Introduction
If you are reading this, there is a decent chance someone has recently said to you:
Congratulations. And condolences.
For many US companies, ERM is still viewed as a nice-to-have. There is no regulator telling you exactly how to do it, no one-size-fits-all handbook, and usually no extra headcount walking in the door with your new responsibility. Most organizations back into ERM when:
- The board starts asking tougher questions about risk
- The company is looking at going public or raising capital
- The risk profile has clearly changed – new markets, new products, new regulation, or new technology (hello, AI)
If you are feeling a mix of curiosity, urgency, and mild impostor syndrome… You are exactly where most ERM leaders start.
This Point of View is written for you: leaders in US companies who suddenly find themselves responsible for ERM, often as another hat you will wear. The goal is not to make you a technical risk theorist. The goal is to:
Give you the foundations you need to feel comfortable launching (or relaunching) ERM
Help you spot the decisions that matter most
Make it clear where you can do a lot on your own and where it is worth bringing help
In this position, you probably have a lot of questions. Let’s answer them.
1
Why is ERM needed now?
Three big shifts are making ERM less of a luxury and more of a basic operating discipline:
Uncertainty is no longer intermittent; it is the background.
Geopolitics, regulation, supply chains, cyber, talent, social expectations, and now AI: very little about your operating environment is stable for long. Leaders are expected to make faster decisions with higher stakes and with more scrutiny than ever.
Stakeholders expect a coherent story about risk.
Boards, investors, regulators, and customers want to know not just what your risks are, but how you know, how they are managed, and how that connects to strategy and performance. Ad hoc slide decks and one-off risk workshops rarely answer those questions consistently.
Data and technology have changed what “good” looks like.
ERM used to be synonymous with big spreadsheets and annual workshops. Now, there is an expectation that risk insights are data-informed, near real-time, and connected to other parts of the business – operations, finance, compliance, cyber, and even ESG.
In short, ERM is no longer about building a long list of risks. It is about helping the organization manage uncertainty and allocate attention and resources where they matter most.
2
How do I know when ERM is right for my organization?
Not every organization needs a full-blown ERM function tomorrow. But there are clear indicators that you are ready – or overdue – for something more structured:
- The board or executive team is asking for a consolidated view of top risks, beyond traditional financial or compliance reporting.
- Major strategic moves are underway – IPO, M&A, new markets, transformational technology – and leadership wants confidence that key risks have been thought through.
- Internal Audit is struggling to align its plan to what leadership actually cares about and is looking for a more systematic way to focus on “the most important things.”
- You have multiple second-line risk functions (cybersecurity, compliance, safety, quality, etc.) that do solid work individually but feel siloed and uncoordinated.
- After every incident or surprise, you hear some version of “We kind of saw that coming… but we did not have a way to connect the dots.”
If several of these sound familiar, ERM is not just “right”; it has probably been missing for a while.
Is ERM right for us? What we need to achieve
- Holistic View
- Strategic Alignment
- Proactive Culture
- Regulatory Compliance
- Improved Decision-Making
- Operational Resilience
The good news: you do not have to start with perfection. You can begin with a practical, agile approach that connects what you already have and grows as your organization matures.
3
Who should lead ERM?
This is one of the most common – and most sensitive – questions.
There is no single “correct” home for ERM, but here are some common structures:
Chief Risk Officer (CRO) Organization
- Most authority and clarity of mandate
- Best suited when risk is already a board-level priority, and the organization has grown in complexity
- Less common in earlier-stage ERM programs, but powerful when done well
Internal Audit
- Very common starting point in US companies
- Strengths: broad view across the organization, comfort with risk concepts, access to the board or audit committee
- Watch-outs: ERM can be perceived as another assurance or compliance activity instead of a strategic partner if the role is not clearly differentiated
Legal or Compliance
- Strengths: credibility with leadership, proximity to regulatory and litigation risk
- Watch-outs: bandwidth is often limited, and focus can skew heavily toward downside and regulatory exposure, crowding out strategic or upside risk
Strategy, FP&A, or Corporate Development
- Often the best long-term fit, because these functions sit close to strategy and capital allocation
- Can help ensure that risk thinking is embedded in planning and investment decisions, not bolted on after the fact
- Less common as the initial home, but worth targeting over time as ERM matures
Wherever ERM sits, what matters most is how it behaves:
It needs access to leadership and the board.
It must be seen as a partner to the business, not a scorekeeper.
It should be curious, analytical, and facilitative – good at asking questions, translating risk language, and connecting dots across functions.
If you have been asked to “own ERM” from one of these functions, you do not have to have all the answers. Your job is to build the structure, invite the right voices, and make it easier for leaders to make risk-informed decisions.
4
How do I get buy-in from our leaders?
You can design a beautiful framework and still fail if your leadership sees ERM as:
Extra paperwork
A threat
(“you are here to rate my failures”)
A fad that will fade
after the next reorg
Early buy-in is less about selling ERM and more about solving problems leaders already care about.
Practical moves to build buy-in:
01. Find a visible champion
Look for an executive or board member who already discusses risk thoughtfully. Ask them what keeps them up at night and where they feel “blind spots.” Position ERM as a way to give them cleaner sightlines, not more reports.
02. Start small and prove value quickly
Pick one or two well-defined areas – for example, a new product launch, a regulatory change, or a major transformation program – and use ERM concepts to help frame the risks and trade-offs. Share a short, crisp output that leadership can actually use.
03. Integrate with existing rhythms
Rather than adding new meetings and templates, plug into what already exists: strategy off-sites, capital allocation forums, quarterly business reviews, and audit committee meetings. Replace or enhance existing risk content before creating brand-new rituals.
04. Be explicit about what success looks like
Work with leadership to define a simple ERM vision statement, such as:
Revisit that statement regularly and show how ERM activities are moving you toward it.
05. Keep the language human
Avoid leading with rating scales and matrices. Start with plain-language discussions of what could derail your strategy, where you might be overconfident, and where you might be underinvesting in resilience.
When leaders see ERM as a decision-support capability rather than a reporting requirement, buy-in tends to follow.
5
What are the first steps I should take to set up an ERM program?
When you are given a blank sheet of paper, it is tempting to jump straight to frameworks, policies, and taxonomies. Resist the urge to over-engineer the early stage. Instead, think in terms of a practical 12–18 month journey.
Launching ERM
Phase 01 – Foundations
Q1 to Q2 (Months 1–6)
Phase 02 – Integration
Q3 to Q4 (Months 7–12)
Phase 03 – Advanced Capabilities
Q5 to Q6 (Months 13–18)
Understand your current state
Before you design something new, get clear on what already exists:
- What risk processes are already happening (e.g., cyber risk assessments, SOX, safety reviews, insurance renewals, business continuity planning)?
- What risk information already goes to the board and executive team?
- Where are the gaps, overlaps, and pain points? (For example: inconsistent risk rating scales, duplicated assessments, or missing coverage in certain areas.)
This does not require a massive diagnostic. A handful of targeted interviews and a quick document review can give you enough to sketch a baseline.
Establish an ERM vision
This is not a website slogan. It is a clear statement of purpose that you can use to prioritize everything else. For example:
- “Provide a consolidated, forward-looking view of our most important risks to support strategic decisions.”
- “Create a common language for risk across the organization.”
- “Ensure the board and leadership have confidence that top risks are identified, owned, and actively managed.”
If you cannot explain your ERM vision in a few sentences without using jargon, it is not ready yet.
Define a roadmap
With a vision and a baseline, you can sketch a phased roadmap, typically along lines like:
- Phase 1 (0–6 months): Stand up basic governance, including a risk committee, perform the first enterprise risk assessment, and produce a concise top-risk report for leadership.
- Phase 2 (6–12 months): Strengthen risk ownership and action planning, refine your risk taxonomy and criteria, and start integrating with strategy and capital allocation.
- Phase 3 (12–18 months): Expand to more advanced capabilities – scenario analysis, quantitative methods where relevant, and selective technology enablement.
The roadmap should be ambitious enough to feel meaningful, but realistic given your capacity.
Build foundational governance
At minimum, you will want to define:
- Roles and responsibilities (who owns ERM, who owns individual risks, how other risk functions connect)
- An ERM policy or charter that describes scope, objectives, and principles
- A basic operating model: how often risks are assessed, who participates, and how results are escalated and reported
Keep the documentation tight. A five-page policy that people will actually read beats a 40-page manual that no one opens.
Create a common language for risk
You do not need a 500-line risk taxonomy on day one, but you do need:
- A clear, simple risk taxonomy (e.g., strategic, financial, operational, compliance, technology, people, sustainability) that other functions can map into
- Standard rating criteria for impact and likelihood (or vulnerability), with examples in plain language
- A shared view of what “high,” “medium,” and “low” actually mean in your context – ideally linked to financial, operational, and reputational thresholds
Enterprise Risk Categories: Financial, Associates (HR), Compliance, Technology, Operations, Reputation, Strategy
Run your first enterprise risk assessment
This is where the program starts to feel “real”:
- Identify a manageable set of participants across functions and business units
- Use a combination of interviews, workshops, and data to identify the top enterprise-level risks
- Apply your common taxonomy and criteria to rate them
- Distill the results into a short list of top risks (often 10–20) with
From there, you can work with risk owners to define treatment plans, metrics, and reporting.
6
How should ERM be positioned with respect to other risk functions?
If your organization already has strong risk functions – cyber, compliance, legal, safety, quality, internal audit, business continuity, ESG – ERM can sound like one more player in an already crowded field.
To avoid confusion and turf wars, be explicit:
ERM is the integrator, not a competitor.
ERM’s role is to provide a cross-functional view of risk and a standard set of tools that other functions can plug into. It should not try to become an expert in every risk domain.
ERM sets the “rules of the game.”
ERM is well placed to drive:
- A common risk taxonomy
- Shared rating criteria and scales
- Templates for risk registers, action plans, and reporting
- A consistent aggregation approach so leaders can see risk across silos
Cadence matters.
Where possible, ERM should align assessment and reporting frequencies across risk functions. This reduces assessment fatigue in the business and makes it easier to present an integrated view to leadership.
Risk committees should be purposeful, not maximalist.
Instead of inviting every possible risk owner to a 20-person committee, consider a small, well-chosen group who:
- Understand the business and its strategy
- Are comfortable discussing both risk and opportunity
- Are well-connected enough to pull others in when necessary
The committee’s job is to prioritize, synthesize, and escalate – not to micromanage every control.
When positioned clearly, ERM becomes the thread that ties risk together, not another box on the org chart.
Three Lines and ERM

7
How can I add value right away?
You do not have to wait for the perfect framework to start being useful. In fact, early, visible wins are one of the fastest ways to gain credibility.
A few ways to deliver value quickly:
1. Clarify the top handful of enterprise risks
Use what you already know – previous assessments, incident logs, strategy documents – to sketch a draft list of top risks. Validate it with a few key leaders and refine. Even a well-framed draft can spark better conversations than a blank page.
2. Create a simple risk narrative for the board
Replace scattered risk content with a single, coherent story:
- What our top risks are
- How they connect to our strategy and performance
- Where we have strong mitigation and where we are more exposed
- What we are doing about it over the next 12–18 months
3. Offer deeper dives into the risks that hurt most
Pick one or two top risks (for example, cyber, AI, supply chain, regulatory change). Convene a small cross-functional group to explore:
- What is driving this risk?
- How would we know if it is getting better or worse?
- What scenarios should we be prepared for?
- Do we have clear owners and plans?
Summarize the output in clear language and use it to inform planning or investment decisions.
4. Make risk discussions more two-way
Many leaders experience risk reporting as a one-directional flow upward. Use ERM to close the loop: after leadership reviews top risks, share what was prioritized, what will change, and where more information is needed. Over time, this increases transparency and engagement in the risk process.
These early moves show that ERM is not about paperwork; it is about helping the organization see around corners and move with more confidence.
8
How should I approach tech enablement and AI?
If you are already wrestling with slides, spreadsheets, and SharePoint folders, the appeal of a GRC platform or AI-powered tool is obvious. Technology and AI can be game-changing, but only if they serve a clear ERM framework, not replace it.
Consider a few principles:
Substance before systems
Before you buy or configure anything, you need:
- A defined ERM framework (taxonomy, rating criteria, aggregation approach)
- Clarity on what information you want to capture and how it will be used
- Agreement on who owns what – both risks and data
Without this, implementers will default to “out-of-the-box” configurations that may not fit your organization and will be painful to fix later.
Start with targeted use cases
Instead of aiming for a fully automated, AI-enabled ERM platform on day one, consider a few discrete, high-value use cases, such as:
- Horizon scanning: using AI to sift news, industry reports, and internal data for early signals on key risk themes
- Driver analysis: using pattern recognition to highlight correlations between operational metrics and incident trends
- KRI monitoring: automatically flagging when certain metrics move outside expected ranges
Keep humans in the loop
ERM depends on judgment, context, and debate. AI can suggest scenarios, cluster risk themes, and surface anomalies, but it cannot make risk decisions. Treat AI as an additional input to better conversations, not a black box that makes the call.
Plan for data quality and governance
Any technology you adopt will only be as good as the data it receives. Be realistic about:
- Where your data lives today
- Who is responsible for keeping it accurate and current
- What level of precision do you actually need for decision-making
In most organizations, the right order is:
Design a fit-for-purpose ERM framework → run it manually → then selectively automate and augment with AI.
Framework First
ERM Framework
Manual Operation
Tech & AI Enablement
9
What should my long-term ERM goals be?
It is tempting to define success as “we have an ERM program.” A more helpful way to think about it is: what does it look like when ERM is genuinely part of how we run the business?
Common long-term goals include:
A consistent way of thinking and talking about risk
Across functions, business units, and geographies, people use similar language and criteria. Leaders can compare risks on an apples-to-apples basis, and there is a clear line of sight from local issues to enterprise-level exposure.
A seat at the decision-making table
ERM is not just a quarterly report. It shows up in strategy discussions, investment committees, product approvals, and M&A decisions. When leaders debate a big move, someone naturally asks, “What does ERM say?”
Aligned and efficient risk functions
Second line functions (cyber, compliance, safety, etc.) and Internal Audit work from a shared framework. Assessment cycles are coordinated, reporting is streamlined, and the business experiences fewer, more meaningful conversations about risk.
Businesses see ERM as a value-add partner
Business leaders do not feel policed. They seek out ERM to help stress-test plans, frame trade-offs, and turn vague concerns into concrete actions and metrics.
A mature, forward-looking view of risk
Over time, ERM should move from cataloging today’s issues to anticipating tomorrow’s – using data, scenarios, and external signals to help leadership understand where the risk landscape is headed and what that means for strategy.

One way to visualize this journey is through a basic ERM maturity model:
Informal
Risk handled locally, with minimal enterprise view
Developing
Initial ERM charter, first top-risk list, inconsistent practices
Established
Clear taxonomy, criteria, governance, and regular reporting
Mature
ERM embedded in planning, capital allocation, and performance management
Advanced
Advanced analytics and AI used to inform strategy; risk and opportunity managed as two sides of the same coin
You do not need to be at level 5 to get value. The biggest step-change often comes from simply moving from Ad Hoc → Defined in a way that fits your organization.
Where you will likely need help
Many ERM leaders can self-start with vision, stakeholder engagement, and a first cut at a risk register. It is both normal and smart to look for support in a few specific areas:
Designing a right-sized framework
Translating good intentions into practical criteria, taxonomies, and governance is harder than it looks on paper. Experienced external partners can help you avoid re-learning hard lessons from other organizations.
Facilitating early assessments and workshops
Having a neutral facilitator can make it easier to surface uncomfortable risks, keep conversations focused, and turn brainstorming into clear outputs that leadership can use.
Aligning ERM with other risk and control programs
Integrating ERM with Internal Audit, SOX, cyber, ESG, and business continuity often requires cross-functional negotiation and design work that benefits from an outside perspective.
Selecting and implementing technology
When you are ready, guidance on tool selection, configuration, and AI use cases can help ensure that technology supports your framework rather than driving it.
The goal of bringing in help is not to outsource ERM. It is to accelerate your learning curve, avoid common traps, and ensure that the capability you build is sustainable and genuinely useful for your organization.
Bringing it all together
- ERM is not about building the perfect framework; it is about helping your organization make better decisions under uncertainty.
- You can start small, practical, and human, using ERM to clarify what matters most, who owns it, and what you are going to do about it.
- Over time, with the right structure, technology, and people, ERM can become a quiet competitive advantage – the discipline that keeps your organization curious, prepared, and confident when the world around you are not.
If you have just been handed ERM as your “side job,” you are not alone. With a clear vision, a few early wins, and the right partners, it can become one of the most impactful things you do for your organization.




