
Enterprise risk management, or ERM, is an organization-wide approach for understanding how different risks interact with strategy, performance, and business objectives. Instead of managing financial, operational, technology, compliance, and strategic risks in separate silos, ERM combines them into a portfolio view so leadership can decide which risks to accept, reduce, transfer, avoid, or deliberately take.
The central idea is simple: an organization rarely fails because one isolated risk exists. Serious problems often emerge when several exposures interact at the same time.
A supplier disruption can reduce production, weaken cash flow, delay customer deliveries, increase financing needs, and damage strategic plans. Enterprise risk management is designed to make those connections visible before management decisions are made.
What Is Enterprise Risk Management?
Enterprise risk management is a structured system for identifying, assessing, prioritizing, responding to, and monitoring risks across an entire organization.
Traditional risk management may focus on an individual department, project, or exposure. ERM takes a broader view.
COSO describes enterprise risk management as an integrated combination of culture, capabilities, and practices used with strategy-setting and performance to manage risk while creating, preserving, and realizing value. COSO’s current ERM framework emphasizes that risk should be considered during strategy development rather than added after major decisions have already been made. COSO
This distinction changes the role of risk management.
ERM is not merely:
- an annual risk register;
- an insurance exercise;
- a compliance checklist;
- an internal audit activity;
- a list of everything that could go wrong.
An effective ERM process influences decisions about capital, expansion, suppliers, technology, acquisitions, financing, staffing, regulation, and long-term strategy.
Risk Management vs Enterprise Risk Management
The terms are related but not identical.
| Risk Management | Enterprise Risk Management |
|---|---|
| May focus on one risk or department | Covers the organization as a whole |
| Often manages risks independently | Examines interactions among risks |
| Can be operational or project-specific | Connects risk with strategy and objectives |
| May use separate risk registers | Builds an enterprise-level risk profile |
| Often focuses on reducing threats | Considers both threats and opportunities |
| Responsibility may sit within one function | Requires involvement across leadership and business units |
A procurement manager might manage supplier risk effectively without running an ERM program.
ERM asks a larger question:
How could supplier risk combine with liquidity, customer concentration, technology dependencies, market conditions, and strategic priorities to affect the organization as a whole?
For readers who need the underlying process first, our guide to [risk management](/risk-management/) explains identification, assessment, treatment, monitoring, and residual risk in more detail.
Why Enterprise Risk Management Matters
Organizations increasingly operate through interconnected systems.
A single company may depend on:
- cloud providers;
- banking relationships;
- logistics companies;
- suppliers in several countries;
- digital payment infrastructure;
- contractors;
- regulatory approvals;
- customer data;
- external software;
- capital markets.
These dependencies mean that risks do not remain neatly inside departments.
NIST’s updated 2025 guidance on integrating cybersecurity with enterprise risk management illustrates this clearly. NIST recommends rolling risk information from operational and system-level registers into broader enterprise risk profiles so leadership can evaluate technology risks alongside other mission and business objectives.
The principle extends beyond cybersecurity.
A business may technically manage each individual risk well while still missing the combined exposure created by several risks occurring together.
ERM Helps Management See Concentration
Suppose a company has:
- one major supplier;
- one primary lender;
- one important cloud provider;
- one customer representing 35% of revenue.
Each dependency may appear manageable independently.
Together, they reveal something more important: the company has significant concentration risk.
Enterprise risk management makes this portfolio-level exposure easier to identify.
The Enterprise Risk Management Process
There is no single mandatory ERM process for every business. Organizations differ in size, industry, ownership structure, geography, and regulatory environment.
However, most useful ERM systems contain several common stages.
1. Define Strategy and Business Objectives
Enterprise risk management should begin with objectives rather than with a blank risk register.
Management first needs to clarify:
- What are we trying to achieve?
- Over what period?
- What resources are required?
- What assumptions does the strategy depend on?
- What level of uncertainty are we willing to accept?
This is why ERM and strategic planning are closely connected.
Risk has meaning only relative to an objective.
For example, currency volatility may be irrelevant to a domestic service business but highly significant to a manufacturer buying materials internationally.
2. Establish Risk Appetite and Risk Tolerance
Risk appetite describes the broad amount and type of risk an organization is willing to accept while pursuing its objectives.
Risk tolerance is usually more specific. It describes acceptable variation or limits around a particular objective or exposure.
Consider a company expanding into a new region.
Its risk appetite might state:
The company accepts moderate commercial uncertainty when entering new markets but has low tolerance for regulatory non-compliance or liquidity stress.
That principle can then be converted into measurable tolerances.
For example:
| Risk | Illustrative Tolerance |
|---|---|
| Customer concentration | No customer above 25% of annual revenue |
| Liquidity | Minimum six months of forecast operating cash needs |
| Supplier dependence | At least two qualified sources for critical inputs |
| Cybersecurity | No critical vulnerabilities unresolved beyond defined deadline |
| Project cost | Maximum 10% budget variance without executive review |
The exact figures depend on the organization. The value comes from defining boundaries before a crisis forces management to improvise.
3. Identify Risks Across the Enterprise
Individual business units usually see risks that senior leadership cannot detect from consolidated financial information alone.
ERM therefore requires risk identification from multiple levels.
Sources may include:
- management interviews;
- financial data;
- operational incidents;
- audit findings;
- supplier reviews;
- customer concentration analysis;
- regulatory developments;
- scenario workshops;
- technology assessments;
- strategic assumptions;
- market trends.
Risks should be described in terms of causes and consequences.
Weak statement:
Supply-chain risk
Better statement:
Dependence on a single overseas component supplier could interrupt production for more than six weeks if transport or manufacturing is disrupted.
The second version can actually be assessed and managed.
4. Assess Likelihood, Impact and Interdependence
A basic assessment considers:
Likelihood × Impact
ERM should go further.
Management should also consider:
- velocity — how quickly the risk could affect the business;
- persistence — how long consequences may continue;
- recoverability — how easily operations can be restored;
- concentration — whether exposure depends on one counterparty or system;
- correlation — whether several risks could occur together.
This is where enterprise risk management differs from a simple departmental risk matrix.
Two risks with medium scores may become a high enterprise exposure if one can trigger the other.
5. Build an Enterprise Risk Register
An enterprise risk register consolidates material risks in a consistent format.
A useful register might contain:
| Field | Purpose |
|---|---|
| Risk statement | Defines the exposure |
| Related objective | Shows what could be affected |
| Risk category | Groups related exposures |
| Likelihood | Estimates probability |
| Impact | Estimates potential consequence |
| Risk owner | Assigns responsibility |
| Existing controls | Shows current protections |
| Response | Defines planned action |
| Residual risk | Estimates exposure after controls |
| KRI | Provides monitoring signal |
| Review date | Sets reassessment timing |
NIST’s ERM guidance uses risk registers as an important mechanism for rolling information from individual organizational levels into enterprise-level risk profiles.
But the register itself is not ERM.
A spreadsheet becomes useful only when it changes decisions.
6. Prioritize Risks as a Portfolio
Prioritization should not mean sorting a spreadsheet by risk score and stopping there.
Leadership needs to ask:
- Which risks threaten multiple objectives?
- Which exposures could create liquidity problems?
- Which risks are highly concentrated?
- Which ones could trigger other risks?
- Which exposures are increasing?
- Where are controls weakest?
- Which risks are necessary to pursue strategic opportunities?
This creates an enterprise risk profile rather than a collection of unrelated risk lists.
7. Choose Risk Responses
Management can generally:
- avoid;
- reduce;
- transfer;
- accept;
- pursue or exploit a risk.
The response should reflect risk appetite, expected benefit, cost, and strategic importance.
A business may accept volatility in sales when entering a promising market while refusing exposure to legal violations.
Both decisions can be rational because different risks have different strategic value.
8. Monitor, Report and Review
ERM is continuous.
Management should monitor:
- key risk indicators;
- changes in probability;
- changes in potential impact;
- control effectiveness;
- strategic assumptions;
- emerging risks;
- incidents and near misses;
- residual risk.
The COSO ERM framework explicitly includes Review & Revision and Information, Communication & Reporting among its five major components.
That is important because a risk assessment becomes stale quickly if conditions change.
The COSO Enterprise Risk Management Framework
The COSO ERM framework is one of the best-known approaches to enterprise risk management.
The 2017 framework, Enterprise Risk Management — Integrating with Strategy and Performance, replaced COSO’s earlier 2004 ERM framework.
COSO reorganized ERM around five interrelated components:
- Governance & Culture
- Strategy & Objective-Setting
- Performance
- Review & Revision
- Information, Communication & Reporting
The framework contains 20 principles across those five components. COSO’s later guidance continues to use these components and principles when applying ERM to areas such as cybersecurity and cloud computing.
Governance & Culture
Governance establishes oversight, responsibilities, authority, and accountability.
Culture influences how people perceive risk and how they respond when objectives conflict with controls or incentives.
A written framework cannot compensate for leadership that rewards excessive risk-taking while formally claiming to be conservative.
Strategy & Objective-Setting
Risk appetite and strategy should be evaluated together.
Management needs to understand what assumptions a strategy depends on and what uncertainty could cause those assumptions to fail.
Performance
Organizations identify, assess, prioritize, and respond to risks that could affect performance.
This component connects risk information to actual execution.
Review & Revision
Organizations review whether:
- risks changed;
- controls remain effective;
- strategy still fits the environment;
- previous assumptions remain valid.
Information, Communication & Reporting
Risk information must reach the people who can act on it.
A sophisticated risk model has little value if management receives the information too late.
COSO ERM vs ISO 31000
COSO is not the only enterprise risk management framework.
ISO 31000 provides broadly applicable principles and guidelines for managing risk across organizations and industries. ISO states that ISO 31000:2018 can be customized to an organization’s context and applied to decision-making at all levels. The 2018 edition remains current as of 2026, while a third edition is under development.
The two approaches overlap but emphasize different things.
| COSO ERM | ISO 31000 |
|---|---|
| Strong emphasis on strategy and performance | Broad principles for risk management |
| Five components and 20 principles | Principles, framework and process |
| Common in corporate governance contexts | Designed for organizations of any type |
| Strong connection to governance | Highly adaptable across industries |
| Explicit focus on creating and preserving value | Focus on integrating risk into organizational activities |
Neither framework automatically creates good risk management.
The value comes from applying the principles to real decisions.
Enterprise Risk Management Example
Consider a mid-sized manufacturer planning to open a second production facility.
A traditional approach might create separate risk assessments:
- Finance evaluates borrowing costs.
- Operations evaluates equipment.
- Procurement evaluates suppliers.
- IT evaluates systems.
- Legal evaluates regulation.
ERM combines the exposures.
Strategic Objective
Increase production capacity by 35% within three years.
Enterprise Risks
Financing risk: Interest rates may increase debt-servicing costs.
Demand risk: Forecast customer demand may not materialize.
Supplier risk: The new plant depends on specialized imported equipment.
Project risk: Construction may exceed budget.
Technology risk: The facility requires integration with existing systems.
Workforce risk: Qualified staff may be difficult to recruit locally.
Management can now examine relationships.
If construction runs 20% over budget and borrowing costs rise and customer demand is delayed, liquidity could become the main enterprise risk even though no individual department originally classified its own risk as critical.
That is the value of the enterprise view.
Enterprise Risk Profile vs Risk Register
These terms are often confused.
Risk Register
A risk register records individual risks and their characteristics.
Enterprise Risk Profile
An enterprise risk profile summarizes the organization’s most significant exposures and how they interact with objectives, risk appetite, and each other.
The profile should help senior management and the board understand:
- top enterprise risks;
- changes since the previous review;
- concentration;
- interconnected risks;
- exposures outside tolerance;
- emerging risks;
- major response actions.
A 300-row register may be useful operationally.
A board rarely needs to review all 300 rows.
ERM should convert detailed information into decision-relevant enterprise insight.
What Are Key Risk Indicators?
Key risk indicators, or KRIs, are measurements used to detect changes in exposure.
Examples include:
- percentage of revenue from the largest customer;
- days of available liquidity;
- supplier delivery delays;
- employee turnover in critical roles;
- system downtime;
- regulatory incidents;
- unresolved cybersecurity vulnerabilities;
- project cost variance.
A useful KRI needs a threshold.
For example:
Customer concentration KRI: Largest customer exceeds 20% of revenue.
Escalation threshold: Executive review at 25%.
Without a threshold, data can become reporting rather than management.
ERM and Business Financing
Enterprise risk management also affects how a company thinks about business financing.
Capital decisions can alter the risk profile.
For example, additional debt may support growth but can also increase:
- refinancing risk;
- interest-rate exposure;
- liquidity pressure;
- covenant risk;
- dependence on future cash flows.
Funding should therefore be evaluated not only by cost but by how it changes the company’s ability to absorb adverse conditions.
This is one reason ERM belongs alongside strategy and finance rather than inside a narrow compliance function.
Common Enterprise Risk Management Failures
ERM often fails because it becomes a reporting exercise.
Failure 1: Creating a Huge Risk Register
An organization collects hundreds of risks but cannot explain which ten exposures matter most.
Why it fails: Volume replaces prioritization.
Better approach: Use detailed registers operationally but maintain a concise enterprise risk profile for leadership.
Failure 2: Managing Risks in Silos
Finance, IT, legal, operations, and procurement each maintain separate frameworks.
Why it fails: Interactions between risks remain invisible.
Better approach: Use common risk terminology and aggregate material exposures.
Failure 3: Treating ERM as Compliance
Employees complete annual forms because policy requires them.
Why it fails: Risk information does not influence decisions.
Better approach: Integrate ERM into budgeting, strategic planning, investments, acquisitions, and major projects.
Failure 4: Confusing Risk Appetite With a Slogan
Statements such as “we have a low appetite for risk” provide little practical guidance.
Better approach: Translate appetite into measurable tolerances.
Failure 5: Focusing Only on Threats
Risk is often treated as synonymous with danger.
Why it fails: Management can become excessively defensive.
Better approach: Evaluate uncertainty around both downside and opportunity.
Failure 6: Reporting Risks Without Owners
A risk is marked “high” but nobody is accountable.
Better approach: Assign a named owner, response, deadline, indicator, and escalation threshold.
Failure 7: Updating ERM Only Once a Year
Annual review may be sufficient for stable exposures but inadequate for rapidly changing areas.
Better approach: Match monitoring frequency to risk velocity.
Practical ERM Implementation for a Smaller Business
A company does not need expensive enterprise software to begin.
A simple process can work.
Step 1: Define Five to Ten Key Objectives
Examples:
- maintain liquidity;
- expand into a new market;
- improve customer retention;
- increase production capacity;
- protect critical systems.
Step 2: Identify the Top Risks to Each Objective
Avoid collecting every conceivable risk.
Focus on material uncertainty.
Step 3: Assign Owners
One person should be accountable for monitoring each major exposure.
Step 4: Establish Appetite and Tolerance
Define when exposure becomes unacceptable.
Step 5: Build a Simple Enterprise Risk Register
A spreadsheet can be sufficient initially.
Step 6: Select Key Risk Indicators
Choose indicators that provide early warning rather than merely reporting past events.
Step 7: Review Risks With Business Decisions
Discuss ERM when:
- approving budgets;
- entering markets;
- taking debt;
- selecting major vendors;
- adopting technology;
- making acquisitions;
- launching important projects.
Step 8: Reassess Regularly
Not every risk requires monthly review.
Review frequency should reflect how quickly exposure can change.
What ERM Should Look Like in Practice
A mature enterprise risk management program is not necessarily the program with the most documents.
A practical ERM system should allow leadership to answer five questions quickly:
- What objectives matter most?
- What could materially affect those objectives?
- Which risks exceed our appetite or tolerance?
- Who owns each major exposure?
- What action or decision is required now?
If leadership cannot answer those questions, the organization may have risk reporting without meaningful enterprise risk management.
Enterprise Risk Management and Governance
Boards and senior executives have different roles from operational risk owners.
Operational teams identify and manage detailed exposures.
Senior management integrates risk information with decisions.
Boards typically provide oversight.
The OECD’s review of risk management and corporate governance emphasizes that risk-taking is fundamental to business and entrepreneurship, but governance systems should ensure that risks are understood, managed, and appropriately communicated. OECD
This is an important distinction.
Good governance does not mean eliminating business risk.
It means ensuring that decision-makers understand what risk is being taken and why.
Key Takeaways
Enterprise risk management is an organization-wide approach to managing uncertainty in the context of strategy, performance, and value.
Effective ERM:
- begins with business objectives;
- defines risk appetite and tolerance;
- identifies risks across departments;
- evaluates interdependencies;
- consolidates material exposures;
- prioritizes risks as a portfolio;
- assigns accountable owners;
- monitors key risk indicators;
- integrates risk into strategic decisions;
- continually reviews changes.
COSO and ISO 31000 provide structured approaches, but neither framework should become a paperwork exercise.
The real purpose of ERM is to help leadership make better decisions when outcomes are uncertain.
FAQ
What is enterprise risk management in simple terms?
Enterprise risk management is a company-wide method for identifying and managing risks that could affect strategy and business objectives. ERM combines risks from different departments so leadership can understand how exposures interact and decide which risks require action.
What is the difference between ERM and risk management?
Risk management may address a single project, department, or exposure. Enterprise risk management examines material risks across the entire organization and connects them to strategy, performance, risk appetite, and business objectives.
What is an enterprise risk management framework?
An enterprise risk management framework provides principles, responsibilities, processes, and reporting structures for managing risk consistently across an organization. COSO ERM and ISO 31000 are two widely used approaches.
What are the five components of COSO ERM?
The five COSO ERM components are Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, and Information, Communication & Reporting. COSO organizes 20 ERM principles across these components. COSO
What is risk appetite in ERM?
Risk appetite describes the amount and type of risk an organization is willing to accept while pursuing objectives. Risk tolerance translates that broad appetite into more specific limits or acceptable variations.
What is an enterprise risk register?
An enterprise risk register is a structured record of material risks, including their causes, potential impacts, owners, controls, responses, indicators, and residual exposure. It provides input for the broader enterprise risk profile.
Does a small business need enterprise risk management?
A smaller business may not need a complex formal ERM department, but it can still benefit from ERM principles. A simple enterprise risk register, clear risk ownership, defined tolerances, and regular review of major exposures can provide much of the practical value.
