Marchetti Book Chapter 1: Overview of Enterprise Risk Management
Enterprise Risk Management Introduction and Core Philosophy
Enterprise risk management (ERM) encompasses the methods and processes utilized by organizations to minimize surprises and seize opportunities associated with reaching objectives.
ERM aligns strategy, process, and knowledge to curtail surprises and losses while capitalizing on business opportunities.
Risk is not exclusively associated with negative outcomes; there is a significant potential value component. Effective risk management balances risk and reward, allowing organizations to take intelligent risks rather than merely avoiding them.
An effective program balances people and processes, involving both quantitative factors and management judgment.
An entity's risk profile is finalized through the actions and decisions of the board of directors, management, and employees.
Organizations generally perform some type of informal risk management, resulting in an undocumented risk management plan.
Strategic Foundations and Organizational Culture
The initial introduction of formal assessment and management is critical to long-term success. Success depends on considering the entity's culture and avoiding overcomplication with technical terminology.
Early discussions should emphasize the benefits of the program. Employees should be encouraged to consider what could fail (threats to performance or perception) regarding entity objectives.
Risk management is essentially choice management, described as a continuous work in progress.
Entities must identify risks to determine whether to assume them or address them through mitigation.
Assessments must consider both tangible consequences (loss of revenue, stock price drops) and intangible possibilities (public perception).
Organizations often utilize a siloed process, focusing on single business areas. However, because risks are dynamic and interdependent, an aggregate view is necessary. Risks should not be separated and managed independently, as this approach is rarely successful.
Integrated Risk Organization Components
The challenge for management is determining the level of uncertainty to accept while striving to improve stakeholder value.
Risk identification starts with identifying strategic goals and objectives, followed by analyzing potential internal and external events that could negatively affect those goals.
An integrated risk organization consists of three specific components:
Centralized risk management reporting directly to the chief executive officer and the board of directors.
An integrated strategy that adopts a holistic view of all risk types.
The integration of risk management directly into business processes.
Execution methods vary based on size, structure, and culture, but a proactive integrated approach transforms risk management into an offensive weapon rather than a defensive reaction.
Historical Guidance and Regulatory Frameworks
In , the Committee of Sponsoring Organizations () of the Treadway Commission issued the conceptual framework: Internal Control – Integrated Framework. Its specific charge was studying factors leading to fraudulent financial reporting.
Internal control is defined as: A process, affected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in three categories:
Effectiveness and efficiency of operations
Reliability of financial reporting
Compliance with applicable laws and regulations
Following the Sarbanes-Oxley Act () in , the Securities and Exchange Commission () suggested the framework for internal control over financial reporting ().
established the Public Company Accounting Oversight Board ().
Auditing Standard () No. (An Audit of Internal Control over Financial Reporting that Is Integrated with an Audit of Financial Statements) directs auditors to utilize a top-down risk-based approach. This emphasizes entity-level controls and high-risk areas.
In , published the ERM – Integrated Framework to help organizations formally establish or improve risk management principles and language.
The Auditing Standards Board issued Statement of Auditing Standards () (the Risk Assessment ), which require documentation of management’s and the auditor’s risk assessment process.
The standard progression involves risk assessment followed by risk mitigation, which is achieved through control activities.
Corporate Governance and Strategy Alignment
Entities should adopt a top-down organization structure starting with corporate governance, progressing to risk assessment, and ending with compliance.
Section initially caused an inverted pyramid effect where organizations focused on compliance first and governance last; recent standards have shifted attention back toward the top-down approach.
Strategy must be documented by executive management and the board of directors, outlining desired goals and objectives to create stakeholder value.
Effective ERM is difficult or impossible to execute without a defined and articulated strategy, as the strategic plan facilitates all future discussions regarding risk mitigation. It must be considered from both financial and operational perspectives.
Modern Drivers and Pressures for ERM
ERM provides a structured approach to align strategy, processes, people, technology, and knowledge to manage uncertainties.
Common themes in ERM include standardizing the management process, using an integrated view of risks, and relating risks to business objectives.
Key drivers for formal ERM development include:
Regulatory guidance from the .
The evolving roles of boards and audit committees, who face increased accountability post-.
Risk assessment standards ( and ) requiring auditors to understand the entity's environment.
Organizations managing risk within defined thresholds are better at predicting performance and avoiding negative consequences of unmitigated events.
The term “internal control” applies to all organizations (, , , ) and refers to all activities used to mitigate risk, regardless of category.
Recent events stimulating risk awareness include the financial crisis, fraud (e.g., the Madoff case), accounting scandals (e.g., Enron, WorldCom), and the Dodd-Frank Wall Street Reform and Consumer Protection Act of .
requires auditors of private companies to report significant deficiencies or material weaknesses in writing to management.
Perceived Barriers to Implementation
Major reported barriers include competing priorities, insufficient resources, lack of board/senior leadership support, and a lack of perceived value.
Many organizations feel the process is too complex or costly ().
In some instances, boards and management remain unaware that they are implicitly responsible for risk management.
Building the Business Case: Value and Benefits
ERM supports value creation by reducing the likelihood of outcomes that lead to value erosion.
It fosters greater accountability, responsibility, and ownership for controls.
Risks are classified as:
Upside risk: Opportunities for value enhancement.
Downside risk: Hazards that lead to value erosion, managed through policies and systems.
Integrated frameworks avoid management silos and increase transparency across business units.
Benefits of comprehensive ERM include:
Cost savings through integrated compliance: Using a common framework for internal audit and process improvement provides operational efficiency.
Risk position assessment: Formally documented assessments allow alignment of strategy with risk tolerance.
Proactive management: Decision-making shifts from crisis management to strategic planning, enhancing management response to acquisitions and product development.
Optimized capital structure: Improved estimation of capital requirements and better allocation among units.
Keys to Successful ERM Implementation
Executive support (Tone-at-the-top) is a necessity, starting from the board of directors and extending through all employee levels.
Organizations should develop a “risk intelligent culture” by educating members on major concepts and objectives before commencing the process.
Risk management should be embedded into core business processes and strategic initiative deliberations.
Risk appetite must be defined early. This ensures the board and management agree on the level of risk the organization is willing to take globally and for specific events. This is often evidenced in authority and approval limit policies.
A phased approach allows for short-term success and reduces the perception that implementation is daunting or requires immediate, total expertise.
Organizations should focus initially on a few high-priority risks or a single risk category to build the foundation for a holistic program.
A monitoring process must be developed early; an ERM program is ineffective if it is not continuously monitored after initial implementation.
Individual entity culture and circumstances must dictate the specific implementation method.
Would you like a summary of the next segment of the text?