« Expect the best, plan for the worst, and be prepared to be surprised. »

Strategy

« Expect the best, plan for the worst, and be prepared to be surprised. »

If I had to define Enterprise Risk Management (ERM), this quote by Denis Waitley would be my favorite.

The headlines these days regularly remind us of situations where poor risk management has had serious consequences for organizations. The financial costs can be significant, but the impact extends far beyond dollars. Organizations may fail to achieve important non-financial objectives, and these situations often reveal shortcomings in governance, where the Board or leadership did not fulfill the role expected of them. Too often, the search is for someone to blame, when the real focus should be on improving the process.

Risk cannot be measured solely in financial terms. It must also be assessed from reputational, regulatory, legal, operational, cybersecurity, human resources, privacy, and other perspectives. In many cases, the consequences in these areas can be even greater than the financial losses themselves.

For this reason, it is essential that everyone within an organization has a shared understanding of its risks. This broader perspective allows leaders to make informed decisions and better achieve the organization's strategic objectives.

Enterprise Risk Management is designed to be an organization-wide management framework in which every level of the organization has a role to play, from employees and managers to senior executives and the Board of Directors.

There is no single approach to risk management. The most appropriate framework depends on several organizational factors, including the organization's size, whether it operates in the public or private sector, and the regulatory environment in which it operates.

Some risks should be avoided, while others may be worth accepting in pursuit of organizational objectives. Every organization must define its risk appetite, that is, the level of risk it is willing to accept while pursuing its strategic goals. Risks must then be identified, analyzed, assessed, and addressed through appropriate mitigation measures. Depending on the circumstances, an organization may choose to reduce a risk, eliminate it, transfer it, or consciously accept it.

Once this work has been completed, the process does not end there. Organizations should develop a risk matrix, assessing each identified risk according to both its likelihood of occurring and its potential impact.

Once this assessment has been completed, the owner of each risk identifies the existing mitigation measures and determines whether they are sufficient to reduce the likelihood of the risk occurring or whether the remaining level of impact falls within the organization's acceptable level of risk.

The overall Enterprise Risk Management plan is then reviewed and approved by senior management and, where appropriate, by the Board of Directors and/or the Audit Committee.

However, the work does not stop there.

If an organization wants to foster a strong risk-aware culture, senior leadership has a critical role to play. Risk awareness must become part of the organization's values, expectations, and day-to-day decision-making.

Risks must be documented, communicated, regularly reassessed, and updated to ensure that decisions are based on a clear understanding of the organization's evolving risk landscape.

Enterprise Risk Management is an ongoing process, not a one-time exercise. Having the right guidance throughout that process is essential. Today, communication and change management remain among the greatest challenges facing organizations. A rigorous strategic planning process cannot be achieved without integrating Enterprise Risk Management.

Choosing not to integrate it is, in itself, a risk.

Did you know that we support organizations in designing and implementing Enterprise Risk Management frameworks? We help establish a clear governance framework and facilitate discussions with key stakeholders to develop a risk management policy tailored to your organization.

We also work alongside the teams responsible for implementation, supporting every stage of the process, including reporting to the Audit Committee and the Board of Directors. Throughout the engagement, we help ensure an objective, disciplined, and effective approach to Enterprise Risk Management.

We look forward to supporting your organization on this journey!