Business Core · Governance · Module

Enterprise risk

How much risk the owners will carry, which risks the whole organisation actually holds, and how the board keeps sight of the distance between the two.

The idea

How it works

Most organisations manage risk in pieces, and manage the pieces reasonably well. Compliance holds regulatory risk, technology holds security risk, the supply chain holds the risk of a supplier failing, and each is kept within tolerance by the people closest to it. What is missing is the sum: several moderate risks that the same event would trigger together, or a total exposure that no single owner would have agreed to.

Enterprise risk is where that sum is taken. It starts from appetite — how much the owners are willing to lose, of what kind, for which gains — and keeps a single register in which risks from every source are described on the same scale. ISO 31000 and COSO’s 2017 framework both define risk against objectives, and the practical consequence is that the register has to be read alongside the strategy it threatens.

Working with it

In practice

  1. 01

    Set the appetite before listing risks

    Without a stated appetite every risk looks either alarming or acceptable, depending on who presents it.

  2. 02

    Take inputs without duplicating them

    Compliance, security and supply risks arrive from the functions that manage them. The enterprise register summarises and relates them; it does not repeat the analysis.

  3. 03

    Look for shared causes

    Group risks by the event that would trigger them. Correlation is where an organisation-wide view adds something a functional view cannot.

  4. 04

    Show the board who gives assurance

    For each principal risk, which of the three lines checks it, and when that last happened.

One level in

The components of enterprise risk

A component is something that exists afterwards which did not exist before — a deliverable or a mechanism, not an intention.

  1. Risk appetite statement

    How much risk the organisation is prepared to carry, by category, with the tolerances that trigger escalation.

    Learn
  2. Enterprise risk register

    The principal risks across the whole organisation, from every source, assessed on one scale and each with an owner.

    Learn
  3. Assurance map

    For each principal risk, who manages it, who oversees it and who checks it independently, and how recently.

    Learn

A register of forty risks all rated amber gives the board nothing to decide. Fewer entries, set against a stated appetite, give it something.