The Committee of Sponsoring Organizations of the Treadway Commission, or more commonly known as COSO, released a report this month on how companies can derive the most benefit from their Enterprise Risk Management (ERM) programs. Authored by two professors and risk practitioners from DePaul University, the report provides approaches and action steps for companies to follow as they embark on their ERM journey. Here is a summary list of key activities to bolster the ongoing implementation of an effective ERM program.
- A program of continuing ERM education for directors and executives
- ERM education and training for business-unit management
- Policies and action plans to embed ERM processes into the organization’s functional units such as procurement, IT,or supply chain units
- Continuing communications across the organization on risk and risk management processes and expectations
- Development and communication of a risk management philosophy for the organization
- Identification of targeted benefits to be achieved by the next step of ERM deployment
- Development of board and corporate policies and practices for ERM
- Further discussion and articulation of a risk appetite for the organization and /or significant business units, including quantification
- Establishment of clear linkage between strategic planning and risk management
- Integration of risk management processes into an organization’s annual planning and budgeting processes
- Expansion of the risk assessment process to include assessments of both inherent and residual levels of risk
- Exploration of the need for a dedicated Chief Risk Officer or ERM functional unit


