How an effective approach to enterprise risk management can improve risk and business outcomes
The concept of Enterprise Risk Management (ERM) within organisations continues to be a work in progress. Each year more and more organisations are embedding of a variety of tools and risk management techniques, however progress is somewhat adhoc. The value of progress towards a more comprehensive approach to ERM is quite clear. Organisations derive benefits in losses avoided, improved project governance (time and cost savings), improved business practices and regulatory compliance.
ERM offers a framework for effectively managing and assessing risks and uncertainty, both today and in the future. ERM is - at its core - a process of gaining a deep understanding of the risk DNA of an organisation. It does this by conducting an informed assessment of both individual risk categories, aggregated groups of common risks and the overall risk profile of a business unit or organisation.
ERM has in many ways been the convergence of a number of risk streams from disparate industries: insurance risk management from the insurance sector, financial risk management from the banking and finance sector, project risk management from construction and civil engineering and information technology risk management from the IT sector. In parallel, the risk management profession itself has developed – with many organisations having a dedicated risk management department and often a Chief Risk Officer.
The risks that organisations face are numerous. In larger organisations, organisational complexity brings with it a multitude of risks. The task of identifying and assessing risks alone is challenging, let alone thinking about how to mitigate a myriad of risks that are identified. For those organisations that have a dedicated risk management function, it is important is to leverage off the skills to strengthen the risk management practices.
See Also: Top Enterprise Risk Management Vendors
For organisations commencing implementation of a holistic approach to ERM, the following key steps should be undertaken:
Develop a Risk Framework – A risk framework consists of a set of policies, processes, and systems to effectively develop fit-for-purpose ERM frameworks. There are numerous frameworks, templates and ‘how to guides’ available. This is the first step and possibly the easiest. As risk management matures in an organisation, the risk framework will also evolve.
Establish Ownership of Risks – Understand where the ownership of both individual risks and risk categories lie. Wherever possible, have the ownership as close as possible to the business activity or function. Ensure that the risk owners have a full understanding of the risks and are skilled and resourced to manage these risks.
Establish a Risk Rhythm - Develop an organisational-wide risk culture and rhythm. Strive to have risk identification, assessment, mitigation and reporting embedded as a core capability. Encourage the discussion of risk in all management forums, investment and project decision making, and business reviews.
Address Key Risks – Once the risk assessment exercise has been completed and specific risks identified, the final step is to develop and implement plans to address the key risks. Again, ensure that risk owners have a full understanding of the risks and are resourced to manage these. It is important to bring to life risk mitigation initiatives, rather than have the risks remain in a report not mitigated.
The above steps will start an organisation on the ERM journey and lead to improved business outcomes.
Check out: Top Risk Management Services Companies
By Leni Kaufman, VP & CIO, Newport News Shipbuilding
By George Evans, CIO, Singing River Health System
By John Kamin, EVP and CIO, Old National Bancorp
By Elliot Garbus, VP-IoT Solutions Group & GM-Automotive...
By Gregory Morrison, SVP & CIO, Cox Enterprises
By Alberto Ruocco, CIO, American Electric Power
By Sam Lamonica, CIO & VP Information Systems, Rosendin...
By Sergey Cherkasov, CIO, PhosAgro
By Pascal Becotte, MD-Global Supply Chain Practice for the...
By Stephen Caulfield, Executive Director, Global Field...
By Shamim Mohammad, SVP & CIO, CarMax
By Ronald Seymore, Managing Director, Enterprise Performance...
By Brad Bodell, SVP and CIO, CNO Financial Group, Inc.
By Jim Whitehurst, CEO, Red Hat
By Clark Golestani, EVP and CIO, Merck
By Scott Craig, Vice President of Product Marketing, Lexmark...
By Dave Kipe, SVP, Global Operations, Scholastic Inc.
By Meerah Rajavel, CIO, Forcepoint
By Amit Bahree, Executive, Global Technology and Innovation,...
By Greg Tacchetti, CIO, State Auto Insurance