CIO.com

enterprise risk management (ERM)

By Alexander S. Gillis

What is enterprise risk management?

Enterprise risk management (ERM) is the process of planning, organizing, directing and controlling the activities of an organization to minimize the harmful effects of risk on its capital and earnings. Enterprise risk management can include financial, strategic and operational risks as well as risks associated with accidental losses.

ERM is an organization-wide strategy enacted to identify and prepare for potential hazards. Because risk management requires the understanding and analysis of the possible risks an organization might face, the ERM process must be proportionate to the size or complexity of the organization. ERM is designed to manage and identify risks across an organization and its extended networks.

ERM is a holistic approach to managing risk, which requires a broad management-based approach. This means that instead of individual business units managing the risk, a company-wide approach is preferred.

ERM standards have been formalized through frameworks such as the Committee of Sponsoring Organizations (COSO), an industry group that maintains and updates ERM standards.

Industry or government regulatory bodies and investors can closely scrutinize enterprises' risk management policies and procedures. In an increasing number of industries, boards of directors are required to review and report on the adequacy of risk management processes in their organizations.

Why is enterprise risk management important?

An ERM program can help increase awareness of business risks across an entire organization, instill confidence in strategic objectives, improve compliance with regulatory and internal mandates, and enhance operational efficiency through more consistent applications of processes and controls.

Enterprises can benefit by shifting their corporate culture from a focus on meeting IT compliance obligations to targeting overall risk reduction, which relies heavily on visibility into the overall security of the organization.

Organizations building a strategic ERM program must have some well-established practices already in place:

ERM is a continuous work in progress that needs to grow and evolve, so organizations must be willing to regularly revisit, revise and update all elements of the program.

How is ERM different from traditional risk management?

With traditional risk management processes, individual division heads typically make risk-based decisions. Each functional leader oversees risk management within their own silo. These roles, for example, can fall under the chief technology officer for managing IT-based risks, the treasurer for financial risks, and the chief operating officer for production and distribution risks.

Enterprise risk management, however, requires a more holistic de-siloed approach. Instead of managing risk in a siloed manner, organization must adopt a firm-wide approach to create a portfolio of the most significant risks to an organization or objective. This process generates a top-down enterprise view of all significant risks that can impact an organization.

In larger or more complex organizations, a traditional risk management approach might have risks that do the following:

What are the components of enterprise risk management?

The following components make up ERM:

What are the benefits of enterprise risk management?

ERM provides organizations with a host of potential benefits:

What are the challenges of enterprise risk management?

There are also potential downsides to ERM, including the following:

Who should manage ERM in an organization?

The board of directors and executive management are both in charge of determining what ERM process should be in place as well as how ERM across the organization should function. More specifically, an organization's top management is responsible for designing and implementing the ERM process, while the board of directors is responsible for providing oversight. This oversight includes the understanding and approval of ERM processes and overseeing identified risks to ensure responses are within the stakeholders' risk appetite.

A chief risk officer (CRO) role is also applicable to manage ERM. The CRO is in charge of identifying, analyzing and mitigating risks that impact the organization as a whole. The CRO also ensures that an organization complies with any government regulations. More granular roles in the process fall on other C-level positions and staff.

ERM implementation best practices

Some best practices to follow when implementing ERM include the following:

ERM frameworks

Enterprise risk management frameworks come in many formats. For some companies, adherence to ERM might be mandated by compliance and regulatory requirements. For other businesses, these frameworks might be useful in shaping and defining ERM in its early stages of development and implementation. Some of the more common frameworks include the following:

ERM tools and software considerations

When evaluating an ERM tool, organizations should consider a product that provides the following features and attributes:

Here are several examples of available ERM tools:

Archer

Recently acquired by private equity firm Cinven, the Archer integrated risk management suite provides tools for enterprise, operational, IT, security and third-party risk management. It's also used for regulatory compliance; management of environmental, social and governance programs; and other risk-related functions.

This platform includes Archer Engage and Archer Insight. Archer Engage is a risk reporting and data collection application that provides a unified user experience for business users and risk management teams. Archer Insight is a risk quantification tool.

AuditBoard

AuditBoard's initial core focus was on streamlining audit and compliance processes for companies required to meet complex regulations. Since then, however, the company has gradually expanded its cloud-based platform into other aspects of risk management.

In July 2023, the company released AuditBoard ITRM for IT risk management, with a focus on IT security risks and support for collaboration between security teams, risk managers and business users.

IBM

IBM OpenPages is an AI-enabled governance, risk and compliance (GRC) platform that supports risk management, regulatory compliance and data governance programs.

IBM acquired OpenPages in 2010 to expand its business analytics offerings into compliance and risk management processes. In 2020, the software was integrated into IBM Cloud Pak for Data, a set of cloud-based tools for organizing, managing and analyzing data.

OpenPages is designed to help organizations centralize siloed risk management initiatives. It includes GRC and ERM tools for managing risks that might appear in IT governance, data privacy and financial controls.

Learn more about the granular roles involved in ERM, such as those in C-level roles.

05 Oct 2023

All Rights Reserved, Copyright 2007 - 2024, TechTarget | Read our Privacy Statement