Enterprise risk management
1 Introduction
Enterprise Risk Management (ERM) can be defined as the:
‘ ... process effected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.’
Enterprise Risk Management – Integrated Framework,
the Committee of Sponsoring Organisations, COSO, 2004
Think of ERM as a development and formalisation of the approaches already described.
2 The COSO framework for ERM
The following diagram sets out the COSO framework for ERM:

Across the top of the cube are all the categories of risk that an enterprise can suffer from: strategic, operations, reporting and compliance. These have already been discussed.
Down the side, going “into” the paper the enterprise is considered at various levels of operation: the whole entity (think of group level); divisional level (Eg European, USA and Asian divisions); then business units (such as cars and commercial vehicles); finally subsidiaries (for example, different marques of car).
Some risks will be felt at entity level – for example, the Volkswagen exhaust emission scandal. Other risks will be more limited - for example, one make and model of vehicle that has to be recalled for repair, or a subsidiary dealing with consumer finance for new vehicles not complying with lending regulations.
Risk consolidation is the process of aggregating divisional/subsidiary risks at the corporate level. Some risks can be handled together and be subject to a common approach, or they might even substantially cancel.
For example, many organisations will organise insurance at the group level to cover injury to employees anywhere in the group. This approach will usually be cheaper than insuring small groups of employees separately.
Similarly, if one subsidiary is exporting and receiving US$, whilst another is importing and spends US$, the net exposure to US$ currency movement might be very low and can be ignored at the group level.
Down the front of the cube are the elements of a risk management approach:
Internal environment
This can be regarded as the outlook and culture of the organisation, including its enthusiasm for risk management and its risk appetite.
For example, some organisations are a bit happy-go-lucky when it comes to risk management whereas others are extremely strict and want things to be done by the book.
Objective setting
Objectives must exist before management can identify potential events affecting their achievement. Enterprise risk management ensures that management has in place a process to set objectives and that the chosen objectives support and align with the entity’s mission and are consistent with its risk appetite.
For example, the objectives of a military operation might be to capture a town and to do that, certain risks will be experienced and have to be assessed and evaluated.
The objectives of a research and development department in a business will establish the risks that it suffers (such as a development failing to work).
The objectives of a marketing department will, again be quite different, and will be judged against their risks such as the failure of a marketing campaign (or too much uptake on special offers!)
Event identification
As discussed earlier, there are internal and external events (both positive and negative) which affect the achievement of an entity’s objectives and must be identified.
Risk assessment
As already discussed, risks are analysed to consider their likelihood and impact as a basis for determining how they should be managed.
Risk response
Management selects risk response(s) to transfer, avoid, reduce or accept risk (TARA).
The aim is to align risks with the entity’s risk tolerance and risk appetite. Risk tolerance is the acceptable variation in outcome compared to an original objective. In setting risk tolerance, management considers the relative importance of the related objective. So, if an objective is particularly important, risk tolerances might be higher to recognise that achieving something really worthwhile is worth accepting more risk.
Control activities
Policies, procedures and control methods help to ensure risk responses are properly carried out. Examples of control activities include authorisation of transactions, reconciliations, segregation of duties (splitting a transaction so that several people are involved), physical controls (such as locking away valuable inventory), the comparison of actual results to budgets. IT controls can also be very important.
Information and communication
Information that monitors or identifies risks must be identified, recorded and communicated quickly enough and in a way that lets people carry out their responsibilities by making decisions. For example, if a product’s sales are lower than expected, this information must be available quickly enough to change prices, alter the advertising campaign – or to withdraw the product.
Monitoring
The entire ERM process must be monitored and modifications made as necessary, to improve current methodologies and to adapt to emerging risks, so that the system stays relevant.
3 Risk reports
UK quoted companies are now required to include risk reports as part of their annual reports. This informs shareholders and others about the organisations’ main risks and what the company is doing about them.
Here is an extract from Unilever’s 2015 report and financial statements:
https://www.unilever.com/Images/governance_and_financial_report_ar15_tcm244-477381_en.pdf
4 Principal Risk Factors
Our business is subject to risks and uncertainties. On the following pages we have identified the risks that we regard as the most relevant to our business. These are the risks that we see as most material to Unilever’s business and performance at this time.
There may be other risks that could emerge in the future. We have also commented below on certain mitigating actions that we believe help us to manage these risks. However, we may not be successful in deploying some or all of these mitigating actions.
If the circumstances in these risks occur or are not successfully mitigated, our cash flow, operating results, financial position, business and reputation could be materially adversely affected. In addition, risks and uncertainties could cause actual results to vary from those described, which may include forward-looking statements, or could affect our ability to meet our targets or be detrimental to our profitability or reputation.
DESCRIPTION OF THE RISK | WHAT WE ARE DOING TO MANAGE THE RISK |
BRAND PREFERENCE | We continuously monitor external market trends and collate consumer, customer and shopper insight in order to develop category and brand strategies. |
SUPPLY CHAIN | We have contingency plans designed to enable us to secure alternative key material supplies at short notice, to transfer or share production between manufacturing sites and to use substitute materials in our product formulations and recipes. |
SAFE AND HIGH QUALITY PRODUCTS | Our product quality processes and controls are comprehensive, from product design to customer shelf. They are verified annually, and regularly monitored through performance indicators that drive continuous improvement activities. Our key suppliers are externally certified and the quality of material received is regularly monitored to ensure that it meets the rigorous quality standards that our products require. |
5 Environmental, social, and ethical issues of risk management
Organisations have an effect on their environment and the human stakeholders with whom they interact. These effects can often produce ethical dilemmas that organisations have to deal with.
Examples of environmental issues
BP and the Deepwater Horizon oil spill in the Gulf of Mexico
VW and car emission misreporting
Release of dangerous chemicals into water supplies
Everyone is wise with hindsight and no-one in the organisations concerned would have wanted these events to happen (though someone in VW was responsible for incorrect reporting).
However, as always, there is a balance to be struck between risk and performance. Quite obviously there would be no oil spills if no company drilled for oil. BP had safety procedures in place but either they were inadequate or BP suffered exceptional bad luck. Not only did the company have to pay huge fines and compensation (about $60Bn) but it suffered severe reputational damage.
Unilever’s risk report also contains a section on sustainability:
SUSTAINABILITY | The Unilever Sustainable Living Plan sets clear long-term commitments to improve health and well-being, reduce environmental impact and enhance livelihoods. Underpinning these are targets in areas such as hygiene, nutrition, sustainable sourcing, fairness in the workplace, opportunities for women and inclusive business as well as greenhouse gas emissions, water and waste. These targets and more sustainable ways of operating are being integrated into Unilever’s day-to-day business. |
Examples of social issues
Use of Facebook, Twitter to ‘troll’ and bully.
Capture of ‘big data’ to analyse consumer habits
Discrimination or lack of diversity in the workplace
Companies suffer reputational risk if their products or information gathering cause damage. The unauthorised release of data can cause financial damage to customers.
Poor recruitment policies leave companies open to accusations of discrimination and this can cause both reputational damage and can lead to legal claims.
Poor diversity policies can cause poor business results as products, services and employees no longer match up to what customers expect.
Ethical issues
For example, a pharmaceutical company is developing a new drug. Some of the ethical issues arising from this are:
Safeguarding the volunteers on whom the drug is tested
How much testing should be done before the drug is marketed? The more testing the greater the delay in releasing a drug very effective in treating a disease but, balancing that, more testing means less chance of undiscovered side effects.
At what price should the drug be sold? A high price might please shareholders and could enable more money to be spent on research and development of more drugs. However, a high price would mean that some patients and health services could not afford the drug. Should different prices be charged for the same drug in different countries depending on the country’s wealth? Poor ethical choices present risks, particularly reputational and compliance.


