Access and Feeds

Enterprise Risk Management: ERM Managers Learn to Think the Unthinkable

By Dick Weisinger

Enterprise Risk Management (ERM) is a management framework used by organizations for making decisions which balance risk against opportunity.  Core elements of ERM include concepts like internal control, regulatory compliance, and strategic planning.   The goal of ERM is to appropriately balance risk with opportunity to build value for stakeholders in the organization.  The stakeholders include owners, management, employees, customers, regulators, and society.

Within the ERM framework, when the risks of a given course of action are identified, the management of the organization draws up a response strategy to the perceived risks.  There are typically five courses of action which can be taken:

  • Stop or avoid the activity to eliminate the risk.
  • Decrease or limit the activity to minimize the risk.
  • Redesign alternate, less-risky, activities that accomplish the same or similar objective as the one with higher risk.
  • Insure against or move to share the risk with others.
  • Accept that the risk is necessary and take no additional action

Enterprises need to define their level of ‘risk appetite’, or the amount of risk that they are willing to take on relative to how much they value their ultimate objective.  The complexity comes into play because of the many decisions and courses of action that are being undertaken simultaneously within an organization.  Risk appetite needs to factor in the impact of potentially multiple worst case events happening in close time proximity. Different organizations, often because of the culture of the organization, will have different tolerances for risk, and risk appetites for an organization will often change over the course of time.

A recent report by the Conference Board identified the five key areas that make up the ‘preparedness’ portion of their ERM strategies.  These five areas include physical security, IT security, business continuity, crises management, and pandemic planning.  Only about half of organizations felt that IT security, business continuity and crises management were areas that were all well coordinated  with their ERM programs.  The report cautions that “companies need to reconsider the scope and operating procedures of their ERM program to ensure it is integrated with the company’s efforts to manage potentially catastrophic security risks.”

At a recent conference on ERM in San Diego, Robert Torok, executive consultant at IBM Canada, commented that “The biggest change that has taken place in the past 10 years [in ERM] is the moving away from a compliance- and insurance-based focus.  The ERM manager responsibility will not be to stop the organization from stumbling by not complying with something.  It will be to find that next big thing…  The one thing as a risk manager you can’t allow your organization to say is, ‘That can’t happen to us.’ ”  Enterprise Risk managers need to try to “think the unthinkable.”

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)
One comment on “Enterprise Risk Management: ERM Managers Learn to Think the Unthinkable
  1. Blue Turtle says:

    Great post, took a while to find it 😀
    I agree, it is always about weighing up risk vs reward and determining that is key to risk management.

Leave a Reply

Your email address will not be published. Required fields are marked *

*