Case study Telekom Malaysia
Embedding ISO 31000 Across a Complex Organisation

Overview
Telekom Malaysia (TM) operates across multiple business units with strict regulatory expectations and high operational complexity.
Risk was managed inconsistently across departments; assessed and reported differently, creating fragmented visibility.
Leadership lacked a unified view of enterprise risk, making it difficult to prioritise what mattered most.
Solution
Designed and implemented an ISO 31000-aligned Enterprise Risk Management framework tailored to TM's operational realities.
Standardised core principles: risk identification, assessment, ownership, and reporting with flexibility across units.
Consolidated risk information into a single view for leadership, enabling informed prioritisation.
Embedded risk management into existing governance and planning processes shifting it from a reporting exercise to a practical tool.
Provided guidance and training so TM's teams could own and sustain the programme internally.
Outcome
Established a consistent, organisation-wide approach to risk management across all business units.
Leadership gained clearer visibility into enterprise-wide risks to support better decision-making.
Teams became more aligned in how they assess and respond to emerging issues.
Risk management moved from fragmented and reactive to coordinated and proactive.
Organisation strengthened readiness for both operational disruptions and regulatory requirements.
Case Study Related to Consulting & Advisory, Crisis & Resilience

