
To manage risk proactively and successfully in your organization, you probably already take an enterprise risk management (ERM) approach. But if you fail to dedicate sufficient time and attention to all the components of ERM, you’re in danger of neglecting some of the key challenges you should be tackling. Here, we examine the 9 components of enterprise risk management and how you should approach them.
The COSO 2013 Framework defines ERM as:
“The culture, capabilities, and practices, integrated with strategy-setting and its performance, that organizations rely on to manage risk in creating, preserving, and realizing value.”
Investopedia defines it as “a methodology that looks at risk management strategically from the perspective of the entire firm or organization.”
Enterprise risk management differs from traditional risk management in its scope (encompassing the entire organization, rather than one process or team), its approach (forward-looking rather than reflective) and its ability to adapt to a changing landscape; the former is typically more agile and fluid, incorporating ERM tools and technology to keep up with the evolving risk landscape. On the other hand, the later – traditional risk management – is more static.
An enterprise risk management framework focuses on three core areas of risk; operations risk, financial risk and strategic risk. Here we look at each of these components of corporate risk management in more detail:
The international capital framework generated by the Basel II Accords defines operations risk as “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events,” including legal liabilities.
Examples of operations risk might include the potential damage caused by employee turnover, management oversight or poor IT design. Managing operational risks requires identification of risks in all operations through surveys, workshops and a framework of risk assessment. Once this is in place, a robust and organization-wide corporate governance structure must be put in place to manage operational risks.
ERM became obligatory after the legendary financial scandals perpetrated by leaders of companies like Enron and WorldCom. In response to these, the US Congress introduced the Sarbanes-Oxley Act of 2002, part of which required internal control systems as at publicly traded companies.
Financial risks emerge from the effects of markets on an entity’s assets and include risks to credit, price and liquidity. Since these risks, unlike operations risk, can, to a certain extent, be projected and planned for, they’re considered a speculative risk. It’s usually the job of the CFO and their department to be on top of them.
Looking at strategic risk requires you to step back from the granular detail of your business’ operations and finances to its future growth and development. It could be put this way: while ERM strategies in operations and finances will help you do things right, strategic risk management is more focused on getting your entity to do the right things. Strategic risks are those that threaten the “big picture” of your operations and future plans.
The company that has the best budgeting and the most efficient operations will go bust if no one wants its products. Turnover and redundancy of products are a natural part of the business cycle; strategic risks that enterprise risk management can help you to handle.
What are the major components of enterprise risk management? As with any management framework, there are many different ERM framework components, with different bodies and experts including different ERM components within their definitions.
One of the best-known ERM frameworks was introduced by the Committee of Sponsoring Organisations of the Treadway Commission (COSO) in 1992.
Although the inclusion of guidelines from the Sarbanes-Oxley Act (SOX) aligns the COSO framework with financial institutions and other large corporations in scope of SOX regulation, the transferability of the COSO ERM framework components means it is used across a range of sectors worldwide.
And although COSO guidance is non-mandatory, its ability to deliver a framework companies can use to assess and improve their controls and processes means it has been highly influential.
Enterprise risk management strategies have many benefits; it’s no surprise that more and more organizations are understanding and embracing ERM. But to achieve these benefits, your ERM framework has to be implemented and monitored at the highest levels of your entity. These practices are not only legally required, but can be your main line of defense against financial and reputational damage.
Understanding the various ERM framework components is a vital step towards delivering the risk mitigation strategy you need.
Diligent’s comprehensive enterprise risk management software accelerates your ERM performance, enabling you to identify, monitor and manage risks across your entire organization. Compliance and reporting are made easy, increasing board and stakeholder confidence in your ability to strategically tackle risk. Find out more about Diligent Enterprise Risk Management.