Enterprise Risk Management (ERM) is the process of identifying and managing risk that would adversely affect the enterprise if it were to come to fruition.
Another way to define enterprise risk would be any event or scenario that would impact your ability to meet the overall goals of the business.
The inverse of this principle is opportunity management, which is any event or actions that would allow your business to meet your goals or otherwise exploit a market opportunity.
Managing risk may appear to take time and focus away from running the business you have today, but it is actually investing in, protecting and positioning the business you will have in the future. Implementing a risk management process is making a deliberate decision to create enough margin of time to understand the strategic, operational and compliance risks facing your business from both inside and outside of the business. After all, there is no way to manage a risk that you do not acknowledge.
There are numerous reasons why any given risk management process would fail to deliver a strategic value or return on investment:
The enterprise risk management program does not have a clear mandate from an executive sponsor.
Lack of a clear program charter, ownership and alignment with organizational goals.
An enterprise risk management methodology has not been implemented.
Tools to identify and manage risks within the business have not been deployed.
There is not a process to accept risk that is not able to be mitigated.
An unclear Return on Investment (ROI) or said differently, an unclear return on effort.
Risk ownership is “owned” by everyone; therefore, no one practically addresses risk within the business.
The organization lacks the discipline to consistently follow an ERM methodology.
The organization reactively addresses risk (fighting fires) and does not have the margin in time or dollars to proactively identify and manage risk.
Executive leaders are unwilling to invest the time for mundane yet challenging risk discussions.
A reluctance from leaders to document accepted risks throughout the business.
After all, there is no way to manage a risk that you do not acknowledge.
As risk and opportunity exists within all business processes, two uncomfortable realities stand out.
By default, you are accepting any risk you have not identified in your business process.
Conversely, you are forgoing any opportunity you have not identified in your business process.
Another more personal reason why an organization may have a reluctance to sponsor and fully deploy resources to implement an enterprise risk management process is the fear of the ERM program failing to produce value (ROI). Perhaps more uncomfortably, leadership may fear what (or who) the ERM program may expose.
A common model for Enterprise Risk Management is a top-down bottoms-up approach, where risks are identified from both an enterprise level and a business unit or functional level. Those identified risks are cataloged and analyzed to find those risks facing the business and those embedded within the business at the business unit or functional level.
Enterprise Level Risks
Business Unit Level Risks
Functional Level Risks
One key outcome of a top-down bottoms-up risk process should be visibility to risks that are impacting multiple functional or business units throughout the enterprise. Those should be reviewed to determine if they should be considered an enterprise level risk.
Are there business functions in your organization that do not currently document the risk within their business processes?
What risks has your organization identified that have impact across multiple business functions?
What is one key risk you are effectively accepting because you have yet to identify and address it?
Would you like to discuss this topic further? Contact Brian Howell from Crestview.io
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.