Practice
Risk, Resilience & Governance
Resilience designed before it is needed.
Thyor helps boards, owners and executives understand where their organisations are genuinely exposed — financial, operational, strategic and third-party — and builds the controls, scenario plans, continuity arrangements and governance rhythms that hold under pressure.
Why it matters
The context behind the practice.
Risk functions in growing businesses tend to accumulate rather than develop: a register maintained for an insurer, controls designed for a smaller company, continuity plans that have never been tested. The gap between the risks the business actually carries and the framework nominally managing them widens silently until an event exposes it.
For private companies and family enterprises the exposure is personal as well as corporate. Concentration — of customers, suppliers, key people, jurisdictions and the owners’ own wealth — is the characteristic risk of private enterprise, and the least formally managed.
Governance is the connective tissue. Boards that receive the right information at the right cadence, with honest scenario analysis behind it, make better decisions in calm periods and far better decisions in difficult ones.
When to engage
Recognisable situations.
- 01
The framework has not kept pace
The business has grown, acquired or internationalised while the control environment stayed where it was.
- 02
Concentration worries the owners
A small number of customers, suppliers, people or markets carry a disproportionate share of the outcome.
- 03
A board wants independent assurance
Directors or owners want an objective view of exposure that management, close to the detail, cannot easily provide.
- 04
A scenario must be planned
A downturn, a contract loss, a key-person event or a geopolitical shift needs structured contingency thinking.
- 05
An incident has occurred
A fraud, a control failure or a near-miss requires investigation support and a credible remediation programme.
- 06
Stakeholders require evidence
Investors, lenders, insurers or regulators expect demonstrated control and continuity arrangements.
How the work is approached
A method built around the decision.
- 01
Establish what matters
The assets, relationships and cash flows whose loss would genuinely damage the enterprise — risk defined by consequence, not catalogue.
- 02
Map exposure honestly
Where the business is actually exposed, including the concentrations and dependencies that sit outside formal registers.
- 03
Test the current defences
Which controls exist, which operate, and which would hold under realistic pressure.
- 04
Design the response
Controls, scenarios, continuity arrangements and governance cadence proportionate to the exposure.
- 05
Rehearse and embed
Tabletop exercises, reporting rhythms and accountability so the framework is lived, not filed.
Scope of work
The advisory workstreams involved.
Risk architecture
- Enterprise risk advisory
- Financial, operational and strategic risk
- Third-party and concentration risk
- Cross-border operating risk assessment
Controls & integrity
- Internal controls and governance
- Fraud-risk and control-environment assessment
- Segregation-of-duties and authority design
- Control remediation programmes
Resilience
- Scenario planning
- Crisis preparedness
- Business continuity
- Downside and contingency planning
Governance
- Board and committee reporting
- Risk appetite and escalation frameworks
- Management cadence and accountability design
- Family enterprise governance support
What clients receive
Concrete working outputs, not presentation theatre.
- Risk exposure and concentration maps
- Control environment assessments and remediation plans
- Scenario and downside planning models
- Business continuity and crisis-preparedness frameworks
- Board and committee reporting suites
- Risk appetite and escalation frameworks
- Third-party and supplier dependency analyses
Representative situations
The shape of mandates in this practice.
Control rebuild after a fraud discovery
A portfolio company discovered a procurement fraud. Thyor supported the investigation’s financial workstreams, assessed the control environment and led the remediation programme the board reported against.
Continuity planning for a concentrated supplier base
A manufacturer dependent on two critical suppliers needed a credible continuity plan. Scenario modelling quantified the exposure; alternative sourcing and contract changes reduced it.
Next step
Resilience designed before it is needed.
Handled with strict confidentiality from first contact.