PM2 scorecard over ISO 31000 Responses
Previous reports show that performance measurement at Intuit's ERM program hasimproved over the years. As this program matures over time, increasing its complexity andvalue, performance measures and reporting likewise evolve. In particular, the approach to thisperformance measure has been updated to keep its relevance and flexibility with respect to theorganization's risk level and management maturity. Intuit’s ERM program, like many othercompanies' programs, includes an annual risk assessment that provides an enterprise-wideunderstanding of critical risks (Orenstein, 2015). This creates a more focused culture for anorganization and a profound perspective on risk. For Intuit to re-implement a new ERM program, it needs to get the fundamentals right toestablish an ERM framework and an implementation plan. A comparison of the two models froma source CAN/CSA-ISO 31000, Risk management –Principles and Guidelines, InternationalStandards Organizations/Canadian Standards Association (2009) shows that ISO 31000 is muchsimpler to implement compared to the complexity of pm 2 risk scorecard (Fraser, Simkins, &Narvaez, 2014). Edmonton Police Service(EPS) presented the ERM process based on ISO 31000framework and EPS have for five years, evolved a mature ERM process based on in-depthperformance measurement tools to identify and treat its risks.In a nutshell, it is thus recommended to re-implement Intuit’s ERM using the ISO 31000method due to its flexibility as opposed to the pm 2 risk scorecard’s difficulty in the mitigationprocess.