Skip to main content
  • Home
  • Enterprise risk management
The Economy Wiki

Enterprise risk management

Enterprise risk management provides an organization-wide system for understanding uncertainty, making risk-informed decisions and aligning exposure with strategy, capacity and accountability.

Entry type: Knowledge article

Field: Risk, Compliance and Governance

Last reviewed: 24 August 2026

Definition

Enterprise risk management (ERM) is the coordinated governance, identification, assessment, response, monitoring and reporting of risks across an organization in relation to its objectives and risk appetite.

Purpose

ERM should improve decisions rather than merely maintain a risk register. It connects strategic planning, capital allocation, operational control and resilience. Risks include threats and opportunities arising from markets, operations, finance, technology, regulation, people and external events.

ERM cycle

Understand

  • Objectives and context
  • Risk identification
  • Scenario and exposure analysis

Respond

  • Avoid, reduce, transfer or accept
  • Controls and contingency
  • Ownership and resources

Learn

  • Monitoring and indicators
  • Assurance and reporting
  • Events and continuous improvement

Governance

ActorResponsibilityKey principle
BoardOversight, appetite and challengeUltimate accountability cannot be outsourced
ManagementObjectives, resources and risk responseRisk ownership sits with decision-makers
Risk functionFramework, aggregation, challenge and reportingAuthority and access are required
Internal auditIndependent assuranceShould not own the risks it audits

Important distinctions

Risk appetite expresses the types and levels of risk an organization is willing to pursue or retain; risk capacity reflects what it can absorb. Compliance risk is one part of ERM, not its entirety. Crisis management responds to acute events, while ERM also addresses slow-moving and strategic uncertainty.

Sources and further reading

View sources and editorial notes
  • ISO 31000, Risk management — Guidelines.
  • COSO, Enterprise Risk Management framework.
  • Institute of Internal Auditors, Three Lines Model.

Editorial note: ERM frameworks must be proportionate to the organization and linked to real decisions; framework adoption alone does not establish effective risk management.