Enterprise Risk Management: Managing Risk Across the Whole Organization
While risk management involves managing risk on an individual basis, enterprise risk management encompasses the entire process of managing organizational risk by treating the discipline of risk management as a whole in relation to the entire organization rather than having separate departments handle their respective risks. Let me now explain what ERM is all about.
Why ERM Emerged as Its Own Discipline
The old-style risk management model usually existed in silos where finance dealt with financial risk, information technology handled technology risk, while operations managed operational risk, all using different methodologies and differing views of seriousness, without much coordination between them. This was very challenging for leadership to know the aggregate risks of the business organization and see how risks from one area could add up to those from other areas. ERM is there just to solve such an issue.
Core Principles of ERM
Holistic View of Risk
As opposed to analyzing each risk separately, ERM takes into account the interplay between the different types of risk and how they can exacerbate one another; for example, a disruption of the supply chain (operational risk) may cause financial risk (not meeting revenue goals) and reputational risk (dissatisfied customers) at once.

Alignment with Strategy
ERM makes risk management directly related to the business strategy and objectives, where risk is analyzed based on its influence on reaching certain business objectives and not just as something defensive.
Risk Appetite and Tolerance
The typical ERM program sets the risk appetite and risk tolerance of the organization (how much risk it is prepared to take in order to reach certain business objectives and what is the permissible deviation from risk measurements).
Continuous, Integrated Process
Instead of periodic, fragmented risk assessment, ERM seeks the implementation of continual risk monitoring as an integral part of the ongoing operational and decision-making process, rather than as a stand-alone annual activity that is separate from the rest of the management.
The COSO ERM Framework
The framework developed by the Committee of Sponsoring Organizations of the Treadway Commission for enterprise risk management (COSO ERM) is one of the most popular reference frameworks for enterprise risk management. It divides the enterprise risk management field into categories such as governance and culture, strategic objectives, performance (risk identification and evaluation within the context of strategy implementation), review and revision, information and communication.

Key Components of an ERM Program
Risk Governance Structure
Organizational clarity of risk-management roles and accountability, which would usually include a Chief Risk Officer, a risk committee, and reporting lines to the board that maintains the overall accountability for the enterprise risk.

Enterprise-Wide Risk Identification
Consistent approach to risk identification within the whole organization, employing a common risk taxonomy that will allow the company to compare and aggregate risks properly.
Risk Assessment and Prioritization
Consistent evaluation of the identified risks, usually based on likelihood and impact assessments, determining which risks need to be managed actively by the company.
Integrated Risk Response
Risk response coordination in different business units, making sure that there is no case when risk-mitigation efforts in one unit increase the risk in another unit.
Board and Executive Reporting
To provide leadership and the board with an aggregate view of the risk exposure of the enterprise, allowing for decision making on the basis of full risk awareness.
How ERM Differs from Traditional Risk Management
Conventional risk management usually concentrates on certain individual risk categories that are dealt with independently. However, ERM brings all of these into a unified system, incorporates risk assessment into the strategy making process and relies more on formalized governance arrangements, which are not always typical for departmental risk management practices.
Who’s Responsible for ERM
Usually, large organizations develop their ERM programs via appointment of a Chief Risk Officer and a specialized team of risk managers with involvement of a cross-departmental risk committee. The board of directors remains responsible for the final oversight of the process despite the fact that it is executed by professional staff.
Common Challenges in Implementing ERM
Data and Reporting Silos
Business units may adopt varying risk terminologies, rating techniques, and systems before the development of the ERM framework, thus necessitating a lot of reconciliation efforts for true aggregation to happen.
Cultural Resistance
An ERM initiative can be considered nothing but a bureaucratic effort without value when it does not receive full support from senior executives in adopting risk-based decisions.
Balancing Rigor with Practicality
Inadequate ERM processes might result to cumbersome processes where business units may be reluctant to participate in the process, whereas simple ERM processes might miss out the risk insights needed by the business.
Bottom Line
Enterprise Risk Management integrates risk identification, assessment, and mitigation within an organization as a whole by using a single framework for risk management rather than having various risk management systems. The success of Enterprise Risk Management depends as much on its actual implementation within an organization’s culture as on the particular framework used.