The Compelling Case for an ERM Mission Statement
Summary
• Enable the timely flow of risk information to all company stakeholders • Gain support from organizational leadership (people with a true and holistic view of company) since those individuals are the key decision-makers who establish budgets and allocate resources. “Enterprise Risk Management (ERM) is the process to identify, assess, mitigate and monitor all enterprise-wide risks that might impair the company’s ability to achieve its strategic business objectives.” Every word matters in this ERM mission statement. Specially, the ultimate goals of the ERM mission statement are to: • ensure ERM is given its full importance within the organization, not perceived as an adjunct to other corporate functions, like Compliance or Internal Audit • establish ERM as a pragmatic and usable regimen, not some stand-alone, academic hypothesis, to realize its maximum impact • pinpoint the risk register – covering the universe of all enterprise-wide risks – as the centerpiece and starting point of all ERM activity • underline the iterative, four-step tactical execution process (identification, assessment, mitigation and monitoring) associated with ERM and that company risk register universe • meld together the ultimate strategic importance of ERM in ensuring that the attainment of key high-level company objectives (e.g. earnings performance, capital adequacy, liquidity, reputation) are best promoted Quite simply, the engine that drives a powerful ERM mission statement is the risk register. Toward that end, ERM One™ is a revolutionary, yet straightforward, risk register application the DoubleCheck LLC has, over time, been privileged to learn from its clients. ERM One™ is out-of-the-box tool that delivers an integrated ERM process together with a comprehensive, high-level categorization of exposures (Financial, Core Business, Operational and Strategic), fully loaded with over 60 pre-populated risks to be used as a starting point for the risk register.