EB Chapter 2 – Enterprise Risk Management in an Organization

Enterprise Risk Management Approaches

  • Enterprise risk management (ERM) provides value by identifying and addressing key risks through systematic frameworks.

  • Bottom-Up Approach: Risks are identified across all levels of the organization to provide a comprehensive view for analysis and prioritization.

  • Top-Down Approach: The board of directors and senior management identify major risks, determine risk management principles, and communicate procedures throughout the organization.

  • Integration: A holistic ERM approach combines both methods to ensure alignment between high-level objectives and operational realities.

Building Blocks for Effective ERM

  • Bottom-Up Building Blocks: Process to identify and prioritize risks at all levels; mitigation policies; integration of risk into normal business decisions; clear risk roles with elevation thresholds; and a vibrant risk culture.

  • Top-Down Building Blocks: Regular senior-level risk discussions; board-level oversight charters; risk management computerized dashboards showing likelihood and effect; and defined risk appetite and strategy statements.

Risk Maturity Models (RMM)

  • RMMs are used to evaluate and improve business processes by assessing progress in ERM development.

  • Capability Maturity Model (CMM): Developed by Carnegie Mellon University with five levels: Ad hoc, Initial, Defined, Managed, and Optimizing.

  • Capability Maturity Model Integration (CMMI): Introduced in 20062006 to evaluate results and the alignment of activities with strategic goals.

  • RIMS Risk Maturity Model: Developed with LogicManager using five maturity levels across seven attributes: Adoption of ERM-based approach, ERM process management, Risk appetite management, Root cause discipline, Uncovering risks, Performance management, and Business resiliency and sustainability.

  • David Hillison Model (19971997): Evaluates organizational value through four levels: Naïve, Novice, Normalized, and Natural.

  • Standard and Poor’s (S&P): Assesses ERM maturity as Positive, Neutral, or Negative based on the effectiveness of policies, tolerances, and stakeholder communication.

Strategic Alignment and Performance

  • Balanced Scorecard: RMMs function as balanced scorecards when risk management professionals add factors to measure the alignment of ERM attributes with strategic objectives.

  • Benchmarking: Studies by Aon and RIMS allow organizations to compare maturity levels; an Aon study found a global average maturity level of 33 out of 55, with only 15%15\% of organizations rating themselves at level 44 or above.

  • Implementation: Reaching the highest level of maturity often takes several years and requires ongoing monitoring and improvement even after full integration.

Organizational Functions and Governance

  • Governance: Boards and senior executives set policies and guidelines, often utilizing dedicated risk committees to provide oversight.

  • Risk Tolerance: Determining risk appetite and tolerance is a governance function influenced by capitalization and regulatory environments.

  • Performance Metrics: Senior executives are accountable for governance and strategic planning, while front-line managers are measured by compliance with risk procedures.

  • Internal Control: These professionals audit operations to detect risk indicators early, collaborating with risk management to evaluate strategic risks.

Evolution of Risk Roles and Regulation

  • Traditionally, risk managers focused on hazard risk while internal control focused on financial risk; modern ERM blurs these lines to manage consequences like directors and officers liability.

  • Chief Risk Officer (CRO): This role often reports to the CEO or CFO and may lead both internal control and risk management functions.

  • Regulatory Standards: Essential compliance requirements include the Sarbanes-Oxley Act of 20022002 and the Dodd-Frank Wall Street Reform and Consumer Protection Act of 20102010.