• EG Conley Home
  • Why EG Conley
    • Business Performance Advisors
    • Strategic Performance Plan
    • The Principa Alliance
    • Our Team
  • Our Services
    • Business Performance & Growth
    • Performance Benchmarking
    • Tax Services
    • Audit
    • Business Valuations
    • Succession Planning
    • Peer Reviews
    • Retirement Plan Services
    • Payday Solutions
  • Tax Tools
    • Tax Tips
      • Individual
      • Business
      • Financial
    • Tax Rates
    • Due Dates
    • Financial Tools
    • Retention Guide
    • IRS Forms
  • Events
    • Summits & Webinars
  • News
    • Monthly Newsletter
    • Daily News
  • Contact Us
    • Careers

EG Conley Blog

Making your business more valuable.

  • Blog Home
  • Tax Tips
    • Business
    • Individual
    • Non-Profit
    • Payroll
  • Business Performance
  • QuickBooks
  • Accounting
Home Business Management Seeing the big picture with an enterprise risk management program

Seeing the big picture with an enterprise risk management program

Posted on January 29, 2024 Written by EG Conley, PC Leave a Comment

There’s no way around it — owning and operating a business comes with risk. On the one hand, operating under excessive levels of risk will likely impair the value of a business, consume much of its working capital and could even lead to bankruptcy if those risks become all-consuming. But on the other hand, no business can operate risk-free. Those that try will inevitably miss out on growth opportunities and probably get surpassed by more ambitious competitors.

How can you find the right balance? One way to manage your company’s “risk profile” is to implement a formal enterprise risk management (ERM) program.

Optimization, not elimination

Most businesses have internal controls to prevent fraud, maintain compliance and reduce errors. But an ERM program goes much further. It’s a top-down framework that starts at the C-suite and addresses risk at every level of the organization. An effective ERM program helps you and your leadership team not only identify major threats, but also devise feasible strategic, operational, reporting and compliance objectives.

Traditional risk management techniques, which are often informal and ad hoc, use a “siloed” approach. In other words, each department focuses on minimizing its own risks. The efficacy of this approach is limited at best, for a couple reasons. First, it fails to address how risks may arise in the way departments interact — or don’t interact — with each other. Second, it often wrongly assumes that the goal of risk management is to eliminate risk. In truth, the proper goal of risk management is to optimize risk; that is, develop strategic objectives and operate the business under acceptable levels of inevitable risk.

An ERM program takes an integrated approach. It recognizes that many risks are enterprise-wide and interrelated. For example, say a business identifies a new vendor offering substantially reduced prices on key materials. From the accounting department’s perspective, the deal may seem like a no-brainer. But an analysis under an ERM program could reveal that the vendor is situated in a high-risk area for natural disasters or civil unrest. Or the ERM analysis might show that the vendor is a bad match technologically or has poor cybersecurity.

Good starting point

Naturally, every company’s framework for an ERM program will differ depending on factors such as its size and structure. But one tool that’s proven helpful to many businesses is the Committee of Sponsoring Organizations of the Treadway Commission’s (COSO’s) Enterprise Risk Management — Integrated Framework, which was originally published in 2004.

COSO is a joint initiative of five private sector organizations that develop frameworks and guidance on ERM, internal controls and fraud deterrence. The five organizations are the American Accounting Association, the American Institute of Certified Public Accountants, Financial Executives International, the Institute of Internal Auditors and the Institute of Management Accountants.

The original COSO framework covers four categories of objectives: strategic, operations, reporting and compliance. It also sets forth eight key components: 1) internal environment, 2) objective setting, 3) event identification, 4) risk assessment, 5) risk response, 6) control activities, 7) information and communication, and 8) monitoring. Note that, in 2017, COSO published an updated complementary publication entitled Enterprise Risk Management — Integrating with Strategy and Performance.

Perfect framework

Are you tired of putting out fires or having to rethink major strategic decisions because they’re just a little bit off the mark? If so, a formal ERM program may be the solution you’re looking for. We’d be happy to help you build the perfect framework for your business.

© 2024

Filed Under: Business Management

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Facebook
  • LinkedIn
  • Tumblr

Search the Blog

Subscribe

Get the Adding Value email newsletter

We never share your email address. Opt out at any time.

Tags

ACA Accounts Autos Benefits Capital Gains Cash Flow Charity Credits Customers Deductions Depreciation Divorce Education Employees Estimated Tax Forms Goals Health Insurance HRAs Income Internal Controls IRAs IRS KPIs Life Insurance LLCs Losses Overtime Partnerships Passive Payroll Planning Profit R&D Regulations Rentals Sales & Exchanges S Corps Section 179 SE Tax State Travel Trucks Withholding

Copyright © 2025 · Focus Pro Theme on Genesis Framework · WordPress · Log in