Governance risk and controls

Complex business environments demand a more proactive approach to governance. Improve risk oversight, and drive compliant, sustainable performance with Wipfli’s governance services.

Webinar: Balancing risk, resilience and growth
Webinar: Balancing risk, resilience and growth

Operational, tech, cyber and AI risks are all interconnected. Learn practical ways to assess and prioritize risk.

How we help you

Wipfli’s services for governance, risk and controls help you foster resilience with informed decision-making and deliver proactive enterprise risk management services that align risk with growth and your strategic plan. 

Maintain trust with legal, ethical and transparent operations.

Stay ahead of evolving privacy regulations.

Mitigate enterprise risk across increasingly complex operations and technology.

Strengthen governance and manage enterprise risk

Our integrated team takes you from governance and risk strategies to tactical execution across your organization.

Explore our governance risk and controls services

Insights and Resources

  • January 2027 Uniform Guidance regulation training

    EVENT | January 19, 2027

    January 2027 Uniform Guidance regulation training

    Join us for a practical and engaging virtual training of the Office of Management and Budget’s (OMB) Uniform Guidance (2 CFR Part 200) — the cornerstone of federal grant compliance. This training is designed to help nonprofit and government professionals understand federal grant regulations and how to apply them effectively and avoid common pitfalls in managing federal awards. Led by experienced trainers with years of auditing and consulting expertise, this session blends regulatory review with real-world examples and actionable insights. Whether you’re new to federal

  • A man and a woman are collaborating on a laptop to review information.

    ARTICLE

    Manufacturing risk management: Key threats and action steps

    The manufacturing industry is in the midst of a volatile period. Manufacturers must overcome risks like tariffs, supply chain disruptions, international macroeconomic pressures from the wars in Iran and Ukraine, AI growing pains and more — all while protecting profitability. Implementing an effective risk management strategy can help your manufacturing business navigate today’s risks. Keep reading to learn more, plus how to assess and mitigate your own top risks. Why risk management matters for manufacturers Manufacturing businesses are currently operating in a high-VUCA environment. The acronym, which stands for volatility, uncertainty, complexity and ambiguity, describes many of the key pressures manufacturing CFOs and COOs face as they try to maintain smooth operations and combat shrinking margins. Risk management is a way to bring a little stability to that high-VUCA environment. There’s so much you can’t control — tariffs, international trade, wars, government policies — but by focusing on what you can do within your own four walls, you can still manage your risks enough to protect your value and operating income. This often starts with a mindset shift. If you’re willing to let go of your old ways of doing business and embrace changes like new technology or revamped processes, you’ll have taken a big first step towards making your business stronger and more adaptable. What are the major risks facing manufacturers? Manufacturers today face risks like supply chain concentration, workforce shortages and cybersecurity threats. Those risks are compounded by big-picture, geopolitical issues like tariffs and international conflicts, as well as the ongoing rise of AI. Top risks for manufacturers include: Tariff risks: Most U.S. imports are now tariffed at between 10-50% , raising materials costs for many manufacturers while also putting additional cost pressures on consumers. Geopolitical risks: The wars in Iran and Ukraine have strained supply chains and caused price spikes for oil and other essential commodities. Workforce risks: Manufacturing’s perennial labor problem hasn’t gotten any easier, with both worker shortages and high labor costs continuing to pressure businesses. Supply chain risks: Many manufacturers still put too many eggs in one basket, relying on overly concentrated supply chains with respect to both vendors and customers. AI risks: While AI can deliver significant benefits to manufacturers , the technology comes with major risks too , especially in areas like data privacy and shadow AI . Cybersecurity risks: Cybersecurity has increasingly gone from just an IT concern to a significant financial risk , as ransomware attacks or data breaches can lead to financial, operational and reputational harm. Shrinking margins: Rising costs on many fronts are cutting into margins, making it harder for manufacturers to get or stay profitable. Production risks: Depending on industry or process type, manufacturers also face production-specific risks around issues like safety and wasted open capacity. How to assess manufacturing risk Your manufacturing business may deal with many of the industrywide risks covered in this article, but it could also face others more specific to your region or niche within the industry. Conducting a manufacturing risk assessment can help you understand your unique risk environment and develop a strategy to mitigate it. Here’s a practical risk assessment framework for manufacturers (a risk advisory firm can help you work through it): 1. Identify and document risks Identify the risk areas and individual risks that could affect your business. This will likely include industrywide risks like tariffs or cybersecurity. Also consider factors more specific to your business, like a mission-critical employee who’s due to retire or production risks like food or chemical safety. 2. Assess the likelihood and impact of each risk Once you have a list of risks, assess each risk based on likelihood and impact. You can rate each of these factors using a scale of low, medium or high. 3. Prioritize risk based on likelihood and impact Prioritize your risks based on likelihood and impact, as well as your essential business objectives. For example, if supply chain disruptions are both high-likelihood and high-impact, that’s a risk you’ll want to tackle right away, while a low-likelihood, medium-impact risk will likely be much lower on your priorities list. Your C-suite should also discuss risk tolerance. 4. Identify existing controls and gaps Assess the controls, policies and procedures you already have in place to mitigate your high-priority risks. This will also help you identify control gaps that need to be filled, like a lack of AI governance or an ineffective system for tracking tariff costs. 5. Develop risk mitigation strategies Develop a risk management roadmap to tackle your top priority risks. This will typically include establishing new controls or policies to manage risk, as well as training, scenario planning and strategic steps like technology upgrades or inventory management changes. 6. Assign risk owners and accountability To ensure your risk management roadmap actually gets implemented, assign owners to each action step. Creating a system of accountability, like regular reporting at the C-suite or board level, can also help drive follow-through. 7. Monitor and assess risk regularly As you implement your risk management roadmap, continue to regularly monitor your risk environment and periodically reassess. Risks are constantly evolving, so your risk management strategy needs to be, too. How can manufacturers mitigate business risks? Implementing a risk management strategy can help manufacturing CFOs and COOs mitigate their top business risks. Depending on the results of your risk assessment, you may wish to consider strategies like: Work with a risk management advisor An advisory firm that works with manufacturers to manage risk and improve performance can help your business navigate today’s high-VUCA environment. Look to an advisor to conduct your risk assessment and help you implement internal controls, operational changes and strategic shifts to manage your risks. Strengthen supply chain resilience Diversify your supply chain to mitigate tariff and disruption risks. Start by mapping your supply chain and identifying possible alternatives for both sourcing and customers. You may also want to do a reshoring or nearshoring evaluation to determine if either could make sense for your business. Improve operational processes and controls Running your business more efficiently can help protect your margins from surging costs . One idea: Implement production monitoring to get a clearer sense of how your production is performing on a day-to-day basis (you’ll get a dashboard showing red or green status for your machines) so you can establish a baseline to improve on. You can also use AI to make predictive maintenance recommendations to reduce your risk of machine downtime. Strengthen your analytics The more data you have, the better you understand how your business is performing. This applies to not just production line performance but also areas like costs, pricing, inventory and organizational performance — all of which can help you identify inefficiencies and understand how what happens in your plant impacts profitability. Implement strong cybersecurity and AI controls You need effective controls for cybersecurity , data protection and AI. This typically includes establishing technology governance , implementing ongoing cybersecurity training and taking steps to make your business more cyber resilient . Improve financial forecasting and scenario planning CFOs should take advantage of AI’s analytical capabilities to do extensive financial forecasting and evaluate the impact of various scenarios. Forecasting and scenario planning can help you to both understand potential risk areas and decide which to prioritize in your risk roadmap. Regularly reassess risks and update controls and strategies Don’t assume today’s risks are the same as tomorrows. Make risk management an ongoing, living practice that includes periodic reassessments and updates to your controls and strategies. Stop putting off succession planning Succession planning isn’t just about who will own the company 10 years from now. Engaging in a thoughtful succession planning process makes your whole business more stable by ensuring continuity of knowledge after a long-time employee retires, passing sales relationships from one generation to the next and giving employees a path to move up in the business. Don’t ignore valuable tax opportunities Manufacturers can often offset margin pressures using tax incentives. Depending on the circumstances, these may include R&D tax credits , bonus depreciation or qualified production property , state-level incentives and even sunsetting energy efficiency deductions like 179D that could still apply to plant upgrades you’ve already made. Read More Can the qualified production property rule help your manufacturing firm reduce tax payments? Cybersecurity in manufacturing: Strategies to mitigate risk Manufacturing trends: What 456 leaders say about the industry today.

  • Business team reviews financial data on a tablet.

    ARTICLE

    From compliance to confidence: Mastering the new CMMC 2.0 requirements

    The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the newest iteration of the Department of Defense’s (DoD) cybersecurity rules for contractors. This framework aims to ensure that all defense contractors implement necessary cybersecurity safeguards to protect controlled unclassified information (CUI) and federal contract information (FCI). CMMC 2.0 compliance requirements were originally scheduled to take effect in four phases from November 2025 through 2028. However, in July 2026, the DoD paused Phase II indefinitely , although most other CMMC requirements remain active. Keep reading to learn what’s changing and how your business may need to adapt. What is CMMC 2.0? The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a cybersecurity compliance framework for defense contractors and other vendors who work with the Department of Defense (informally referred to as the Department of War). CMMC 2.0 is the latest version of the CMMC framework and now appears in all DoD contracts with the goal of raising cybersecurity standards for the defense industrial base (DIB). Is CMMC compliance mandatory? DoD contractors who wish to continue bidding on federal defense contracts must meet CMMC 2.0 compliance requirements . However, the Phase II pause means you no longer have to complete a third-party assessment in order to demonstrate compliance. Who does CMMC 2.0 apply to? CMMC 2.0 applies to all contractors, vendors and other third-party organizations that do business with the Department of Defense. Especially in light of the Phase II pause, expect that CMMC will continue to evolve in the coming years. What is the CMMC 2.0 Phase II pause? On July 13, 2026, the DoD announced it was pausing Phase II of the CMMC 2.0 rollout indefinitely. Phase II, which was supposed to begin on November 10, 2026, originally required organizations handling higher levels of sensitive information to complete third-party CMMC compliance assessments. However, due to the pause, organizations no longer have to complete third-party assessments to demonstrate CMMC 2.0 compliance. Most other requirements remain in effect, and DoD is continuing to include CMMC in new contracts. It is likely that DoD will announce significant revisions to the rest of the CMMC rollout at some point in the future. Before the pause, CMMC 2.0 had originally established a three-year phased implementation period CMMC 2.0 was originally scheduled to roll out in four phases from 2025 through 2028. While the Phase II pause means the entire rollout schedule will likely be revamped, here is that original schedule as it was first established: Phase I: The first phase began on November 10, 2025. During this phase, the DoD can begin to include CMMC 2.0 requirements in new contracts. Contractors will need to meet Level 1 or Level 2 self-assessment requirements as a condition of contract award. Phase II: Before the pause, the second phase was originally scheduled to start one year after Phase I, on November 10, 2026. In this phase, contractors handling CUI would have been required to undergo a third-party assessment by a certified assessor organization as a condition of award. Phase III: The third phase was scheduled to begin on November 10, 2027. This phase would have involved the DoD itself conducting Level 3 CMMC assessments for contracts involving the most sensitive CUI, but will also likely be revamped in light of the Phase II pause. Phase IV: The final phase was supposed to start three years on November 10, 2028. This phase would have marked the full implementation of the CMMC requirements across all applicable solicitations and contracts. This phased approach was intended to address ramp-up issues, provide runway to train the necessary number of assessors and allow companies the time needed to understand and implement CMMC requirements . Key clarifications around CMMC 2.0 compliance requirements As the newest version of DoD cybersecurity rules, CMMC 2.0 provides several key clarifications that are crucial for CISOs and compliance officers at defense contractors to understand. These include: The operational plan of action allows contractors to identify temporary vulnerabilities and deficiencies, as opposed to documenting in a plan of action and milestones (POA&M). This allows for management to remediate vulnerabilities or deficiencies identified through the normal operation of detective controls without causing you to go out of compliance. Contractors must retain artifacts used in evidence for an assessment for at least six years after the date of their certification assessment. This retention obligation extends to the annual self-certifications that contractors must perform. External service providers are not required to have CMMC certification, but are “in-scope” if they store, transmit or process CUI. An endpoint hosting a virtual desktop infrastructure (VDI) client configured to disallow processing, storage or transmission of CUI beyond keyboard/video/mouse sent to the VDI client is considered an out-of-scope asset. How should you implement the CMMC 2.0 cybersecurity framework? Even with the Phase II pause, most CMMC 2.0 requirements remain in effect. Defense contractors must take several steps to become compliant and properly flow down the compliance requirements to their subcontractors, including: 1. Understand the three CMMC 2.0 levels Based on the type of sensitive information or CUI your organization handles, you should determine the appropriate CMMC level for your organization. This will guide your compliance efforts and help you identify the specific requirements you need to meet. The three levels are: Level 1: Basic protection of FCI, requiring an annual self-assessment. Level 2: General protection of CUI, which can now be achieved through a self-assessment in light of the Phase II pause. Level 3: Enhanced protection against advanced persistent threats. This would have required an assessment led by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), starting with Phase III in November 2027, but may now be revamped. 2. Conduct proper scoping of your environment. Proper scoping of your environment for CMMC 2.0 is crucial because it clearly defines the boundaries where CUI is stored, processed and transmitted within your organization. This allows you to focus security efforts only on the relevant systems and data, minimizing the scope of your assessment and ultimately reducing the cost and complexity of achieving compliance while ensuring the most critical assets are adequately protected. If not done correctly, your entire network could be considered “in-scope” for assessment, leading to unnecessary overhead and potential noncompliance issues. 3. Perform a gap analysis. Assess your current cybersecurity posture against the CMMC 2.0 standards. Conduct a thorough gap analysis to identify deficiencies in your existing cybersecurity controls. This will help you develop a POA&M to address these gaps and achieve compliance. 4. Implement required controls. Based on the results of your gap analysis, implement the necessary cybersecurity controls to meet the CMMC requirements. This may involve updating your policies, procedures and technical controls, or implementing new technology. 5. Prepare for assessment. You’ll need to complete a self-assessment to demonstrate CMMC 2.0 compliance. Before you begin, ensure that you have all the required documentation and evidence in place. This includes maintaining control evidence for six years and being prepared for potential audits by the DoD. 6. Flow down requirements to subcontractors. Ensure that your subcontractors are also compliant with the CMMC requirements. Flow down the relevant requirements to all subcontractors at every tier and verify their compliance. By following these steps, defense contractors can help ensure that they are fully compliant with the CMMC 2.0 requirements and are well-prepared to protect sensitive information from evolving cyberthreats. A third-party advisor can help you navigate this process and implement solutions to bring you up to speed. Read more Cybersecurity is a financial issue The right cybersecurity framework boosts a business’s value 5 common CMMC 2.0 pitfalls

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Reach out to our team

Talk to our team to see how you can better navigate complex governance, risk and compliance challenges.

FAQs about enterprise risk management services