When Everything Becomes an Enterprise Risk - Nothing Is
The misconception
I've never viewed enterprise risk management as a compliance exercise.
Throughout my career I've viewed it as one of the most powerful management tools an organisation can have. When designed well, enterprise risk management doesn't slow organisations down—it gives leaders the confidence to make better decisions, allocate resources more effectively and respond to uncertainty before it becomes a problem.
However, one observation has remained remarkably consistent.
Most organisations don't struggle because they lack enterprise risk management, or even the capacity to deliver it effectively. They struggle because enterprise risk management becomes focused on maintaining risk registers rather than enabling better decisions. When it becomes a task to complete instead of a management tool embedded in business processes, its purpose is reduced to maintaining registers rather than informing strategic decisions.
Enterprise risk management is a crucial and often unsung hero in how organisations grow and deliver on their strategic objectives. Its purpose is to provide leaders with meaningful information about uncertainty so they can make informed decisions, allocate resources effectively and respond to changing circumstances.
In doing so, it enables leaders to steer the organisation in the right direction, while keeping a mind's eye on new and emerging risks that could materially impact the achievement of strategic objectives.
With that in mind, I ask the question:
If enterprise risk management exists to support better decisions and enable the achievement of strategic objectives, why doesn't it?
Risk registers become the ending – not the beginning
The purpose of enterprise risk management isn't to just to design, develop, review and report on risk registers. It isn’t to write papers detailing every risk at every level of the organisation to the Board. And it isn’t a compliance exercise to be conducted quarterly with a simple email or call asking: “is this still the same as last”?
Effective enterprise risk management is less about collecting every organisational risk, and more about ensuring the right risks are discussed by the right people at the right level.
So if enterprise risk management is such a crucial mechanism for achieving strategic objectives, why does it lose value?
I've seen enterprise risk registers containing everything from strategic regulatory reform through to local operational issues. While every one of those risks may be important, they don't all require the same conversations or the same decision-makers.
This doesn't usually happen intentionally. As organisations grow, every business unit quite reasonably wants visibility of its risks. Over time, enterprise risk registers become repositories for every important issue rather than mechanisms for strategic decision-making.
The right risks, discussed at the right level
There are only so many hours in a day, and so many Board or Audit Committee meetings per year, and as such, senior decision makers should focus on the critical risks, those which can impact strategic objectives. Trust and delegation of principal and operational risks is paramount not only to build capability, but also for speed and implementation of mitigation measures.
From my experience, it is often a case of seeing the wood for the trees, and that effective enterprise risk management is ensuring the right information reaches the right people at the right time to make the right decisions. When supported by a Board approved Risk Appetite Statement, setting a clear tone for decision making across the business, enterprise risk management can make a real difference.
When everything becomes an enterprise risk
For example:
We can all agree that having appropriate capability in the business to deliver operational and/or strategic outcomes is crucial for a well-oiled business unit, ensuring the correct skills, knowledge and experience is in place to enable seamless operations. Capability is important, but is the Board going to make strategic decisions to achieve organisational objectives based on a staff training risk?
Probably not.
This is crucial because if everything is elevated to an Enterprise Risk.
Nothing is.
Risks are dynamic
Risks are not static. An operational risk may remain operational for years, but changes in scale, frequency or consequence can require escalation. Likewise, an enterprise risk may reduce in significance over time as controls mature and external conditions change. An effective enterprise risk framework should therefore enable risks to potentially move between risk levels as the organisation evolves.
Going back to our example of staff capability, I think we can also agree that individual staff capability is operational, mistakes being made in payroll, delayed reports, control deficiencies.
However,
If widespread capability gaps begin affecting service delivery, regulatory compliance or achievement of strategic objectives, the discussion and consequences change.
The same underlying issue has evolved into an enterprise risk.
A connected risk hierarchy
One of the best enterprise risk management frameworks I worked with recognised that not every risk belongs in front of the Board. Essentially this was split into three separate, but connected levels:
- Enterprise Risks: Those capable of materially impacting strategic objectives and requiring Board or Audit Committee oversight. These risks should be mutually exclusive but collectively inclusive, manageable but not over aggregated.
- Principal Risks: Risks that could impact multiple business units, requiring executive ownership that could escalate into enterprise risks.
- Operational Risks: Business unit risks owned and managed by operational leaders.
What made this approach extremely powerful was the connection between risk levels.
Each level serves a different purpose but remains connected through a common enterprise risk framework.
Operational risks mapped to a principal risk, and each principal risk mapped to an enterprise risk. This provided clear breadcrumbs and enabled users of the enterprise risk management framework to clearly see the pathway to Board, the organisation’s risk appetite, and the importance of managing risks at all levels.
Each level of risk has a purpose
So when does enterprise risk management add the most value?
My principle is simple, enterprise risk management adds the most value when – it is used as a mechanism to make informed strategic decisions, and supporting documents are living, breathing and dynamic to capture changing environments. Put simply:
| Risk Level | Primary Purpose | Primary Decision Maker |
|---|---|---|
| Enterprise Risk | Strategic decision making | Board / Audit Committee |
| Principal Risk | Executive decision making | Executive Leadership |
| Operational Risk | Operational performance | Business Unit Leaders |
Each of the above levels is important, and with the principles outlined above, clearly interrelate, driven by a clearly articulated Risk Appetite Statement. When each level fulfils its purpose, enterprise risk management becomes a connected system rather than a collection of disconnected registers.
Enterprise risk management as a decision-making system
Enterprise risk management will never eliminate uncertainty.
Nor should it try.
Its purpose is to ensure the right people have the right information at the right time to make informed decisions. To support leaders in understanding where the most uncertainty lies and being able to dedicate resources to it as necessary to prevent unforeseen or minimise any consequential loss.
When that happens, Boards spend less time reviewing operational detail and more time discussing strategic choices, trade-offs and opportunities. Enterprise risk management stops being a compliance exercise and becomes one of the most valuable strategic management tools an organisation has.
Ken De Negri
BSc, MSc, FCCA
De Negri Advisory Pty Ltd
About the author
Ken De Negri is the founder of De Negri Advisory, providing governance, risk, internal audit and sustainability advisory services to organisations across Australia. If this perspective resonates with your organisation or you'd like to discuss how these principles could be applied in practice, feel free to get in touch.