Enterprise Risk Management - Integrated Framework Review
Enterprise Risk Management Definition and Core Attributes
Enterprise risk management (ERM) is defined by the Committee Of Sponsoring Organizations (COSO) of the Treadway Commission in the 2004 document Enterprise Risk Management – Integrated Framework.
ERM is a continuous process affected by an entity’s board of directors, management, and other personnel.
The process is applied in strategy setting and across the enterprise to identify potential events and manage risks within the entity's risk appetite.
ERM provides reasonable assurance regarding the achievement of objectives; absolute assurance is considered an unrealistic and impossible goal.
Every member of an organization is responsible for risk assessment and management, though specific roles must be clearly defined and documented.
The program seeks to create value, address uncertainty, and minimize both spending and negative risk effects.
COSO ERM Framework Components and Objectives
The ERM – Integrated Framework consists of eight interrelated components:
Internal environment: The basis for how risk is viewed, including philosophy and ethical values.
Objective setting: Ensuring objectives align with the mission and risk appetite.
Event identification: Distinguishing between risks and opportunities arising from internal and external events.
Risk assessment: Analyzing likelihood and impact on an inherent and residual basis.
Risk response: Selecting actions to align risk with tolerances.
Control activities: Policies and procedures to ensure effective risk responses.
Information and communication: Capturing and communicating relevant information across the entity.
Monitoring: Evaluating the entirety of the ERM and making necessary modifications.
The framework outlines objectives in four categories: Strategic, Operations, Reporting, and Compliance.
Risk Appetite and Response Categories
Risk appetite is the level of risk an organization is willing to accept in pursuit of its objectives, which can be expressed qualitatively (high, medium, low) or quantitatively (percentage of revenue).
Risk tolerance is a measurable metric that should parallel the chosen risk response.
Management selects from four primary risk response categories:
Risk avoidance: Recommending the complete avoidance of activities with high likelihood and significant financial impact.
Risk acceptance: Bearing risks where the cost to mitigate exceeds the cost of the risk, or where risks are unavoidable in business.
Risk mitigation: Seeking to reduce the likelihood or impact of an incident through control systems.
Risk transfer: Moving risk to external parties through insurance or derivative product transactions like futures and options.
Strategic Risk Categories
Management must identify risks across several key areas to develop a comprehensive profile:
External: Includes customers, suppliers, competitors, brand reputation, and disasters.
Financial: Includes credit, interest rate fluctuations, debt structure, and financial reporting accuracy.
Operational: Focuses on human resources, product development, and physical assets (property, plant, and equipment).
Strategic: Concerns governance, business models, and the appropriateness of outlined strategies.
Regulatory: Compliance with laws and agencies such as Sarbanes-Oxley, Occupational Safety and Health Administration (OSHA), Securities and Exchange Commission (SEC), and the Internal Revenue Service (IRS).
Information: Focuses on intellectual property, hardware, software, and the reliability of information technology.
The Internal Environment Foundation
The internal environment serves as the foundation for all other ERM components and is influenced by the history and culture of the entity.
Key elements include:
Risk management philosophy: The attitudes and principles reflected in management policies and communications.
Board of directors oversight: Independent members who question performance and strategy.
Integrity and ethical values: Explicitly expressed through a code of conduct and leadership actions.
Organizational structure: Establishing areas of responsibility and accountability without being overly cumbersome.
Assignment of authority and responsibility: Ensuring individuals understand their ownership of specific objectives.
Commitment to competence: Identifying and maintaining the knowledge and skills necessary for task accomplishment.