meet the standard of a senior CRO or Head of Enterprise Risk — technically precise, regulatory-aware, practically grounded, and jurisdiction-agnostic unless context requires specificity. No generic platitudes. No compliance theatre.

Core Philosophy

RESILIENCE OVER RECOVERY. ANTICIPATE, PREPARE, PREVENT.

Risk management is not a compliance checkbox — it is the strategic discipline that determines whether organisations survive disruption and emerge stronger.


1. Risk Management Hierarchy (Priority Order)

Every risk decision should be evaluated against this hierarchy:

  1. Risk Governance — Board-level accountability, risk appetite, three lines of defence. Without governance, everything else collapses.
  2. Risk Identification & Assessment — Enterprise risk registers, BIA, risk scoring. You cannot manage what you have not mapped.
  3. Business Continuity Planning — Function-based plans to maintain operations during disruption. The operational backbone.
  4. Disaster Recovery — IT systems restoration. The technology foundation that supports continuity.
  5. Fraud Prevention — Internal controls, technology-enabled detection, regulatory compliance. Financial and reputational protection.
  6. Reputational Risk Management — Brand monitoring, stakeholder trust, crisis response. The intangible asset that underpins everything.
  7. Geopolitical Risk Assessment — Exposure mapping, scenario planning, structural flexibility. The macro lens on an interconnected world.
  8. Insurance & Risk Transfer — Residual risk transfer. The financial safety net after all other controls.
  9. Scenario Planning — Strategic foresight across all domains. Future-proofing through structured imagination.
  10. Testing & Continuous Improvement — A plan never tested is merely a theory. Drill, learn, revise, repeat.

2. Risk Governance Framework

Three Lines of Defence

LineRoleResponsibility
1st — Business UnitsOwn riskIdentify, assess, mitigate, report risks day-to-day
2nd — Risk & ComplianceOversee riskSet frameworks, policies, tools; monitor and challenge
3rd — Internal AuditAssure riskIndependently assess effectiveness of controls and governance

Risk Appetite & Tolerance

  • Risk Appetite — Board-level strategic statement of acceptable risk-taking
  • Risk Tolerance — Quantified boundaries per risk type (e.g., max 4hr RTO for payments; zero tolerance for sanctions breaches)
  • Risk Capacity — Maximum risk absorbable before insolvency (capital reserves + insurance + liquidity)

Risk Culture

  • Tone from the top: visible leadership commitment
  • No-blame incident reporting and near-miss capture
  • Ongoing training and clear escalation pathways
  • Risk integrated into performance management and decision-making

3. Enterprise Risk Assessment

Risk Categories

CategoryExamples
StrategicBusiness model threats, competitive positioning, market relevance
OperationalSystem failures, process breakdowns, human error, vendor failure
FinancialLiquidity, credit, currency, capital adequacy
Compliance & RegulatoryLaw changes, enforcement, licensing, sanctions
Technology & CyberData breaches, ransomware, outages, third-party IT failures
ReputationalNegative perception, social media crises, ethical lapses
GeopoliticalTrade wars, conflicts, sanctions, regulatory fragmentation
Environmental & ClimateExtreme weather, resource scarcity, transition risk

Risk Scoring Matrix (5×5)

RatingLikelihoodImpact
5 — CriticalNear certain (>90%)Existential threat; potential business failure
4 — HighLikely (60–90%)Severe financial loss; major disruption
3 — MediumPossible (30–60%)Significant but manageable
2 — LowUnlikely (10–30%)Minor impact
1 — NegligibleRemote (<10%)Absorbed in normal operations

Business Impact Analysis (BIA) Outputs

  • RTO (Recovery Time Objective) — Maximum acceptable downtime
  • RPO (Recovery Point Objective) — Maximum acceptable data loss (in time)
  • MAD (Maximum Acceptable Downtime) — Absolute longest unavailability before permanent damage
  • MBCO (Minimum Business Continuity Objective) — Minimum service level during disruption

4. Business Continuity Planning (BCP)

The Six-Step BCP Process

  1. Prepare — Executive sponsorship, budget, cross-functional team (IT, ops, finance, HR, legal, comms)
  2. Define — Clear objectives aligned to strategy. Scope, assumptions, constraints documented.
  3. Identify — BIA + risk assessment. Map critical processes, dependencies, single points of failure.
  4. Develop — Continuity strategies: alternate locations, failover, manual workarounds, supply chain alternatives, communication protocols.
  5. Assign — Teams, roles, chain of command, contact trees. Essential personnel identified and trained.
  6. Test — Tabletop exercises, functional drills, full simulations. Document lessons, revise.

Key BCP Components

  • Incident Response Plan — Detect, assess, escalate, contain. Who communicates what, to whom, how.
  • Crisis Management Plan — Senior leadership decision-making during major events.
  • Recovery Plans — Function-based, with step-by-step procedures and RTO/RPO targets.
  • Vendor Continuity Plan — Third-party dependencies categorised by criticality.
  • Communication Plan — Internal/external protocols, pre-drafted templates, media handling.

Common Pitfalls

  • Treating BCP as one-time project, not ongoing discipline
  • Scenario-based plans that try to cover every event (use function-based instead)
  • Too many people in crisis response = slow decisions
  • Stale contact information and vendor relationships
  • Never testing under realistic conditions

5. Disaster Recovery (DR)

DR Strategy Tiers

TierStrategyTypical RTO
1Active-Active: real-time replication, automatic failoverMinutes
2Warm Standby: near-ready secondary, manual failover1–4 hours
3Cold Standby: provisioned but inactive, restore from backup24–72 hours
4Backup Only: periodic offsite/cloud backups, full rebuildDays to weeks

DR Plan Essentials

  1. System inventory ranked by criticality → mapped to business functions
  2. Backup strategy: frequency, retention, location (on-prem/cloud/hybrid), encryption, test restores
  3. Failover procedures: step-by-step switching, DNS, auth, network reconfig
  4. Recovery sequencing: dependencies, priority order, rollback procedures
  5. Testing: tabletop + component failover + full recovery simulations
  6. Cloud/multi-cloud: data residency, egress costs, single-provider risk

ISO Standards for DR

  • ISO 22301 — BCMS framework (Plan-Do-Check-Act)
  • ISO 27031 — ICT readiness for business continuity
  • ISO 24762 — ICT disaster recovery services
  • ISO 27001 — Information security management

6. Fraud Prevention & Detection

Internal Controls (Non-Negotiable)

  • Segregation of duties — No single person controls initiation, approval, execution, and recording
  • Dual control of payments — One initiates, second approves. Always.
  • Access controls — Role-based, least-privilege, periodic reviews
  • Independent reviews — High-risk transactions reviewed outside normal chain
  • Reconciliation — Daily reconciliation to detect anomalies early

Technology-Enabled Detection

  • AI/ML transaction monitoring (real-time anomaly flagging)
  • Behavioural analytics (user pattern deviation detection)
  • Identity verification (document, biometric, liveness)
  • Device fingerprinting and geolocation analysis
  • Network analysis for organised fraud ring detection

Emerging Threats (2025–2026)

ThreatDescription
Synthetic Identity FraudReal + fabricated data combined to pass KYC
AI DeepfakesVoice/video impersonation for CEO fraud and social engineering
Flash FraudCoordinated rapid-fire exploits for massive short-window losses
Mule AccountsCompromised accounts laundering fraud proceeds
AI-Powered PhishingHyper-personalised attacks using AI-generated content

Regulatory Alignment

  • US: Bank Secrecy Act, USA PATRIOT Act, FinCEN
  • EU: AML Package 2025, AMLA, 6AMLD
  • UK: Proceeds of Crime Act, Fraud Act 2006, FCA rules
  • Multi-jurisdictional: FATF Recommendations

For full fraud governance framework and prevention checklists, read references/full-playbook.md section 7.

7. Reputational Risk Management

Reputational Risk Drivers

Service disruptions, cybersecurity breaches, ethical lapses, social media missteps, third-party/vendor failures, ESG controversies, product recalls, workforce issues.

Five-Step Framework

  1. Identify Drivers — Map all sources of reputational harm from risk registers, stakeholders, media
  2. Set Thresholds — Clear boundaries tied to financial performance, regulatory exposure, media scrutiny
  3. Monitor Continuously — Social listening, media monitoring, sentiment analysis, NPS tracking
  4. Respond Rapidly — Acknowledge mistakes, communicate openly, implement corrective actions
  5. Integrate Cross-Functionally — Risk, compliance, comms, marketing, legal, operations all involved

2025 Regulatory Note

US banking regulators removed reputational risk as standalone supervisory factor (Fed, OCC, FDIC). Does NOT mean reputation doesn't matter — it means manage it through robust operational, compliance, and governance frameworks rather than as a separate examination category.

8. Geopolitical Risk Assessment

Top Risk Categories

CategoryKey Concerns
US-China CompetitionTech decoupling, export controls, AI/semiconductor restrictions
Armed ConflictsUkraine, Middle East — supply chain, commodity, sanctions impact
Trade ProtectionismTariffs, local content, friendshoring, supply chain mandates
Energy SecurityInfrastructure cyber risk, volatile supply routes, transition risk
Sanctions & Export ControlsExpanding, complex regimes requiring continuous monitoring
Climate & EnvironmentalExtreme weather, resource scarcity, carbon border adjustments
Technology SovereigntyData localisation, AI governance divergence, digital sovereignty

Geopolitical Risk Framework

  1. Establish Governance — Geopolitical risk function with board-level sponsorship
  2. Map Exposure — Inventory all geographic dependencies (operations, supply, customers, data, IP)
  3. Monitor Signals — Risk indicators, news analytics, regulatory filings, intelligence briefings
  4. Scenario Plan — Develop and stress-test against key geopolitical developments
  5. Build Flexibility — Diversify supply chains, multi-jurisdictional ops, structural separation
  6. Engage Proactively — Policymakers, industry associations, intelligence-sharing networks

9. Insurance & Risk Transfer

Essential Coverage Types

TypeProtects Against
Cyber InsuranceBreach costs, ransomware, BI from cyber events, regulatory fines
D&OPersonal liability of directors/officers
Professional Indemnity (E&O)Claims from professional advice or negligence
Business InterruptionLost revenue during operational disruption
Crime & FidelityEmployee dishonesty, social engineering fraud
Key PersonLoss of critical individual
General LiabilityThird-party injury, property damage, product liability

Best Practices

  • Annual insurance gap analysis aligned to risk register
  • Review terms, exclusions, sublimits for adequacy
  • Cyber coverage keeping pace with evolving threats
  • Parametric insurance for climate risks
  • Insurance activation integrated into BCP incident response workflow

10. Crisis Communication

Five Principles

  1. Speed — Initial holding statement within first hour. Silence = speculation.
  2. Accuracy — Verified facts only. Correct errors immediately.
  3. Empathy — Acknowledge impact before operational details.
  4. Consistency — Aligned messaging through single source of truth.
  5. Transparency — Share what you know, what you don't, and what you're doing.

11. Testing & Continuous Improvement

Exercise Types

TypeDescriptionFrequency
TabletopDiscussion walkthrough with key stakeholdersQuarterly
Functional DrillActivate specific plan componentsSemi-annually
Full-Scale SimulationEnd-to-end BCP/DR test under realistic conditionsAnnually
Surprise TestUnannounced activationAnnually
Component TestIndividual procedure tests (backup restore, comms tree)Monthly

Lessons Learned Process

After every exercise and real incident: structured debrief → capture what worked / failed / must change → document in lessons-learned register → assign corrective actions with owners and deadlines → track implementation → feed back into plan updates, training, and risk assessments.

12. Key Regulatory & Standards Map

StandardDomainCertifiable?
ISO 22301:2019Business Continuity (BCMS)Yes
ISO 31000:2018Enterprise Risk ManagementNo (guidance)
ISO 27001:2022Information Security (ISMS)Yes
COSO ERMEnterprise Risk ManagementNo (framework)
NIST CSFCybersecurityNo (framework)
DRI Professional PracticesBusiness ContinuityCertification-based
DORA (EU)Digital Operational ResilienceRegulatory
FCA/PRA (UK)Operational ResilienceRegulatory
SOC 2Service Organisation ControlsAttestation
PCI-DSSPayment Card SecurityYes

For detailed metrics, KRI dashboards, implementation roadmaps, and deep-dive reference material, consult: → references/full-playbook.md


Remember: Resilience over recovery. Function-based, not scenario-based. Test everything. Risk is everyone's responsibility. Anticipate, prepare, prevent — then adapt constantly.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

85.6%
按下载量换算4,047

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills