Chapter 06 · Governance & regulationGovernance, Ethics & Risk
Enterprise risk management (ERM)
Definition
Enterprise risk management is an organisation-wide approach to identifying, assessing, managing and monitoring risks in relation to objectives.
References
This reference provides supporting context for how “Enterprise risk management (ERM)” is defined and used.
Overview
What it means in practice
Enterprise risk management (ERM) should be read as a governance, ethics and risk term. Its meaning depends on the role, authority, control, legal context and decision being assessed.
In practice, users should state the boundary, actor, evidence and decision context. That keeps enterprise risk management (erm) specific enough for review without turning it into a generic assurance claim.
Why it matters
Enterprise risk management (ERM) matters because governance language determines who is accountable, what is controlled and how risks are escalated. Clear definitions reduce the chance that responsibility is implied but not operational.
Common misconception
A common error is to treat Enterprise risk management (ERM) as proof that governance is effective. The stronger approach is to state the owner, mandate, control, evidence and limits of authority.
Review questions
Who is responsible, and who is affected? What evidence supports the term? What limitation, authority or remedy would change how a reader interprets it?
How it is used
The term appears in legislation, policies, governance systems, contracts, oversight and compliance decisions, where policymakers, regulators, legal teams, boards and organisations use it to classify, assess or communicate an organisation-wide approach to identifying, assessing, managing and monitoring risks in relation to objectives.
Its correct use depends on the applicable jurisdiction, legal or policy text, effective date, scope and responsible actor.