I provide tailored risk management services to help organizations identify, assess and manage risks that may affect their objectives, operations and long-term resilience.
Drawing on extensive professional experience across regulatory, advisory and corporate environments, I support organizations in developing practical and proportionate risk management frameworks, methodologies, risk assessments and risk registers, aligned with recognized standards such as ISO 31000 and COSO ERM.
My approach is focused on making risk management a practical decision-making tool, adapted to each organization’s size, activities and specific risk profile.
My services cover the full risk management cycle, from establishing an appropriate framework and methodology to identifying and assessing risks, defining mitigation measures and monitoring their evolution over time.
Depending on the organization’s needs, this may include risk assessments, risk registers, risk treatment plans, employee training and awareness, periodic reviews and ongoing risk management support. The approach is tailored to the organization and informed by internationally recognized frameworks and good practices, including ISO 31000 and COSO ERM.
I support organizations in developing or reviewing risk management frameworks and methodologies tailored to their size, activities, governance structure and risk profile.
The framework provides a consistent and practical approach to identifying, assessing, managing and reporting risks across the organization, while clearly defining roles, responsibilities and decision-making processes.
Depending on the organization’s needs, the service may include the development or review of risk management policies and methodologies, risk assessment criteria and scales, risk appetite and tolerance principles, roles and responsibilities, risk reporting mechanisms and supporting tools and templates.
The approach is informed by internationally recognized principles and good practices, including ISO 31000 and COSO ERM, while remaining proportionate and practical for the organization.
I conduct structured risk assessments to help organizations identify and understand the risks that may affect their objectives, operations and performance, and determine appropriate measures to manage them.
The process is tailored to the organization and may include risk identification, analysis of likelihood and impact, evaluation of existing controls, determination of inherent and residual risk levels, and development of appropriate mitigation measures and action plans.
The results are documented in a practical risk register, providing a clear view of key risks, controls, risk owners, mitigation actions and priorities. Where a risk assessment is already in place, I can also support its periodic review and reassessment to reflect changes in the organization, its activities or the external environment.
The objective is not simply to document risks, but to provide management with a practical tool for prioritizing actions, allocating resources and supporting informed decision-making.
I provide tailored risk management training designed to help employees, managers and risk owners understand their role in identifying, assessing and managing risks within the organization.
Training content is adapted to the organization’s activities, risk profile and existing risk management framework, combining key risk management concepts with practical examples relevant to participants’ roles and responsibilities.
Sessions may cover risk identification and assessment, risk ownership, controls and mitigation measures, risk reporting and escalation, as well as the practical use of the organization’s risk management methodology and tools.
The objective is to build a consistent understanding of risk across the organization and support the integration of risk management into day-to-day activities and decision-making.
Organizations that require a dedicated risk management function do not always need – or wish to maintain – a full-time in-house Risk Manager.
I can act as an outsourced Risk Manager, providing ongoing support in coordinating and maintaining the organization’s risk management framework and processes, while working closely with management, risk owners and other relevant functions.
Depending on the agreed scope, the role may include coordinating periodic risk assessments and reviews, maintaining the risk register, monitoring mitigation actions, supporting risk owners, identifying and assessing emerging risks, preparing management risk reports and supporting the continuous improvement of the risk management framework.
This model provides organizations with access to experienced risk management expertise on a flexible, part-time or ongoing basis, without the costs and long-term commitment associated with a full-time internal position.
Effective risk management should do more than document risks. It should provide clarity, support better decisions and help organizations respond proactively to uncertainty and change.


When searching for risk management services in Romania, clients often raise similar questions about risk registers, ISO 31000 compliance, risk assessments, and outsourced risk management consultancy. Below, I provide clear answers that explain how my services as a freelance risk management consultant in Bucharest can help companies strengthen their enterprise risk management frameworks, ensure regulatory compliance with Romanian and EU standards, and reduce exposure through tailored risk mitigation strategies.
A risk assessment is the process through which an organization identifies, analyzes and evaluates the risks that may affect its objectives and determines how those risks should be managed.
A risk management framework is broader. It establishes how risk management operates across the organization, including the methodology and assessment criteria, roles and responsibilities, risk ownership, reporting and escalation mechanisms, and the processes for monitoring and reviewing risks over time.
An organization may conduct individual risk assessments without having a formal risk management framework. However, a structured framework helps ensure that risks are assessed and managed consistently across the organization and that risk information becomes part of ongoing management and decision-making.
There is no general legal requirement for every company in Romania to implement a company-wide risk management framework or conduct an enterprise-wide risk assessment. However, specific risk assessments are mandatory for certain organizations or areas of activity under sector-specific legislation, including areas such as anti-money laundering, occupational health and safety, financial services and other regulated sectors.
Even where a comprehensive organizational risk assessment is not legally required, it can provide significant business value. A structured risk assessment helps organizations anticipate potential threats and vulnerabilities before they materialize, understand which risks require immediate attention, prioritize resources and mitigation efforts, and make better-informed strategic and operational decisions. It also supports business continuity and organizational resilience by enabling management to respond more effectively to changes, disruptions and emerging risks.
Yes. The risk management function can be performed internally, outsourced to an external specialist, or organized through a combination of internal and external resources, depending on the organization’s size, complexity and needs.
Outsourcing can be particularly suitable for organizations that require dedicated risk management expertise but do not need a full-time internal position. The external Risk Manager can coordinate the risk management process, work with management and risk owners, oversee risk assessments and reviews, monitor mitigation actions and support risk reporting.
Regardless of the model chosen, management and risk owners remain responsible for the risks within their areas of responsibility and for the decisions taken in response to those risks.
No. Risk management can provide value to organizations of any size and in any sector. Smaller and medium-sized organizations may be particularly exposed to certain risks because they often operate with more limited financial, human or operational resources and may be more vulnerable to unexpected disruptions.
A proportionate risk management approach does not need to be complex or bureaucratic. It should reflect the organization’s size, activities and risk profile, helping management focus on the risks that matter most, anticipate potential problems and allocate resources more effectively.
Besides risk management services, I also offer:
Phone: +40 733 920 484
Email: ioana@guardiancompass.ro
©2026 Guardian Compass, All right reserved.