Launching ERM When It Isn’t Your Day Job

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Phasellus pharetra tortor eget lacus ullamcorper, posuere fringilla justo convallis.

Uniqus Insights

Launching ERM When It Isn’t Your Day Job

A practical FAQ for US business and risk leaders

25, May 2026

 

Introduction

If you are reading this, there is a decent chance someone has recently said to you:

“We really should have Enterprise Risk Management… can you take a look at that?”

Congratulations. And condolences.

For many US companies, ERM is still viewed as a nice-to-have. There is no regulator telling you exactly how to do it, no one-size-fits-all handbook, and usually no extra headcount walking in the door with your new responsibility. Most organizations back into ERM when:

  • The board starts asking tougher questions about risk
  • The company is looking at going public or raising capital
  • The risk profile has clearly changed – new markets, new products, new regulation, or new technology (hello, AI)

If you are feeling a mix of curiosity, urgency, and mild impostor syndrome… You are exactly where most ERM leaders start.

This Point of View is written for you: leaders in US companies who suddenly find themselves responsible for ERM, often as another hat you will wear. The goal is not to make you a technical risk theorist. The goal is to:

1

Give you the foundations you need to feel comfortable launching (or relaunching) ERM

2

Help you spot the decisions that matter most

3

Make it clear where you can do a lot on your own and where it is worth bringing help

In this position, you probably have a lot of questions. Let’s answer them.


1

Why is ERM needed now?

Three big shifts are making ERM less of a luxury and more of a basic operating discipline:

1

Uncertainty is no longer intermittent; it is the background.

Geopolitics, regulation, supply chains, cyber, talent, social expectations, and now AI: very little about your operating environment is stable for long. Leaders are expected to make faster decisions with higher stakes and with more scrutiny than ever.

2

Stakeholders expect a coherent story about risk.

Boards, investors, regulators, and customers want to know not just what your risks are, but how you know, how they are managed, and how that connects to strategy and performance. Ad hoc slide decks and one-off risk workshops rarely answer those questions consistently.

3

Data and technology have changed what “good” looks like.

ERM used to be synonymous with big spreadsheets and annual workshops. Now, there is an expectation that risk insights are data-informed, near real-time, and connected to other parts of the business – operations, finance, compliance, cyber, and even ESG.

In short, ERM is no longer about building a long list of risks. It is about helping the organization manage uncertainty and allocate attention and resources where they matter most.

2

How do I know when ERM is right for my organization?

Not every organization needs a full-blown ERM function tomorrow. But there are clear indicators that you are ready – or overdue – for something more structured:

  • The board or executive team is asking for a consolidated view of top risks, beyond traditional financial or compliance reporting.
  • Major strategic moves are underway – IPO, M&A, new markets, transformational technology – and leadership wants confidence that key risks have been thought through.
  • Internal Audit is struggling to align its plan to what leadership actually cares about and is looking for a more systematic way to focus on “the most important things.”
  • You have multiple second-line risk functions (cybersecurity, compliance, safety, quality, etc.) that do solid work individually but feel siloed and uncoordinated.
  • After every incident or surprise, you hear some version of “We kind of saw that coming… but we did not have a way to connect the dots.”

If several of these sound familiar, ERM is not just “right”; it has probably been missing for a while.

Is ERM right for us? What we need to achieve

  • Holistic View
  • Strategic Alignment
  • Proactive Culture
  • Regulatory Compliance
  • Improved Decision-Making
  • Operational Resilience

The good news: you do not have to start with perfection. You can begin with a practical, agile approach that connects what you already have and grows as your organization matures.

3

Who should lead ERM?

This is one of the most common – and most sensitive – questions.

There is no single “correct” home for ERM, but here are some common structures:

Chief Risk Officer (CRO) Organization

  • Most authority and clarity of mandate
  • Best suited when risk is already a board-level priority, and the organization has grown in complexity
  • Less common in earlier-stage ERM programs, but powerful when done well

Internal Audit

  • Very common starting point in US companies
  • Strengths: broad view across the organization, comfort with risk concepts, access to the board or audit committee
  • Watch-outs: ERM can be perceived as another assurance or compliance activity instead of a strategic partner if the role is not clearly differentiated

Legal or Compliance

  • Strengths: credibility with leadership, proximity to regulatory and litigation risk
  • Watch-outs: bandwidth is often limited, and focus can skew heavily toward downside and regulatory exposure, crowding out strategic or upside risk

Strategy, FP&A, or Corporate Development

  • Often the best long-term fit, because these functions sit close to strategy and capital allocation
  • Can help ensure that risk thinking is embedded in planning and investment decisions, not bolted on after the fact
  • Less common as the initial home, but worth targeting over time as ERM matures

Wherever ERM sits, what matters most is how it behaves:

1

It needs access to leadership and the board.

2

It must be seen as a partner to the business, not a scorekeeper.

3

It should be curious, analytical, and facilitative – good at asking questions, translating risk language, and connecting dots across functions.

If you have been asked to “own ERM” from one of these functions, you do not have to have all the answers. Your job is to build the structure, invite the right voices, and make it easier for leaders to make risk-informed decisions.

4

How do I get buy-in from our leaders?

You can design a beautiful framework and still fail if your leadership sees ERM as:

Extra paperwork

A threat

(“you are here to rate my failures”)

A fad that will fade

after the next reorg

Early buy-in is less about selling ERM and more about solving problems leaders already care about.

Practical moves to build buy-in:

01. Find a visible champion

Look for an executive or board member who already discusses risk thoughtfully. Ask them what keeps them up at night and where they feel “blind spots.” Position ERM as a way to give them cleaner sightlines, not more reports.

02. Start small and prove value quickly

Pick one or two well-defined areas – for example, a new product launch, a regulatory change, or a major transformation program – and use ERM concepts to help frame the risks and trade-offs. Share a short, crisp output that leadership can actually use.

03. Integrate with existing rhythms

Rather than adding new meetings and templates, plug into what already exists: strategy off-sites, capital allocation forums, quarterly business reviews, and audit committee meetings. Replace or enhance existing risk content before creating brand-new rituals.

04. Be explicit about what success looks like

Work with leadership to define a simple ERM vision statement, such as:

“We want a clear, consistent view of our most important risks, so leaders can make confident decisions and know whether mitigation investments are working.”

Revisit that statement regularly and show how ERM activities are moving you toward it.

05. Keep the language human

Avoid leading with rating scales and matrices. Start with plain-language discussions of what could derail your strategy, where you might be overconfident, and where you might be underinvesting in resilience.

When leaders see ERM as a decision-support capability rather than a reporting requirement, buy-in tends to follow.

5

What are the first steps I should take to set up an ERM program?

When you are given a blank sheet of paper, it is tempting to jump straight to frameworks, policies, and taxonomies. Resist the urge to over-engineer the early stage. Instead, think in terms of a practical 12–18 month journey.

Launching ERM

1

Phase 01 – Foundations

Q1 to Q2 (Months 1–6)

2

Phase 02 – Integration

Q3 to Q4 (Months 7–12)

3

Phase 03 – Advanced Capabilities

Q5 to Q6 (Months 13–18)

Step 01

Understand your current state

Before you design something new, get clear on what already exists:

  • What risk processes are already happening (e.g., cyber risk assessments, SOX, safety reviews, insurance renewals, business continuity planning)?
  • What risk information already goes to the board and executive team?
  • Where are the gaps, overlaps, and pain points? (For example: inconsistent risk rating scales, duplicated assessments, or missing coverage in certain areas.)

This does not require a massive diagnostic. A handful of targeted interviews and a quick document review can give you enough to sketch a baseline.

Step 02

Establish an ERM vision

This is not a website slogan. It is a clear statement of purpose that you can use to prioritize everything else. For example:

  • “Provide a consolidated, forward-looking view of our most important risks to support strategic decisions.”
  • “Create a common language for risk across the organization.”
  • “Ensure the board and leadership have confidence that top risks are identified, owned, and actively managed.”

If you cannot explain your ERM vision in a few sentences without using jargon, it is not ready yet.

Step 03

Define a roadmap

With a vision and a baseline, you can sketch a phased roadmap, typically along lines like:

  • Phase 1 (0–6 months): Stand up basic governance, including a risk committee, perform the first enterprise risk assessment, and produce a concise top-risk report for leadership.
  • Phase 2 (6–12 months): Strengthen risk ownership and action planning, refine your risk taxonomy and criteria, and start integrating with strategy and capital allocation.
  • Phase 3 (12–18 months): Expand to more advanced capabilities – scenario analysis, quantitative methods where relevant, and selective technology enablement.

The roadmap should be ambitious enough to feel meaningful, but realistic given your capacity.

Step 04

Build foundational governance

At minimum, you will want to define:

  • Roles and responsibilities (who owns ERM, who owns individual risks, how other risk functions connect)
  • An ERM policy or charter that describes scope, objectives, and principles
  • A basic operating model: how often risks are assessed, who participates, and how results are escalated and reported

Keep the documentation tight. A five-page policy that people will actually read beats a 40-page manual that no one opens.

Step 05

Create a common language for risk

You do not need a 500-line risk taxonomy on day one, but you do need:

  • A clear, simple risk taxonomy (e.g., strategic, financial, operational, compliance, technology, people, sustainability) that other functions can map into
  • Standard rating criteria for impact and likelihood (or vulnerability), with examples in plain language
  • A shared view of what “high,” “medium,” and “low” actually mean in your context – ideally linked to financial, operational, and reputational thresholds

Enterprise Risk Categories: Financial, Associates (HR), Compliance, Technology, Operations, Reputation, Strategy

Step 06

Run your first enterprise risk assessment

This is where the program starts to feel “real”:

  • Identify a manageable set of participants across functions and business units
  • Use a combination of interviews, workshops, and data to identify the top enterprise-level risks
  • Apply your common taxonomy and criteria to rate them
  • Distill the results into a short list of top risks (often 10–20) with

From there, you can work with risk owners to define treatment plans, metrics, and reporting.

6

How should ERM be positioned with respect to other risk functions?

If your organization already has strong risk functions – cyber, compliance, legal, safety, quality, internal audit, business continuity, ESG – ERM can sound like one more player in an already crowded field.

To avoid confusion and turf wars, be explicit:

ERM is the integrator, not a competitor.

ERM’s role is to provide a cross-functional view of risk and a standard set of tools that other functions can plug into. It should not try to become an expert in every risk domain.

ERM sets the “rules of the game.”

ERM is well placed to drive:

  • A common risk taxonomy
  • Shared rating criteria and scales
  • Templates for risk registers, action plans, and reporting
  • A consistent aggregation approach so leaders can see risk across silos

Cadence matters.

Where possible, ERM should align assessment and reporting frequencies across risk functions. This reduces assessment fatigue in the business and makes it easier to present an integrated view to leadership.

Risk committees should be purposeful, not maximalist.

Instead of inviting every possible risk owner to a 20-person committee, consider a small, well-chosen group who:

  • Understand the business and its strategy
  • Are comfortable discussing both risk and opportunity
  • Are well-connected enough to pull others in when necessary

The committee’s job is to prioritize, synthesize, and escalate – not to micromanage every control.

When positioned clearly, ERM becomes the thread that ties risk together, not another box on the org chart.

Three Lines and ERM

7

How can I add value right away?

You do not have to wait for the perfect framework to start being useful. In fact, early, visible wins are one of the fastest ways to gain credibility.

A few ways to deliver value quickly:

1. Clarify the top handful of enterprise risks

Use what you already know – previous assessments, incident logs, strategy documents – to sketch a draft list of top risks. Validate it with a few key leaders and refine. Even a well-framed draft can spark better conversations than a blank page.

2. Create a simple risk narrative for the board

Replace scattered risk content with a single, coherent story:

  • What our top risks are
  • How they connect to our strategy and performance
  • Where we have strong mitigation and where we are more exposed
  • What we are doing about it over the next 12–18 months

3. Offer deeper dives into the risks that hurt most

Pick one or two top risks (for example, cyber, AI, supply chain, regulatory change). Convene a small cross-functional group to explore:

  • What is driving this risk?
  • How would we know if it is getting better or worse?
  • What scenarios should we be prepared for?
  • Do we have clear owners and plans?

Summarize the output in clear language and use it to inform planning or investment decisions.

4. Make risk discussions more two-way

Many leaders experience risk reporting as a one-directional flow upward. Use ERM to close the loop: after leadership reviews top risks, share what was prioritized, what will change, and where more information is needed. Over time, this increases transparency and engagement in the risk process.

These early moves show that ERM is not about paperwork; it is about helping the organization see around corners and move with more confidence.

8

How should I approach tech enablement and AI?

If you are already wrestling with slides, spreadsheets, and SharePoint folders, the appeal of a GRC platform or AI-powered tool is obvious. Technology and AI can be game-changing, but only if they serve a clear ERM framework, not replace it.

Consider a few principles:

Substance before systems

Before you buy or configure anything, you need:

  • A defined ERM framework (taxonomy, rating criteria, aggregation approach)
  • Clarity on what information you want to capture and how it will be used
  • Agreement on who owns what – both risks and data

Without this, implementers will default to “out-of-the-box” configurations that may not fit your organization and will be painful to fix later.

Start with targeted use cases

Instead of aiming for a fully automated, AI-enabled ERM platform on day one, consider a few discrete, high-value use cases, such as:

  • Horizon scanning: using AI to sift news, industry reports, and internal data for early signals on key risk themes
  • Driver analysis: using pattern recognition to highlight correlations between operational metrics and incident trends
  • KRI monitoring: automatically flagging when certain metrics move outside expected ranges

Keep humans in the loop

ERM depends on judgment, context, and debate. AI can suggest scenarios, cluster risk themes, and surface anomalies, but it cannot make risk decisions. Treat AI as an additional input to better conversations, not a black box that makes the call.

Plan for data quality and governance

Any technology you adopt will only be as good as the data it receives. Be realistic about:

  • Where your data lives today
  • Who is responsible for keeping it accurate and current
  • What level of precision do you actually need for decision-making

In most organizations, the right order is:

Design a fit-for-purpose ERM framework → run it manually → then selectively automate and augment with AI.

Framework First

1

ERM Framework

2

Manual Operation

3

Tech & AI Enablement

9

What should my long-term ERM goals be?

It is tempting to define success as “we have an ERM program.” A more helpful way to think about it is: what does it look like when ERM is genuinely part of how we run the business?

Common long-term goals include:

1

A consistent way of thinking and talking about risk

Across functions, business units, and geographies, people use similar language and criteria. Leaders can compare risks on an apples-to-apples basis, and there is a clear line of sight from local issues to enterprise-level exposure.

2

A seat at the decision-making table

ERM is not just a quarterly report. It shows up in strategy discussions, investment committees, product approvals, and M&A decisions. When leaders debate a big move, someone naturally asks, “What does ERM say?”

3

Aligned and efficient risk functions

Second line functions (cyber, compliance, safety, etc.) and Internal Audit work from a shared framework. Assessment cycles are coordinated, reporting is streamlined, and the business experiences fewer, more meaningful conversations about risk.

4

Businesses see ERM as a value-add partner

Business leaders do not feel policed. They seek out ERM to help stress-test plans, frame trade-offs, and turn vague concerns into concrete actions and metrics.

5

A mature, forward-looking view of risk

Over time, ERM should move from cataloging today’s issues to anticipating tomorrow’s – using data, scenarios, and external signals to help leadership understand where the risk landscape is headed and what that means for strategy.

One way to visualize this journey is through a basic ERM maturity model:

1

Informal

Risk handled locally, with minimal enterprise view

2

Developing

Initial ERM charter, first top-risk list, inconsistent practices

3

Established

Clear taxonomy, criteria, governance, and regular reporting

4

Mature

ERM embedded in planning, capital allocation, and performance management

5

Advanced

Advanced analytics and AI used to inform strategy; risk and opportunity managed as two sides of the same coin

You do not need to be at level 5 to get value. The biggest step-change often comes from simply moving from Ad Hoc → Defined in a way that fits your organization.


Where you will likely need help

Many ERM leaders can self-start with vision, stakeholder engagement, and a first cut at a risk register. It is both normal and smart to look for support in a few specific areas:

1

Designing a right-sized framework

Translating good intentions into practical criteria, taxonomies, and governance is harder than it looks on paper. Experienced external partners can help you avoid re-learning hard lessons from other organizations.

2

Facilitating early assessments and workshops

Having a neutral facilitator can make it easier to surface uncomfortable risks, keep conversations focused, and turn brainstorming into clear outputs that leadership can use.

3

Aligning ERM with other risk and control programs

Integrating ERM with Internal Audit, SOX, cyber, ESG, and business continuity often requires cross-functional negotiation and design work that benefits from an outside perspective.

4

Selecting and implementing technology

When you are ready, guidance on tool selection, configuration, and AI use cases can help ensure that technology supports your framework rather than driving it.

The goal of bringing in help is not to outsource ERM. It is to accelerate your learning curve, avoid common traps, and ensure that the capability you build is sustainable and genuinely useful for your organization.


Bringing it all together

  • ERM is not about building the perfect framework; it is about helping your organization make better decisions under uncertainty.
  • You can start small, practical, and human, using ERM to clarify what matters most, who owns it, and what you are going to do about it.
  • Over time, with the right structure, technology, and people, ERM can become a quiet competitive advantage – the discipline that keeps your organization curious, prepared, and confident when the world around you are not.

If you have just been handed ERM as your “side job,” you are not alone. With a clear vision, a few early wins, and the right partners, it can become one of the most impactful things you do for your organization.

Topics in this article

Related

Newsletter

FRM Regulatory Pulse- August 2026

Executive Summary The second edition of the Uniqus "Regulatory Pulse" bulletin covers key regulatory developments and supervisory themes observed across India and the Middle East over the quarter ended June 2026. Consistent with the series, this publication focuses on banking...

Newsletter

Sustainability & Climate Pulse- August 2026

In the News Global Record Climate Finance by Multilateral Development Banks Reaches USD 163 Billion in 2025 In a significant boost for global climate action, multilateral development banks (MDBs) achieved a record climate finance total of USD 163 billion in...

Early Impressions

FASB’s Proposed Accounting Standards Update

Executive Summary On June 10, 2026, the FASB issued a proposed Accounting Standards Update that would clarify the discount rate used to measure the benefit obligation under Subtopic 715-30, Compensation—Retirement Benefits—Defined Benefit Plans—Pension, for certain market-return cash balance plans. The...

Ask Uniqus
Your AI Knowledge Assistant
AI
Hi 👋 How can I help you today?

Download the pdf of this publication


This will close in 0 seconds