Governance. Risk. Compliance. Cybersecurity.
GRC Advisory · Playbook

Risk management frameworks compared — NIST RMF, ISO 31000 and COSO ERM.

A long-form GRC framework guide: when each framework wins, how they map to regulators, and how to combine them into one auditable programme.

AuthorGRC Practice LeadPublishedJun 2026Read time4 min readFormatPlaybook
GRC AdvisoryPlaybookGRCAuditRegulatory
GRC Advisory insight — Risk management frameworks compared — NIST RMF, ISO 31000 and COSO ERM.
MAST Consulting Group · GRC Advisory practice

This playbook captures the sequence MAST Consulting Group uses on GRC Advisory engagements when a programme owner has roughly the next two quarters to show measurable progress. It is opinionated, written to be lifted into your own plan, and assumes you already have a control framework in place — the question is how to move from documented to demonstrably operating.

What this piece is actually arguing

The title — "Risk management frameworks compared — NIST RMF, ISO 31000 and COSO ERM" — is a deliberate claim. A long-form GRC framework guide: when each framework wins, how they map to regulators, and how to combine them into one auditable programme. The framing assumes you have the next two quarters to act, and want to know where the marginal hour returns the most.

In GRC Advisory work, that claim has to map to something concrete: the unified control framework; the enterprise risk register; the control catalogue. Those are the anchors a delivery team will return to when they want to test whether the recommendations actually hold.

Why this matters now

Regulators are increasingly asking for evidence that the three lines are operating, not just that they are documented. For GRC Advisory programmes, that has changed who the work is performed for: not just the board risk committee, but also external auditors covering ICFR and sector regulators (CBUAE, SAMA, DFSA, RBI, SEBI, IRDAI).

The internal sponsor — typically the Chief Risk Officer backed by the head of compliance — now has to defend the same control twice in the same quarter to two different audiences, often with different vocabularies. That changes the operating model more than the controls themselves.

The recommendations in this playbook are written for that reality. They assume continuous evidence, regulator-on-site visits, customer-driven assurance requests and AI-assisted reviewer tooling that surfaces inconsistencies the moment they appear.

A the next two quarters working plan

MAST Consulting Group runs this GRC Advisory work in four moves. Each move is short, evidence-producing, and signed off by a Lead Practitioner before the next begins.

  • Frame (week 1). Confirm scope, regulators in play, and the decisions the work has to enable — referenced against the three lines of defence. Without that framing, the rest becomes a documentation exercise the audit committee will not read.
  • Diagnose (weeks 2–4). Walk through control testing programme and KRI dashboard as they exist today. Capture not just gaps but the design decisions behind every existing control — those are usually where audit findings hide.
  • Design (weeks 5–8). Make the contested choices early and pre-clear them with sector regulators (CBUAE, SAMA, DFSA, RBI, SEBI, IRDAI). Document the rationale; GRC Advisory reviewers care more about reasoned decisions than perfect ones.
  • Operate (weeks 9–12). Move evidence collection into GRC platforms (Archer, ServiceNow IRM, OneTrust) and or a deliberately spreadsheet-and-Confluence stack for early-stage programmes. A control that depends on a separate GRC tool nobody opens will fail within two cycles.

Pitfalls we keep seeing

Across MAST Consulting Group's GRC Advisory portfolio, the same recurring failure modes show up cycle after cycle. None are exotic; all are expensive when they reach the audit report.

  • Pattern: issue tracker maintained in parallel by audit, risk and compliance. What good looks like: the same control evidenced inside the workflow it governs, not separately for the audit.
  • Pattern: risk appetite statement that the second line cannot operationalise. What good looks like: the same control evidenced inside the workflow it governs, not separately for the audit.
  • Pattern: duplicate controls across ISO/SOC/PCI catalogues with no master mapping. What good looks like: the same control evidenced inside the workflow it governs, not separately for the audit.
  • Pattern: KRIs that move but no one is accountable for the response. What good looks like: the same control evidenced inside the workflow it governs, not separately for the audit.

Tooling we actually reach for

MAST Consulting Group is deliberately tool-agnostic, but in practice the same shortlist keeps appearing on GRC Advisory engagements because the integrations are cheap and the evidence is defensible:

  • BI tools (Power BI, Tableau) for board dashboards — used not because it is fashionable, but because the audit trail it generates is one the reviewer accepts on the first ask.
  • GRC platforms (Archer, ServiceNow IRM, OneTrust) — used not because it is fashionable, but because the audit trail it generates is one the reviewer accepts on the first ask.
  • or a deliberately spreadsheet-and-Confluence stack for early-stage programmes — used not because it is fashionable, but because the audit trail it generates is one the reviewer accepts on the first ask.

How MAST Consulting Group can help

MAST Consulting Group runs GRC Advisory programmes for banks, insurers, healthcare networks, payments providers, telcos and government entities across the UAE, KSA, India and the wider GCC. We bring Lead Practitioners, sector specialists, and a working library of policies, risk methodologies and evidence templates that have passed audit at firms recognisable to your board.

If anything in this playbook is relevant to a programme you are scoping or rescuing, the fastest next step is a 30-minute working session with the practice lead. We will look at your specific situation, share what we have seen work for GRC Advisory programmes at similar scale, and tell you honestly if the work is something you should bring to us or run in-house.

GRC Advisory

Build a GRC operating model your board will trust.

Unified control frameworks, three-lines design, risk appetite statements and tooling decisions — sequenced to the next two audit cycles.

  • Operating-model and three-lines diagnostic
  • Unified Control Framework harmonisation
  • Board-ready KRI/KPI design

Prefer email? info@mastcgroup.com

Book a GRC advisory call

Reply within one business day from a senior consultant.

By submitting you agree to be contacted by a MAST consultant. We never share your details.

Matched on service area and shared topics.

Back to all insights