Business Core · Governance · Module
Enterprise risk
How much risk the owners will carry, which risks the whole organisation actually holds, and how the board keeps sight of the distance between the two.
The idea
How it works
Most organisations manage risk in pieces, and manage the pieces reasonably well. Compliance holds regulatory risk, technology holds security risk, the supply chain holds the risk of a supplier failing, and each is kept within tolerance by the people closest to it. What is missing is the sum: several moderate risks that the same event would trigger together, or a total exposure that no single owner would have agreed to.
Enterprise risk is where that sum is taken. It starts from appetite — how much the owners are willing to lose, of what kind, for which gains — and keeps a single register in which risks from every source are described on the same scale. ISO 31000 and COSO’s 2017 framework both define risk against objectives, and the practical consequence is that the register has to be read alongside the strategy it threatens.
Working with it
In practice
- 01
Set the appetite before listing risks
Without a stated appetite every risk looks either alarming or acceptable, depending on who presents it.
- 02
Take inputs without duplicating them
Compliance, security and supply risks arrive from the functions that manage them. The enterprise register summarises and relates them; it does not repeat the analysis.
- 03
Look for shared causes
Group risks by the event that would trigger them. Correlation is where an organisation-wide view adds something a functional view cannot.
- 04
Show the board who gives assurance
For each principal risk, which of the three lines checks it, and when that last happened.
One level in
The components of enterprise risk
A component is something that exists afterwards which did not exist before — a deliverable or a mechanism, not an intention.
Risk appetite statement
How much risk the organisation is prepared to carry, by category, with the tolerances that trigger escalation.
LearnEnterprise risk register
The principal risks across the whole organisation, from every source, assessed on one scale and each with an owner.
LearnAssurance map
For each principal risk, who manages it, who oversees it and who checks it independently, and how recently.
Learn
A register of forty risks all rated amber gives the board nothing to decide. Fewer entries, set against a stated appetite, give it something.
The other modules in governance
Ownership
Who owns the business, in what shares and with what rights — and what the owners have said they expect from it in return.
LearnThe board
Who oversees the business on the owners’ behalf: its composition, what it has reserved to itself, how its year runs and how it judges its own work.
LearnSuccession and exit
Who takes over the leadership and the ownership when the current holders step back, and by which routes the owners could leave if they chose to.
Learn