Enterprise risk management
Enterprise risk management provides an organization-wide system for understanding uncertainty, making risk-informed decisions and aligning exposure with strategy, capacity and accountability.
Definition
Enterprise risk management (ERM) is the coordinated governance, identification, assessment, response, monitoring and reporting of risks across an organization in relation to its objectives and risk appetite.
Purpose
ERM should improve decisions rather than merely maintain a risk register. It connects strategic planning, capital allocation, operational control and resilience. Risks include threats and opportunities arising from markets, operations, finance, technology, regulation, people and external events.
ERM cycle
Understand
- Objectives and context
- Risk identification
- Scenario and exposure analysis
Respond
- Avoid, reduce, transfer or accept
- Controls and contingency
- Ownership and resources
Learn
- Monitoring and indicators
- Assurance and reporting
- Events and continuous improvement
Governance
| Actor | Responsibility | Key principle |
|---|---|---|
| Board | Oversight, appetite and challenge | Ultimate accountability cannot be outsourced |
| Management | Objectives, resources and risk response | Risk ownership sits with decision-makers |
| Risk function | Framework, aggregation, challenge and reporting | Authority and access are required |
| Internal audit | Independent assurance | Should not own the risks it audits |
Important distinctions
Risk appetite expresses the types and levels of risk an organization is willing to pursue or retain; risk capacity reflects what it can absorb. Compliance risk is one part of ERM, not its entirety. Crisis management responds to acute events, while ERM also addresses slow-moving and strategic uncertainty.
Related concepts
Sources and further reading
View sources and editorial notes
- ISO 31000, Risk management — Guidelines.
- COSO, Enterprise Risk Management framework.
- Institute of Internal Auditors, Three Lines Model.
Editorial note: ERM frameworks must be proportionate to the organization and linked to real decisions; framework adoption alone does not establish effective risk management.