Businesses can’t eliminate risk, but they can manage it to maximize the entity’s economic return. A new framework aims to help business owners and managers more effectively integrate enterprise risk management (ERM) practices into their overall business strategies.
On September 6, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) published Enterprise Risk Management — Integrating with Strategy and Performance. You can use the updated framework to develop a more effective risk management strategy and to monitor the results of your ERM practices.
The updated framework discusses ERM relative to the changes in the financial markets, the emergence of new technologies and demographic changes. It’s organized into five interrelated components:
1. Governance and culture. This refers to a company’s tone and oversight function. It includes ethics, values and identification of risks.
2. Strategy and objective setting. Proactive managers align the company’s appetite for risk with its strategy. This serves as the basis for identifying, assessing and responding to risk. By understanding risks, management enhances decision making.
3. Performance. Management must prioritize risks, allocate its finite resources and report results to stakeholders.
4. Review and revision. ERM is a continuous improvement process. Poorly functioning components may need to be revised.
5. Information, communication and reporting. Sharing information is an integral part of effective ERM programs.
COSO Chair Robert Hirth said in a recent statement, “Our overall goal is to continue to encourage a risk-conscious culture.” He also said that the updated framework is not intended to replace COSO’s Enterprise Risk Management — Integrated Framework. Rather, it’s meant to reflect how the practice of ERM has evolved since 2004.
The updated framework clarifies several misconceptions from the previous version. Specifically, effective ERM encompasses more than taking an inventory of risks; it’s an entitywide process for proactively managing risk. Additionally, internal control is just one small part of ERM; ERM includes other topics such as strategy setting, governance, communicating with stakeholders and measuring performance. These principles apply at all business levels, across all functions and to organizations of any size.
Moreover, the update enables management to better anticipate risk so they can get ahead of it, with an understanding that change creates opportunities — not simply the potential for crises. In short, it helps increase positive outcomes and reduce negative surprises that come from risk-taking activities.
ERM in the future
We can help you identify and optimize risks in today’s complex, volatile and ambiguous business environment. We’re familiar with emerging ERM trends and challenges, such as dealing with prolific data, leveraging artificial intelligence and automating business functions. Contact us for help adopting cost-effective ERM practices to help make your business more resilient.
Stay up to date! Subscribe to our future blog posts!