Elliot Book Chapter 1: Introduction to Enterprise Risk Management
Core Concepts of Enterprise Risk Management (ERM)
ERM emerged following large-scale corporate failures like Enron and WorldCom and the financial crisis of .
Traditional risk management focuses on pure hazard risk, whereas ERM integrates operational, financial, and strategic risks.
The International Organization for Standardization (ISO) defines risk management as coordinated activities to direct and control an organization regarding risk.
Risk is defined as the effect of uncertainty on objectives, linking risk management directly to organizational goals.
Theoretical Pillars of ERM
Interdependence: Recognizes that risks managed together behave differently than if managed in isolation.
Correlation: Uncorrelated risks can provide a hedge or balance to reduce overall risk, whereas correlated risks increase it.
Portfolio Theory: Assumes risk includes both individual risks and their interactions; a portfolio in this context is a combination of risks.
Governance and Organizational Roles
The Chief Risk Officer (CRO) facilitates risk strategic goals using SWOT (strengths, weaknesses, opportunities, and threats) analysis.
The Dodd-Frank Act () requires certain financial companies to establish board risk committees.
Boards of directors and audit committees have ultimate oversight responsibility, often aided by executive-level risk committees.
ERM fosters a risk culture where managers and individual employees become risk owners.
Risk Classifications and Quadrants
Pure Risk: Chance of loss or no loss, with no potential for gain.
Speculative Risk: Chance of gain or loss, including price risk, credit risk, and investment risks (market, inflation, interest rate, and liquidity risks).
Objective vs. Subjective: Objective risk is based on data ( executives surveyed by PwC), while subjective risk is based on opinion or perceived control.
Diversifiable vs. Nondiversifiable: Nondiversifiable risks are correlated and affect large segments of society simultaneously (e.g., inflation, natural disasters).
Systemic Risk: Potential for major disruption in an entire financial system, such as the failure of Lehman Brothers.
The Four Quadrants: Hazard (property/liability), Operational (people/processes), Financial (market/credit), and Strategic (economic/political/demographic trends).
Internal and External Drivers of ERM
Internal: Strategic planning enhancement, management of financial volatility, and the optimization of capital allocation.
External: Includes the Sarbanes-Oxley Act (SOX) of (specifically Section regarding internal controls), SAS (), credit rating agencies (S&P, Moody's), and investor demand for transparency.
Social Responsibility: FERMA () data indicates corporate social responsibility () and catastrophic events () are primary triggers for risk programs.
Case Study (Target): Implementation driven by Securities and Exchange Commission Rule and S&P criteria, narrowing focus to the top risks to align appetite and strategy.
ERM Value Proposition
Strategic Decision Making: Shifts focus from "cost/benefit" to "risk/reward" and aligns risk appetite (total exposed amount) with risk tolerance (acceptable uncertainty).
Risk Radar: A scanning system to identify emerging risks that may not yet exist but could impact operations if they materialize.
Business Performance: ERM helps reduce earnings volatility, improve credit ratings, and ensure business resiliency against external threats like weather or terrorist disasters.
Capital Allocation: Identifies methods to reduce the cost of risk, exemplified by the University of California, and directs capital to high-reward strategic options.
Regulatory Compliance: Ensures adherence to global standards like the Basel II Accord and national laws like the Dodd-Frank Act ().