What is Enterprise Risk Management?

Enterprise Risk Management is a structured approach to identifying, assessing and managing risk across an organisation. This guide explains what ERM is, how it differs from traditional risk management and why it has become a fundamental part of effective governance. You'll also learn the core principles that underpin a successful ERM programme.
5 min read time

Enterprise risk management gets discussed in boardrooms, referenced in regulatory guidance, and cited in governance frameworks across virtually every sector. Despite that prominence, it means different things to different organisations, and the gap between what ERM is described as and what it actually delivers in practice can be significant.

Whether you are a Chief Risk Officer building a programme from scratch, a board member trying to understand what you should be overseeing, or a risk manager explaining to the business why the framework matters, a clear understanding of what ERM actually involves is the foundation of everything else.

This article covers the core definition, how ERM differs from traditional approaches to risk management, the main frameworks in use, what a mature programme looks like in practice, and the most common reasons implementations fall short.

The Core Definition

At its heart, enterprise risk management is a structured, organisation-wide approach to identifying, assessing, managing, and monitoring risks that could affect an organisation's ability to achieve its objectives. What makes it "enterprise" risk management, rather than simply risk management, is scope and integration. ERM takes a joined-up view across the whole organisation, rather than allowing each department to manage its own risks in isolation with no shared language, no common methodology, and no consolidated picture available to leadership.

The most widely referenced formal definition comes from the Committee of Sponsoring Organisations of the Treadway Commission (COSO), which describes ERM as a process, effected by the entity's board of directors, management, and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within the risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.

ISO 31000 takes a complementary but broader view, defining risk as the effect of uncertainty on objectives. That definition is worth pausing on. Risk is not only bad things that might happen. It is uncertainty in relation to what the organisation is trying to achieve, encompassing both threats that could prevent success and opportunities that could accelerate it. ERM is how an organisation develops a structured relationship with that uncertainty rather than being surprised by it.

How ERM Differs From Traditional Risk Management

The Fragmentation Problem

Traditional risk management tends to be reactive and fragmented. A finance team manages financial risk. An IT department handles cyber threats. Operations manages supply chain disruption. Each area does its job, but nobody is looking at how these risks interact, whether a single event could cascade across multiple functions simultaneously, or whether the organisation's overall risk exposure is within a level the board has actually endorsed.

The consequences of this fragmentation are predictable. Risks that span multiple functions get addressed partially by each and comprehensively by none. The board receives risk information by function rather than a coherent enterprise view. Resources are allocated to managing risks by departmental priority rather than by strategic significance. And the connections between risks, where the failure of one control creates exposure across multiple risk categories simultaneously, are invisible.

What ERM Changes

ERM changes the unit of analysis from departmental risk to enterprise risk exposure. By aggregating risks across functions and aligning them explicitly to strategic goals, a well-implemented ERM programme allows leadership to understand the organisation's overall risk profile at any point, prioritise resources based on what poses the greatest actual threat to objectives, identify interdependencies between risks that would be invisible in a siloed approach, and make better-informed decisions about strategy, investment, and operations.

For risk managers and CROs, ERM provides the framework that elevates risk from a compliance exercise to a strategic function. For the board, it provides the consolidated view needed to exercise genuine governance rather than rely on disconnected functional reporting.

The Key Components of a Mature ERM Programme

Risk Governance and the Three Lines Model

The governance structure underpinning ERM determines whether accountability for risk is genuine or nominal. The IIA's Three Lines Model provides the standard framework. The first line, operational management, owns and manages risk day to day. The second line, the risk and compliance function, sets the framework, provides oversight, and consolidates the risk picture. The third line, internal audit, provides independent assurance that the first two lines are functioning as intended.

This structure only works when accountability is genuine at each level. First-line managers who treat risk management as something the risk function does on their behalf; risk functions that complete assessments for business units rather than challenging them; and internal audit teams that report only to management rather than to the board, are all signs of a governance structure that is in place on paper but not in practice.

At board level, the FCA's systems and controls requirements for regulated firms, and equivalent expectations from other regulators, are explicit that the board bears ultimate responsibility for the organisation's risk management approach, including setting and approving risk appetite.

Risk Appetite

Risk appetite is the amount and type of risk the organisation is willing to accept in pursuit of its objectives. It is the cornerstone of any ERM framework, and one of the most misunderstood and most poorly expressed concepts in practice.

Effective risk appetite has two characteristics that many appetite statements lack. First, it is specific enough to guide actual decisions. A statement that says "we have a low appetite for reputational risk" provides no practical guidance for a manager deciding whether to proceed with a partnership. A statement that says "we will not enter commercial relationships with parties that have been subject to regulatory sanction in the past three years" is actionable.

Second, it is actively monitored and enforced. An appetite statement that is approved by the board, filed with the framework documentation, and never referenced again has no governance value. Appetite only functions as a governance mechanism when it is regularly compared against actual risk positions, with clear processes for escalating and responding to breaches.

Risk Identification and Assessment

Risk identification should be continuous rather than annual. Risks change as processes evolve, strategies shift, and the external environment changes. An identification process that only operates on an annual assessment cycle produces a risk register that is accurate on the day it is completed and progressively less so for the next eleven months.

Assessment evaluates each identified risk on likelihood and impact, typically producing a rating that allows risks to be prioritised and compared. The distinction between inherent risk, before any controls are applied, and residual risk, after controls are considered, is fundamental. The gap between the two represents what the control environment is claiming to achieve, and that claim needs to be evidenced rather than assumed.

Controls and Monitoring

The risk register identifies what could go wrong. The control framework specifies what is being done about it. The connection between the two should be explicit: each significant risk should have clearly mapped controls, with assessed effectiveness, not simply a list of mitigating activities.

Key risk indicators provide real-time monitoring between formal assessment cycles. A well-designed KRI moves before the risk event occurs, providing the early warning that allows intervention before a risk materialises. The Chartered Institute of Internal Auditors identifies continuous monitoring through KRIs as a distinguishing feature of mature risk management programmes.

Reporting to the Board

Risk reporting that tells the board what it wants to hear rather than what it needs to know is one of the most persistent and most damaging features of weak ERM programmes. The board requires a current, accurate view of the organisation's most significant risks, explicit comparison against appetite, clear identification of where management action is required, and enough contextual information to ask substantive questions.

The Main Frameworks

COSO ERM Framework

The COSO ERM Framework, updated significantly in 2017, is the most widely referenced ERM framework globally. Its 2017 revision placed considerably greater emphasis on the integration of ERM with strategy and performance, moving away from a purely compliance-oriented framing toward one that positions risk management as central to strategic decision-making.

COSO organises its framework around five interrelated components: governance and culture, which establishes the tone and operating structures; strategy and objective-setting, which integrates ERM into strategic planning; performance, which covers risk identification, assessment, and prioritisation; review and revision, which covers how the organisation monitors and updates the ERM programme; and information, communication, and reporting, which covers how risk information flows through the organisation.

ISO 31000

ISO 31000 provides principles and guidelines for risk management applicable to any organisation regardless of size, sector, or geography. Unlike COSO, ISO 31000 is not certifiable and is considerably less prescriptive. It sets out eight principles of effective risk management, a framework for integrating risk management into organisational governance and operations, and a process for identifying, analysing, evaluating, and treating risk.

Many organisations use ISO 31000 as the philosophical foundation for their approach and draw on COSO for more detailed structural guidance. The two are complementary rather than competing.

Who Needs ERM?

Any organisation that has objectives and faces uncertainty in achieving them would benefit from ERM, but the practical urgency varies considerably. In financial services, the FCA, the Prudential Regulation Authority, and the Central Bank of Ireland each expect regulated firms to demonstrate structured, documented risk governance appropriate to the nature and scale of their business. For credit unions, insurers, and payment institutions in particular, the regulatory expectation of mature ERM has become more explicit in recent years.

Healthcare, public sector, infrastructure, professional services, and not-for-profit organisations all face growing expectations around governance quality, and ERM is increasingly the standard against which governance is measured. The question is not whether ERM is relevant but how a proportionate, credible programme can be built and maintained given the organisation's specific resources and risk profile.

What Good Looks Like

A well-functioning ERM programme is identifiable by a consistent set of characteristics. Risk information visibly influences real decisions, rather than sitting in a register nobody consults between formal review cycles. The board receives reporting that is current, specific, and actionable. Risk owners engage with their responsibilities throughout the year, not just at annual assessment time. When something goes wrong, the organisation understands why and can demonstrate what has changed as a result. And the risk appetite framework is actively used to guide decisions, not filed with the governance documentation and never referenced again.

The common failure modes are equally consistent across organisations and sectors: governance that is clearly defined on paper but weak in practice; risk registers completed annually and ignored the rest of the time; reporting that describes the risk landscape without identifying what requires action; and cultural resistance to surfacing bad news that causes the risk picture to be optimistic relative to reality.

References and Further Reading

Next Steps

Ready to elevate your enterprise risk management?

Join 150+ organisations who’ve already made calQrisk their competitive edge.