Skip to main content
Category: Enterprise Risk Management

ERM Program

Also known as: ERM, Enterprise Risk Management Program, Enterprise-Wide Risk Management Program
Simply put

An ERM program is an organization-wide approach to identifying and managing the full range of significant risks an organization faces, considering both threats and opportunities. Rather than handling risks in isolated pockets, it brings them together so leaders can discuss and address them at an institutional level. The aim is to support the organization's ability to achieve its objectives.

Formal definition

An ERM program is an integrated, entity-wide structure and set of processes for managing the full spectrum of significant risks against organizational objectives, addressing both downside threats and upside opportunities. It commonly encompasses risk governance, risk identification, risk quantification or assessment, and risk-reward decision-making applied holistically across the organization rather than within functional silos. As a management (rather than assurance) activity, an ERM program is typically owned and operated by management to enhance the organization's ability to achieve its objectives; specific framework selection, governance structures, and implementation details vary by organization, sector, and jurisdiction.

Why it matters

Organizations rarely fail because of a single, isolated risk; more often, significant exposures accumulate across functions where no one holds a complete picture. An ERM program addresses this by bringing the full spectrum of significant risks together so that leaders can consider them at an institutional level rather than within functional silos. This integrated view helps ensure that risks affecting the organization's ability to achieve its objectives are surfaced, discussed, and weighed against one another instead of being managed in disconnected pockets.

Because an ERM program considers both downside threats and upside opportunities, it supports risk-reward decision-making rather than pure risk avoidance. Positioning risk information alongside strategic objectives allows management to make more informed trade-offs and to allocate attention and resources where exposure is most material. The intent is to enhance, not guarantee, the organization's ability to meet its goals; an ERM program does not eliminate uncertainty, and its effectiveness depends on how well it is designed, owned, and operated within a given organization.

Who it's relevant to

Risk Managers and Chief Risk Officers
Those responsible for designing and operating the risk function use an ERM program to integrate risk identification, assessment, and risk-reward decision-making across the organization rather than managing exposures in isolated pockets. As a management activity, the program is typically owned and operated by these roles.
Senior Leadership and Governing Bodies
Executives and boards rely on the institutional-level view an ERM program provides to discuss and address the full spectrum of significant risks against organizational objectives, weighing both threats and opportunities in strategic decisions.
Public Sector and Agency Leaders
Government agencies apply ERM as an agency-wide approach to addressing the full spectrum of significant risks they face, considering both threats and opportunities. Specific governance structures and implementation details vary by jurisdiction.
Higher Education and Institutional Administrators
Campus leaders use ERM as a holistic process to discuss and manage risk at an institutional level, bringing exposures that span academic, operational, and other functions into a shared view rather than treating them separately.
Internal Auditors and Assurance Functions
While auditors do not own or operate the ERM program, they may evaluate whether it is designed and functioning effectively. Maintaining the distinction between this independent assurance role and management's ownership of the program is important.

Inside ERM

Governance and Oversight Structure
The defined roles, decision rights, and accountability arrangements that direct the program, commonly involving the board or a board committee, executive management, and a risk function. This structure clarifies who owns risk decisions and who provides oversight, and it typically spans the governance pillar rather than day-to-day risk treatment.
Risk Appetite and Tolerance Statements
Articulations of the amount and type of risk the organization is willing to pursue (appetite) and the acceptable variation around specific objectives (tolerance). These are distinct: appetite is generally a higher-level, forward-looking expression, while tolerance sets more granular, often measurable, boundaries.
Risk Identification and Assessment Processes
Methods for surfacing risks and evaluating them, commonly considering likelihood and impact. Assessments may distinguish inherent risk (before controls) from residual risk (after controls), though the availability of a true inherent-risk view varies in practice.
Risk Treatment and Response
The decisions and actions taken to address assessed risks, such as accepting, mitigating, transferring, or avoiding. These are management activities and should be distinguished from assurance activities that independently evaluate their effectiveness.
Monitoring, Reporting, and Escalation
Mechanisms for tracking the risk profile over time and communicating it to appropriate levels, including escalation paths when tolerances are approached or breached. Reporting cadence and content commonly vary by organization, sector, and jurisdiction.
Roles Across the Lines Model
An allocation of responsibilities in which operational management typically owns and manages risk (first line), risk and compliance functions provide oversight and challenge (second line), and internal audit provides independent assurance (third line), consistent with the IIA's three lines model. The independence of the third line should be preserved.
Framework Alignment
Reference to recognized frameworks such as COSO ERM, issued by the Committee of Sponsoring Organizations of the Treadway Commission, and ISO 31000, issued by the International Organization for Standardization, which provide principles and guidance for enterprise risk management rather than prescriptive compliance mandates.

Common questions

Answers to the questions practitioners most commonly ask about ERM.

Is an ERM program the same as operational risk management?
No. An ERM program provides an enterprise-wide, portfolio view of risk against organizational objectives, coordinating risk identification, assessment, and treatment across the whole organization. Operational risk management addresses a narrower category of risk, typically arising from failed or inadequate internal processes, people, systems, or external events. Operational risk management commonly sits within the broader ERM structure rather than being equivalent to it.
Does having an ERM program guarantee that risks will be prevented or eliminated?
No. An ERM program is designed to help an organization identify, assess, and treat uncertainty against its objectives; it does not guarantee outcomes. Even a mature program cannot eliminate all risk, and residual risk typically remains after treatment. ERM commonly aims to keep risk within the organization's stated appetite and tolerance and to improve the quality of risk-informed decisions, not to provide assurance that adverse events will never occur.
How does an ERM program typically relate to the three lines model?
In many organizations, an ERM program draws on the roles described in the IIA's three lines model. Management functions that own and manage risk commonly form the first line, a risk management function that establishes and oversees the ERM framework often operates in the second line, and internal audit provides independent assurance over the framework's effectiveness from the third line. The specific allocation of responsibilities varies by organization, and it is important to keep assurance activities distinct from the management activities being assured.
What frameworks are commonly used to structure an ERM program?
Two frequently referenced references are COSO's enterprise risk management framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission, and ISO 31000, a risk management standard issued by the International Organization for Standardization. Organizations may adopt one, blend elements of both, or align with sector-specific guidance. This entry does not cover implementation specifics, tooling, or the selection of a particular framework, which depend on organizational context, jurisdiction, and industry.
How is the scope of an ERM program typically defined?
Scope is commonly defined in relation to the organization's objectives and the risks that could affect their achievement, and it often reflects the organization's stated risk appetite and tolerance. Governance bodies typically play a role in setting decision rights, roles, and oversight for the program. Appropriate scope varies with jurisdiction, industry, and organization size, and requirements that apply in one context should not be assumed to apply universally.
How might the effectiveness of an ERM program be evaluated?
Effectiveness is often assessed through independent assurance activities, such as internal audit reviews of whether the ERM framework is designed and operating as intended, kept distinct from the management functions that own the risks. Organizations may also monitor whether risks are being maintained within appetite and tolerance and whether risk information is supporting decisions. This entry does not provide specific metrics, maturity models, or legal advice, as suitable approaches vary by organization and framework.

Common misconceptions

An ERM program is essentially the same as a compliance program.
ERM concerns the identification, assessment, and treatment of uncertainty against objectives across the organization, whereas compliance concerns adherence to external laws and regulations and internal policies. They can overlap, compliance risk is one category within ERM, but they are distinct disciplines with different aims.
Risk appetite and risk tolerance are interchangeable terms.
Appetite generally expresses, at a higher level, the amount and type of risk an organization is willing to pursue, while tolerance sets the acceptable variation around specific objectives and is often more granular and measurable. Treating them as synonyms can obscure where boundaries actually apply.
Adopting a framework such as COSO ERM or ISO 31000 guarantees that risks will be controlled.
These frameworks provide principles and guidance, not assurance of outcomes. An ERM program can reduce and inform decisions about risk, but no program eliminates uncertainty or guarantees objectives will be met; effectiveness depends on implementation, culture, and context.

Best practices

Define and document risk appetite and tolerance separately, linking tolerances to specific objectives so that escalation triggers are clear and measurable.
Preserve the independence and objectivity of assurance functions by keeping the third line's evaluation of controls separate from the management activities that own and operate those controls.
Distinguish inherent from residual risk in assessment documentation so that decision-makers can see the effect of existing controls, while acknowledging where a reliable inherent-risk view is not practical.
Align the program with a recognized framework such as COSO ERM or ISO 31000 as guidance, while tailoring it to the organization's jurisdiction, sector, and size rather than treating any framework as a universal mandate.
Establish clear governance, roles, and escalation paths consistent with a lines-of-responsibility model, so ownership of risk decisions and oversight responsibilities are unambiguous.
Report the risk profile to the board or appropriate committee on a defined cadence, using qualified, context-specific language that reflects uncertainty rather than implying guaranteed outcomes.
Promotional banner for the Pentest Readiness checklist download