EB Chapter 2 – Enterprise Risk Management in an Organization
Enterprise Risk Management Approaches
Enterprise risk management (ERM) provides value by identifying and addressing key risks through systematic frameworks.
Bottom-Up Approach: Risks are identified across all levels of the organization to provide a comprehensive view for analysis and prioritization.
Top-Down Approach: The board of directors and senior management identify major risks, determine risk management principles, and communicate procedures throughout the organization.
Integration: A holistic ERM approach combines both methods to ensure alignment between high-level objectives and operational realities.
Building Blocks for Effective ERM
Bottom-Up Building Blocks: Process to identify and prioritize risks at all levels; mitigation policies; integration of risk into normal business decisions; clear risk roles with elevation thresholds; and a vibrant risk culture.
Top-Down Building Blocks: Regular senior-level risk discussions; board-level oversight charters; risk management computerized dashboards showing likelihood and effect; and defined risk appetite and strategy statements.
Risk Maturity Models (RMM)
RMMs are used to evaluate and improve business processes by assessing progress in ERM development.
Capability Maturity Model (CMM): Developed by Carnegie Mellon University with five levels: Ad hoc, Initial, Defined, Managed, and Optimizing.
Capability Maturity Model Integration (CMMI): Introduced in to evaluate results and the alignment of activities with strategic goals.
RIMS Risk Maturity Model: Developed with LogicManager using five maturity levels across seven attributes: Adoption of ERM-based approach, ERM process management, Risk appetite management, Root cause discipline, Uncovering risks, Performance management, and Business resiliency and sustainability.
David Hillison Model (): Evaluates organizational value through four levels: Naïve, Novice, Normalized, and Natural.
Standard and Poor’s (S&P): Assesses ERM maturity as Positive, Neutral, or Negative based on the effectiveness of policies, tolerances, and stakeholder communication.
Strategic Alignment and Performance
Balanced Scorecard: RMMs function as balanced scorecards when risk management professionals add factors to measure the alignment of ERM attributes with strategic objectives.
Benchmarking: Studies by Aon and RIMS allow organizations to compare maturity levels; an Aon study found a global average maturity level of out of , with only of organizations rating themselves at level or above.
Implementation: Reaching the highest level of maturity often takes several years and requires ongoing monitoring and improvement even after full integration.
Organizational Functions and Governance
Governance: Boards and senior executives set policies and guidelines, often utilizing dedicated risk committees to provide oversight.
Risk Tolerance: Determining risk appetite and tolerance is a governance function influenced by capitalization and regulatory environments.
Performance Metrics: Senior executives are accountable for governance and strategic planning, while front-line managers are measured by compliance with risk procedures.
Internal Control: These professionals audit operations to detect risk indicators early, collaborating with risk management to evaluate strategic risks.
Evolution of Risk Roles and Regulation
Traditionally, risk managers focused on hazard risk while internal control focused on financial risk; modern ERM blurs these lines to manage consequences like directors and officers liability.
Chief Risk Officer (CRO): This role often reports to the CEO or CFO and may lead both internal control and risk management functions.
Regulatory Standards: Essential compliance requirements include the Sarbanes-Oxley Act of and the Dodd-Frank Wall Street Reform and Consumer Protection Act of .