ERM Objective:
Hold risk owners accountable to manage their risks.
The Trap:
Confusing risk assessment with managing risk is common. When we set strategic plans we establish measurable targets. However, when we identify risks the mandate is often simply to “manage the risk”.
The Solution:
Essentials for risk management accountability:
- Describe with great clarity what each risk looks like when it is properly managed (we rarely eliminate risks, so what does the successfully managed risk look like
- Don’t ask risk owners to “manage” risks that are already within tolerances, they will not understand what they are supposed to do (see Challenge #8)
- Management MUST review risk response status reports with the same frequency that they review corporate performance
- Corporate risk responses should have board visibility quarterly
No comments:
Post a Comment