Elliot Book Chapter 1: Introduction to Enterprise Risk Management

Core Concepts of Enterprise Risk Management (ERM)

  • ERM emerged following large-scale corporate failures like Enron and WorldCom and the financial crisis of 20082008.

  • Traditional risk management focuses on pure hazard risk, whereas ERM integrates operational, financial, and strategic risks.

  • The International Organization for Standardization (ISO) 20092009 defines risk management as coordinated activities to direct and control an organization regarding risk.

  • Risk is defined as the effect of uncertainty on objectives, linking risk management directly to organizational goals.

Theoretical Pillars of ERM

  • Interdependence: Recognizes that risks managed together behave differently than if managed in isolation.

  • Correlation: Uncorrelated risks can provide a hedge or balance to reduce overall risk, whereas correlated risks increase it.

  • Portfolio Theory: Assumes risk includes both individual risks and their interactions; a portfolio in this context is a combination of risks.

Governance and Organizational Roles

  • The Chief Risk Officer (CRO) facilitates risk strategic goals using SWOT (strengths, weaknesses, opportunities, and threats) analysis.

  • The Dodd-Frank Act (20102010) requires certain financial companies to establish board risk committees.

  • Boards of directors and audit committees have ultimate oversight responsibility, often aided by executive-level risk committees.

  • ERM fosters a risk culture where managers and individual employees become risk owners.

Risk Classifications and Quadrants

  • Pure Risk: Chance of loss or no loss, with no potential for gain.

  • Speculative Risk: Chance of gain or loss, including price risk, credit risk, and investment risks (market, inflation, interest rate, and liquidity risks).

  • Objective vs. Subjective: Objective risk is based on data (1,0001,000 executives surveyed by PwC), while subjective risk is based on opinion or perceived control.

  • Diversifiable vs. Nondiversifiable: Nondiversifiable risks are correlated and affect large segments of society simultaneously (e.g., inflation, natural disasters).

  • Systemic Risk: Potential for major disruption in an entire financial system, such as the failure of Lehman Brothers.

  • The Four Quadrants: Hazard (property/liability), Operational (people/processes), Financial (market/credit), and Strategic (economic/political/demographic trends).

Internal and External Drivers of ERM

  • Internal: Strategic planning enhancement, management of financial volatility, and the optimization of capital allocation.

  • External: Includes the Sarbanes-Oxley Act (SOX) of 20022002 (specifically Section 404404 regarding internal controls), SAS 115115 (20092009), credit rating agencies (S&P, Moody's), and investor demand for transparency.

  • Social Responsibility: FERMA (20132013) data indicates corporate social responsibility (31%31\,\%) and catastrophic events (45%45\,\%) are primary triggers for risk programs.

  • Case Study (Target): Implementation driven by Securities and Exchange Commission Rule 33908933-9089 and S&P criteria, narrowing focus to the top 1010 risks to align appetite and strategy.

ERM Value Proposition

  • Strategic Decision Making: Shifts focus from "cost/benefit" to "risk/reward" and aligns risk appetite (total exposed amount) with risk tolerance (acceptable uncertainty).

  • Risk Radar: A scanning system to identify emerging risks that may not yet exist but could impact operations if they materialize.

  • Business Performance: ERM helps reduce earnings volatility, improve credit ratings, and ensure business resiliency against external threats like weather or terrorist disasters.

  • Capital Allocation: Identifies methods to reduce the cost of risk, exemplified by the University of California, and directs capital to high-reward strategic options.

  • Regulatory Compliance: Ensures adherence to global standards like the Basel II Accord and national laws like the Dodd-Frank Act (20102010).