Running head: ENTERPRISE RISK MANAGEMENT 1
Individual Paper: Enterprise Risk Management
Iva White
ACCT 521-D01
November 13, 2017
RISK MANAGEMENT
2
Enterprise Risk Management
Risk management is very important in a business environment. People face risk
everywhere, but in business everything is done to curtail the risks that can be predicted. The
position of risk manager in business has become increasingly more popular since the 1980s,
beginning with the larger corporations. It has replaced other insurance related occupations such
as insurance clerk and insurance manager. Preventatives are put into action to perceive any
difficulties before they can become a problem, because it is easier to stop the situation before it
becomes too involved. If risks aren’t recognized and dealt with, it can mean substantial losses for
a company. According to “Collier and Ampomah operational risks include five things: the failure
of internal processes, human resource error, system failure information, losses resulting from
environmental events outside the company, and damages for violation of rules and laws
apply”[Azh17]. An efficient ERM must take all five of these things into account and prepare for
them. Companies must avert the catastrophes, if possible and plan for a solution if the
catastrophe is not able to be avoided.
Risk management is so important for companies and investors, that in December of 2009,
the United States Securities & Exchange Commission (SEC) has required risk oversight by all
boards of directors after the financial crisis of 2008. Investors were upset that they were not more
aware of the risks that certain companies faced. “Among other things, it would require a
RISK MANAGEMENT
3
narrative disclosure about the company’s compensation policies and practices create risks that
are reasonably likely to have a material adverse effect on the company”[SEC09]. Companies
must also disclose how the board takes a role in risk oversight. “The 2010 Dodd-Frank Act
established the Financial Stability Oversight Council, which heightened standards of risk
management”[Chr15].
Risk management is necessary to any establishment. Risk can be found at every level of
the organization from the very top all the way down to the auditors in a business. Accountants
are also affected by ERM, as internal auditors have a significant role in consulting with
companies about risk management, and the audit committee has the responsibility of oversight
when it comes to risk management. Because Internal Auditing deals with risk, there are many
boards that have tasked the internal auditor with implementing their ERM. There are also
numerous articles that discuss the role an internal auditor should take when implementing an
ERM. One of the main concerns when it comes to IAs and risk management is that internal
auditing is more concerned with operational risk, financial reporting, and compliance. As long as
the auditor can remain neutral in regard to their involvement, they are a great asset and can add
value to the company and its ERM. Enterprise risk management (ERM) is a process that is
advocated by the SEC as an answer to the new rules that were enacted in 2009. “ERM has
become a major focus of many organizations because of legislation and regulations, as well as
recent corporate failures” [Vis16]. Many businesses still doubt that the use of an ERM will
provide them any benefit, and question all of the rules from the SEC, court cases, and Standard
& Poor’s choice to include an organization’s ERM efforts in its assessments used to determine
the stability of a company. Companies resisted the changes put into motion by the Dodd-Frank
Act, and argue that they are not beneficial, but there have been several studies done that show
RISK MANAGEMENT
4
that there is a pronounced lowering of earning volatility for companies that have an efficient
ERM implemented. “The risk management literature frequently identifies lower earnings
volatility as a primary benefit from risk management because of its ability to reduce costs
associated with financial distress”[Chr15]. When looking over the market in the financial crisis
of 2008, it was found that funds that used an efficient risk management model did consistently
better than funds with no model of portfolio risk.
There have been some documented problems for companies when implementing an
efficient ERM. One of the largest problems is the cost of implementation. An efficient ERM
system can be very costly to smaller companies, and the benefits sometimes do not outweigh the
risks. “ERM is often viewed by smaller and medium sized firms as ‘out of their league’ in terms
of cost and sophistication”[Geo15]. Technology plays a large role in the growth and
implementation of an ERM. The process of a full enterprise-wide risk-management program has
not reached maturity, but studies show that it is a lot closer in large companies versus smaller
companies. The supporters of ERM for all businesses do not take this into account when urging
new rules and laws requiring risk management for all companies. While larger companies have
no problem paying for the resources and hiring the staff needed for implementing, smaller
companies find the process much too sophisticated. Small businesses can get bogged down in
implementation, because they don’t understand where to start and cannot afford to take the same
steps as a larger company. Management training is commonly lacking when it comes to assessing
risks and implementing the precautions needed to save a company from a disaster. The tools used
for implementation of risk management can be overwhelming to executives in a company of any
size, but if the process is taken in small increments, it is a viable and beneficial addition to a
small business.
RISK MANAGEMENT
5
For some companies, the board recognizes how beneficial ERM is, though they may
struggle to implement one that is efficient in preventing loss.
A number of practitioner articles have been published with insights and
suggestions related to processes important when implementing ERM. Some
articles provide detailed steps, activities, and tools that should be used, while
others describe individual firms that have implemented ERM, but not necessarily
how they did it[Vis16].
There have been several ERM frameworks devised over the last several years to help companies
with a model and application. Once the executives of a firm decide to implement an ERM, they
may seek assistance from a risk manager or from outside consultants specialized in ERM
frameworks. The committee of Sponsoring Organizations of the Treadway Commission (COSO)
has long been a thought leader when it comes to risk management, and has a ERM framework
that is thought to be one of the best. The last update, building on its previous framework, was in
September of 2017. ERM frameworks are always being updated for the increasing technology
and needs of an ERM.
In the article “Ten Steps to Sustainable Enterprise Risk Management”, the authors outline
ten considerations that can help the companies strategically implement an ERM:
•
Top executives of the firm should be leaders and accept responsibility for the
implementation and daily running of risk management. This first guideline
advises companies to get the entire company, top to bottom, involved with the
implementation of an ERM. It also advises that the executive level take
responsibility for the efficiency of the ERM
•
Appoint a Chief Risk Officer (CRO). By appointing a CRO, and giving this
person the appropriate power, the firm sends a message to the importance of risk
management.
RISK MANAGEMENT
6
•
Establish the risk appetite and make it a daily part of operation. The population
realizes that removing all chance of risk is an impossibility, so number 3 suggests
making a decision on how much risk the company is willing to tolerate. “Risk
appetite is the heart of ERM, and reflects the mission and strategy, including
organizational objectives, strategic plans, and stakeholder expectations”[Ste16].
•
Use strategic planning to incorporate ERM. An efficient strategy is necessary to
recognize and breakdown all barriers that may impede implementation of an
efficient ERM. This starts with the top executives, and trickles down to the lowest
echelons of staff.
•
Include ERM in the company’s formal governance program[Ste16]. This is one of
the more important steps in implementing an efficient ERM. Clear rules should be
laid out in all areas of the ERM, and should include clear roles and
responsibilities, thorough controls, effective oversight and monitoring, continuing
education, and open communication. Incentives can also be offered for employees
make the right decisions and choices.
•
The potential of fraud should be of great concern when implementing an ERM.
The employees of a company are the first line of defense against fraud, and
strategies must be put into place to prevent fraud, and if not able to prevent it,
steps to control it once it happens.
•
Work to recognize risk when it shows up and then find mitigating control. This
step coincides with the last step.
•
Recognize the nature and potential effects of new risks. Companies should
recognize that it is hard to keep up with technology. The risks will continue to
change and evolve on a daily basis, so employees need to keep up to date on the
potential new risks, and identify how to prevent them and steps that need to be
taken in case the firm is unable to prevent the risk.
RISK MANAGEMENT
7
•
Problems should be addressed immediately, and steps taken to resolve them. Once
a problem shows up, it should be taken care of immediately. The root cause
found, and a plan put into place to stop the occurrence from happening again.
•
Remember that the needs of an ERM will constantly evolve, and the company
must also evolve. “The process never ends, making it imperative to embed ERM
and fraud risk management considerations in routine, day-to-day
management”[Ste16].
This is not a complete list of what a company should consider when implementing, but it does
lend some credible advice to companies that need help implementing, and do not know where to
start. Companies must be willing to grow and change to maintain efficient risk management.
They must also be willing to take the steps mentioned above to ensure that oversight and
governance is effective.
It is important when facing the daunting task of implementing an Enterpriise Risk
Management framework, that firms don’t panic. There are resources available for those who find
themselves at a loss for how to begin. Academic research on risk management is growing daily,
working on catching up to the legislature that requires companies to have an ERM in place. ERM
is still evolving, and it is still costly and difficult to implement, but new thoughts and concepts
are delivered daily. There is no reason that firms should be so intimidated by the idea of ERM,
that they don’t try. “ERM is not about avoiding failure but rather achieving success”[Geo15].
RISK MANAGEMENT
8
References
Cassar, G., & Gerakos, J. (2017). Do risk management practices work? Evidence from hedge funds.
Springer Science+Business, 22, 1084-1121. doi:10.1007/s11142-017-9403-5
Chung, D., & Hensher, D. (2015). Risk management in public-private partnerships. Australian Accounting
Review, 1-27.
Edmonds, C. T., Edmonds, J. E., Leece, R. D., & Vermeer, T. E. (2015). Do risk management activities
impact earnings voloatility? Research in Accounting Regulation, 27, 66-72.
Harvey, G. (2015). Enterprise risk management: An update. Petroleum Accounting and Financial
Management Journal, 34(3), 10.
RISK MANAGEMENT
9
Lanen, W. N., Anderson, S. W., & Maher, M. W. (2017). Fundamentals of Cost Accounting (5th ed.). New
York, NY: McGraw-Hill/Irwin.
Steinhoff, J. C., Price, L. A., Comello, T. J., & Cocozza, T. A. (2016). Ten steps to sustainable enterprise risk
management. Journal Of Government Financial Management, 12-18.
Susanato, A. (2017). The influence of business process and risk management on the quality of accounting
information system. International journal of Scientific & Technology Research , 6(9).
U.S. Securities and Exchange Commission. (2009, December 16). Retrieved from SEC Approves Enhanced
Disclosure About Risk, Compensation and Corporate Governance:
https://www.sec.gov/news/press/2009/2009-268.htm
Viscelli, T. R., Beasley, M. S., & Hermanson, D. R. (2016). Research insights about risk governance:
Implications from a review of ERM research. Sage. doi:10.1177/21582440I6680230
RISK MANAGEMENT
10