Basics of Enterprise Risk Management (ERM): How to Get Started

Enterprise risk officer carrying a compartmentalized case that represents integrated enterprise risk management

Enterprise risk management (ERM) is the organization-wide practice of identifying, assessing, responding to, and monitoring uncertainty that could affect strategic objectives. It connects risk decisions to strategy, performance, governance, and day-to-day execution instead of leaving each department to manage risk in isolation.

The basics of enterprise risk management help teams get started with a shared view of risk, clear ownership, defined response thresholds, and evidence that controls are working. A strong ERM program does not guarantee outcomes, but it helps leaders make better decisions, respond earlier, and pursue opportunities without taking unmanaged exposure.

This guide covers the foundations of enterprise risk management, its benefits, the COSO, ISO 31000, and CAS approaches, a practical five-stage ERM process, and a memorable case showing how several risks can interact.

What is enterprise risk management (ERM)?

Enterprise risk management, often shortened to ERM, is a coordinated approach to uncertainty that could affect objectives. It identifies threats and opportunities across the organization, evaluates their significance, assigns responses, and monitors whether those responses work.

“The culture, capabilities, and practices, integrated with strategy-setting and performance, that organizations rely on to manage risk in creating, preserving, and realizing value.” – The Committee of Sponsoring Organizations of the Treadway Commission (COSO), from Enterprise Risk Management – Integrating with Strategy and Performance
As well as identifying risks, the practice of enterprise risk management also involves making preparations for dealing with these risks and deciding prioritization over multiple active or potential risks.

Risk policies, decisions, and reports should be documented and accessible to the people responsible for oversight and execution. Sensitive registers and response plans still require role-appropriate access and clear ownership.

ERM is utilized in all industries, from construction, finance, aviation, healthcare, energy, and marketing. The International Organization for Standardization (ISO) defines risk management as:
“coordinated activities to direct and control an organization with regard to risk … [a] systematic application of policies, procedures and practices to the activities of communicating and consulting, establishing the context and assessing, treating, monitoring, reviewing, recording and reporting risk.” – ISO 31000 – Risk Management Guidelines
Risk management is not a new concept; historically, companies would manage risk with insurance policies. Liability, malpractice, loss or injury, property insurance, natural disasters – different policies to “manage” different risks relating to different business activities. In recent years, as standards for risk management have become more established and seen widespread adoption, risk management has become more akin to a business process management framework. That is to say, ERM systems will typically focus more on control of internal processes, using principles of continuous improvement, internal audits, compliance with standards – seeking to minimize controlled risk as much as possible, as well as setting up preventative measures for risks and hazards outside the scope of control of business processes. Let’s look at some of the benefits of successfully implementing an ERM program.

Why a well-implemented ERM program matters

ERM works best when leaders, risk owners, control owners, and operators understand the same objectives, risk appetite, escalation rules, and reporting expectations. That shared language helps the organization compare risks across functions instead of treating each one as a separate problem.

A well-run program can improve decisions by connecting risk to strategy, clarifying who owns each response, and making tradeoffs visible. It can also reduce surprises by creating a regular cadence for reviewing changing conditions, control performance, and new evidence.

Enterprise risk management is not only about preventing loss. It can expose opportunities for process improvement, resilience, and better allocation of resources. A response that reduces one risk may also remove bottlenecks or strengthen the customer experience.

That is why risk should not be evaluated only by the possible downside. Teams should also ask what new capability, market position, or operating advantage could come from handling the uncertainty well.

Processes can then be improved and optimized, producing immediate operational benefits while reducing future exposure.

Core ERM areas and responsibilities

One practical way to understand the operating scope of ERM is through four connected areas:

Hazard risk and control

To assess hazards, risk managers follow these five steps:
  1. Identify exposures to risk
  2. Assess the frequency and severity of these exposures
  3. Identify alternative approaches (including process improvements)
  4. Choose an alternative and implement it
  5. Monitor the implementation and adjust as needed
This process is focused on both preventative and crisis risk management. While not specifically relating to any one framework of ERM, the example below clearly illustrates the relationship between risk, hazard, and exposure:
Hazard, exposure, likelihood, control, and consequence shown in a focused risk-control model

Internal control

This is another way of saying the meta-processes that companies use to make sure internal processes are being followed. Internal control processes are also used to improve process efficiency in areas such as reporting, conformity, and general process effectiveness. Larger organizations, especially those in highly regulated industries, will often have elaborate and expansive systems of internal control.

Internal audits

Simply put, internal audits are used to make sure internal controls are working properly. This is different to risk management – it’s another meta-level process that looks instead at the cost, efficiency, and effectiveness of the ERM processes. Internal audits are concerned with how the risks are actually being managed in practice, and how this evidentiality sits in-line with the documented policies and procedures of the ERM. Teams of internal auditors will look at operating activities, consistency, and compliance. Results of the audit including weaknesses and recommendations are typically given in the form of an audit report.

Regulatory compliance

Certain rules and regulations must be followed by companies; this area of enterprise risk management concerns efforts to make sure these requirements are met. For example, government bodies may issue requirements for site safety, environmental policy, social responsibility, or financial reporting. Companies will typically have a specialized compliance unit or officer who interprets these requirements, giving advice, training, and recommendations for conformance.

Examples of ERM approaches

Over the years, various frameworks for ERM have been established. Each of them describes a different approach for the identification, analysis, response, and general management of risks and opportunities. Here are a few of the most prominent ERM approaches:

ISO 31000

ISO 31000 refers to a family of standards for risk management, defined by The International Organization for Standardization. As well as the wider family of standards, ISO 31000 also refers to a specific standard within that family. ISO 31000:2018 is the current published edition, reviewed and confirmed by ISO in 2023 while the next revision proceeds. ISO 31000:2018 for risk management provides a set of guidelines for organizations to manage risk. It is not a set of requirements, and as such cannot be certified to, unlike other ISO standards like ISO 9001. Other standards in the family include IEC 31010:2019, Risk management, risk assessment techniques, which provides guidance on specific techniques for risk management.

CAS

The Casualty Actuary Society (CAS) is a society of professionals trained in the discipline of actuarial science, specializing in property and casualty insurance. In 2003, the society’s Enterprise Risk Management Committee defined ERM using two concepts: risk type, and risk management processes. Of ERM they said the following:
“…the discipline by which an organization in any industry assesses, controls, exploits, finances, and monitors risks from all sources for the purpose of increasing the organization’s short- and long-term value to its stakeholders.” – CAS ERM Committee, from Overview of Enterprise Risk Management
Examples of risk type include:
  • Hazards: e.g. natural disasters and property damage
  • Financial risks: e.g. asset, securities, or fiat currency risk
  • Strategic risks: e.g. business competition and trends
  • Operational risks: e.g. customer satisfaction, brand integrity, reputation, product faults and failure
Risk management process:
  1. Establish context: internal and external scope of the organization, and the scope of the ERM system
  2. Identify risks: As they relate to the organization’s objectives; these should be well-documented and include the corresponding potential for gaining competitive advantage as a result of process improvement
  3. Analyze severity risks: For each of the risks identified, assess (and if possible, quantify) the severity of each risk
  4. Integrate risks: Based on the results of previous risk analysis, aggregate all risk distributions and align the analysis with the determined impact on KPIs
  5. Prioritizing risks: Determine a ranked order of prioritization for each of the risks identified
  6. Risk management strategies: This involves strategies for resolving and exploiting risks identified
  7. Monitoring and reviewing results: The continuous improvement of the risk management process by way of monitoring and assessment of the risk environment; basically what works and what doesn’t, and figuring out how to improve the process

COSO

COSO connects enterprise risk management directly to strategy and performance. Its Enterprise Risk Management: Integrating with Strategy and Performance framework states:

“Enterprise risk management is not a function or department. It is the culture, capabilities, and practices that organizations integrate with strategy-setting and apply when they carry out that strategy, with a purpose of managing risk in creating, preserving, and realizing value.” – Enterprise Risk Management: Integrating with Strategy and Performance
COSO enterprise risk management components from governance and strategy through performance, review, and reporting
The framework organizes ERM into five connected components: 1. Governance and culture: Enterprise risk management cannot succeed unless the organization seeks to fully integrate it within the culture of their workplace. This pertains to the ethics behind worker responsibilities, codes of conduct, and the proper comprehension of risks, as well as all associated management programs and solutions. 2. Strategy and objective-setting: A fundamental part of ERM is making sure the risk management strategies align with core objectives and broader business strategies. Business objectives are the basis for planning and implementing strategies, while simultaneously serving as a launch-pad for identifying, assessing, and responding to risks. 3. Performance: Assessing how certain risks will impact the performance of key processes is important for risk prioritization. In this context, risks are prioritized in order of their severity. Following this, risk responses are selected based on an assessment of the potential for risk that has been identified. Results of this part of the process are typically reported to key stakeholders. 4. Review and revision: By reviewing the performance of risk management processes, organizations can determine how well the ERM program is working, including whether or not changes are needed. 5. Information, communication, and reporting: ERM is not a single checklist or a fixed set of steps; it is an ongoing process of collecting and assessing information from internal and external sources, across all parts of an organization. The five components above are supported by an additional set of principles. These principles are wide-ranging, covering everything from corporate leadership of the ERM program to risk monitoring methods. Each of the principles are short and succinct; here they are, as they appear in Enterprise Risk Management: Integrating with Strategy and Performance (2017 Edition): Organizations can use these principles as a clear reference point for contextualizing and evidencing their efforts to understand and strive for an enterprise risk management program that is firmly aligned with its strategy and business objectives.

The enterprise risk management cycle

The enterprise risk management cycle has five recognizable stages: set objectives and context, identify risks, assess and prioritize them, choose responses, and monitor results. The stages repeat as strategy, operations, regulations, and external conditions change.

Five-stage enterprise risk management process from objectives through monitoring

Set objectives and define risk appetite

ERM starts with the objectives the organization is trying to achieve. Leaders define the relevant context, connect objectives to mission and strategy, and establish risk appetite, tolerance, ownership, and escalation thresholds.

Risk appetite, tolerance, and limit shown as distinct governance thresholds

Risk appetite expresses the broad amount and type of risk the organization is willing to pursue or retain. Tolerance turns that direction into an operating range. A limit marks the point where escalation or a different response is required.

This alignment prevents a common ERM failure: building a detailed risk register that is disconnected from the decisions leadership actually makes. The board and executives set direction and oversight. Business and process owners translate that direction into controls, indicators, and response plans that can be tested in daily work.

Identify and document risks

Risks are uncertainties that could affect objectives. Identification should cover the enterprise, business units, projects, processes, third parties, technology, compliance obligations, and emerging risks such as cyber or AI-related change.

Each material risk needs a clear description, owner, affected objective, existing controls, and evidence source. A consistent risk register makes cross-enterprise comparison possible without pretending every risk can be measured the same way.

Use both top-down and bottom-up identification. Leadership can surface strategic, financial, regulatory, and external risks that span the organization. Operators can identify process failures, handoff gaps, weak controls, and changing conditions that are visible only where the work happens. Third-party, cyber, and AI-related risks often cut across both views.

Assess and prioritize documented risks

Identification alone is not enough. Teams assess likelihood, impact, velocity, and the effectiveness of current controls. Qualitative, quantitative, and semi-quantitative methods can all be useful when they match the quality of available evidence. NIST maintains a current risk-assessment terminology reference for these approaches.

Brainstormed risks still need scrutiny. Assumptions, data quality, dependencies, and control performance should be tested before a risk is prioritized. Simple tools such as a prioritization matrix can help, but the score does not replace judgment.

Separate inherent risk from residual risk. Inherent risk describes the exposure before controls. Residual risk reflects what remains after the controls are applied. That distinction helps leaders see whether a high score comes from the underlying activity, a weak control, or both. It also prevents teams from treating the existence of a policy as proof that the risk is controlled.

A likelihood-impact heat map supports discussion about relative priority and risk appetite. It should make the selected assumptions visible, not imply false precision.

Likelihood-impact risk heat map with one selected supplier outage risk

Choose a risk response

Management selects a response after considering likelihood, impact, cost, timing, dependencies, and the organization’s appetite. Common responses include avoiding, reducing, sharing or transferring, accepting, and, where appropriate, pursuing an opportunity.

Avoidance: Stop the activity or change the objective so the exposure no longer exists. A company might leave a market or discontinue a product when the downside exceeds its appetite.

Reduction: Lower likelihood or impact through controls. Diversification, backups, training, revised procedures, and automation can reduce exposure, though no control removes every source of error.

Sharing or transfer: Allocate part of the exposure to another party through insurance, contracts, hedging, or a joint venture. The original organization still needs to understand retained risk and counterparty risk.

Acceptance: Make an explicit decision to retain the risk within appetite. Assign an owner, define monitoring and escalation thresholds, and maintain a contingency or reserve where needed.

Pursuit: Take informed risk when the potential upside supports strategy. The same analysis used to constrain downside can reveal an opportunity worth developing.

Responses rarely operate alone. A supplier concentration risk might be reduced by qualifying a second supplier, transferred in part through contract terms, and accepted for a limited period with additional inventory and a clear escalation threshold. The response plan should name each action, owner, due date, evidence requirement, and trigger for reassessment.

Monitor, report, and improve

Risk changes with the operating context. Owners review indicators, incidents, control evidence, and response progress on a defined cadence. Material changes trigger escalation, reassessment, or a revised response.

Monitoring works best when it combines leading and lagging indicators. A leading indicator might show control drift, overdue reviews, supplier deterioration, or rising exception volume before a loss occurs. A lagging indicator records incidents, findings, downtime, or financial impact after the event. Both should connect to an owner and a decision threshold.

Like continuous improvement, ERM is ongoing. Monitoring should show not only whether a risk changed, but whether the control worked and whether the decision remains aligned with strategy.

The Russian frozen-chickens case and its ERM lessons

This historical case is adapted from John J. Hampton’s Fundamentals of Enterprise Risk Management: How Top Companies Assess Risk, Manage Exposure, and Seize Opportunity. The case examines four aspects of risk identified in pursuit of a risk opportunity associated with the export of a cargo of frozen chickens from Virginia and North Carolina to St. Petersburg, Russia. The company planned to load a number of 60-80 pound boxes on pallets for an ocean voyage. Except, the port of St. Petersburg had no shoreside refrigeration to allow quick unloading of an expensive reefer vessel.

Expropriation risk

If the ship wasted too long docked in St. Petersburg waiting for containers to offload the shipment, it would incur significant fees for delayed operations. One solution would be to build a warehouse, but the risk manager identified an expropriation risk. A case from the mid-1990s was cited: a European-invested hotel in St. Petersburg incurred hefty fines after the Russian government learned it was using a foreign bank account to handle dollar transactions. The result was the expropriation of the hotel premises by the Russian government. While the risk manager knew she could obtain reimbursement insurance from a U.S. government agency, the identified expropriation risk didn’t seem to be the answer. Therefore, the company opted to seek a strong Russian partner with high-level government connections and allow the partner to accept the expropriation and storage exposure. Lesson learned: Investigate all options for risk reduction. Don’t assume that the obvious approach is the best answer!

Credit risk

So far so good; the company had a strong Russian partner. This was also bad news, as it created a credit risk. How could the U.S. company make sure the Russian partner paid in a timely manner? It wasn’t realistic to ask for an up-front payment, neither was it reasonable to obtain a letter of credit guaranteeing future payment. As it transpired, the Russian partner was not able to pay for the first cargo until 30 days after receiving it. To deal with this problem of credit exposure, an agreement was made that the Russian partner would pay for one cargo before it received a subsequent. This mitigated exposure to credit risk because the stream of profits from a series of cargo shipments was significantly larger than a default payment on a single cargo. If the Russian partner didn’t pay by day 45 after receipt of a cargo, the ship carrying the next cargo would be diverted from Russia to a northern European port. Lesson learned: Give other parties incentives to help your organization mitigate risk.

Physical security risk

Once the Russian partner accepted the chicken in St. Petersburg, the shipment was transported by rail to Moscow, Yekaterinburg, and beyond via locked refrigeration containers loaded onto flat railcars. On the fifth journey, one of the containers was discovered to be empty when it arrived in Moscow after the three-day trip from St. Petersburg. The shipment had been stolen. At this point, the partner was facing a physical security risk. Two viable strategies were identified:
  1. Purchase insurance
  2. Door-to-door container placement so that the doors could not be opened if the locks were broken
The first strategy was dismissed quickly. Who would insure a cargo with an already-existing high chance of loss? Premiums would be prohibitively high. The second strategy was chosen. This proved effective for a time; however, the story was not over. Several journeys later, another container arrived empty. Realizing that someone had a crane on a siding when the train stopped in the middle of the night, the Russian partner considered what else should be tried. Finally, the problem was solved by placing a boxcar on the back of the train. The car had fitted heaters and cots, carrying guards armed with Kalashnikovs. Whenever the train stopped, the guards stepped out to protect the containers. Lesson learned: Sometimes it’s worth sticking with a risk management strategy, tweaking and fine-tuning the solution until the problem is solved. Not everything will work out-of-the-box.

Upside of risk

While the security situation on Russian railroads has improved significantly since the 1990s, this story also identifies the upside of risk. Once the cargo was being protected by armed guards, the Russian partner had the opportunity to offer insurance services to third parties to protect their cargoes as well as the frozen chickens. The loss incurred from managing the risk with the paid armed guards and rear boxcar would, in that case, be offset by the confidence that the train would experience no losses, and the additional revenue from the insurance services offered. Lesson learned: Risk management does not end with the mitigation of risk – always look for an upside!

Manage your risks with automation

ERM creates recurring operational work: collecting risk information, routing assessments, assigning responses, gathering evidence, approving exceptions, and reviewing controls. Structured automation helps teams run that work consistently while preserving human judgment for the decisions that need it.

Process Street is one Compliance Operations Platform. Docs provides governed policies and procedures with versioning and approvals. Ops turns those procedures into executable workflows with assignments, conditional routing, escalations, and evidence capture. Built-in AI helps teams draft workflows, surface risk, and improve operations inside the same governed system.

For ERM, that means a risk policy can stay connected to the workflow that carries out the assessment and response. Each run creates an audit trail showing what happened, who approved it, what evidence was collected, and where an exception needs attention.

Process Street workflow for supplier risk review, control evidence, approval, escalation, and monitoring

If you are evaluating the wider market, compare the capabilities in this guide to current risk management software. The best fit should support your risk model, ownership structure, evidence needs, and systems of record.

Related resources:

Explore Process Street plans and the 14-day Pro trial.

How does your organization approach enterprise risk management? Which frameworks, controls, and operating routines are most useful?

Get our posts & product updates earlier by simply subscribing

Take control of your workflows today