Pivot Point Insights  |  Enterprise Risk Management

A New Look at How Enterprise Risk Management
Can Get You Home for Dinner

We see our email boxes filling up, our calendars overrun with meetings, and we struggle to manage all of the demands on our time. It is difficult to focus on the vital few when there is a constant barrage of urgent issues competing for your attention. Even on days when you answer dozens of emails and make countless decisions, you still feel like you have not moved the needle.

You begin to realize that you need an organizing principle — one that aligns you and your company around what is critically important. A well-run Enterprise Risk Management (ERM) program provides this clarity and ensures that you have the focus necessary to move your company, business unit, department, or simply yourself forward in the most effective way.

When evaluating your ERM, it should be understood that this is not a legal or compliance exercise. This is a strategic process that should align your budgets, staffing matrices, and, at its core, how you and everyone else in the company allots their time.

You have heard the adage: if everything is important, then nothing is important. We need data and math to help determine how we are going to organize ourselves.

"The essence of mathematics is not to make simple things complicated, but to make complicated things simple."

— S. Gudder

The Four Categories of Risk

When we have completed the data exercise, our risks and opportunities will be divided into four categories. This division creates the alignment of budget, time, and overall resources. We achieve this alignment by identifying at what level team members will be tasked with understanding what is occurring, and to what level of detail.

ERM Risk Classification Matrix — four quadrants: Improve, Monitor, Operate, Tolerate
Figure 1 — ERM Risk Classification Matrix. Risks are plotted against probability and severity to determine the appropriate organizational response. The formula P × (S + V) = Risk drives placement.

The organization's focus should be on items in the Improve category, which should receive resources, budget, and the attention of the most senior leaders. The management team should track and remain aware of what falls into both the Improve and Monitor categories — though not with equal weight. Items in the Monitor category are the likely risks that could derail the organization in the future and warrant a watchful eye.

Individual subject matter practitioners and departments should maintain awareness of all four risk types, but again not equally. Their calendars, hiring decisions, budgets, and overall attention should be scaled based on the seriousness of the risk. Items in the Operate and Tolerate categories do not require the same focus — and that is precisely the point.


Aligning the Organization by Level

You want the board and audit committee to be briefed on the most critical issues you are working on, but they do not need to crowd their agenda with a review of nascent risks — the items that fall into the Operate category. More importantly, this structure drives the time and focus at each level of the organization. Your goal is to prevent the loudest person or group from dominating your executives' agenda with an issue that the data says should be in the Tolerate category.

Organizational Risk Focus by Level — Board, Management, Practitioners
Figure 2 — Organizational Risk Focus by Level. ERM attention and resource allocation scale with risk severity and organizational role. The Board focuses on Improve; Management tracks Improve and Monitor; Practitioners maintain awareness across all four categories.

If the organization is planning a new product launch, significant M&A activity, or a push into a new geography, potential risks and opportunities should be brought forward and weighted to ensure they receive the necessary attention as part of the larger business plan. It is a significant mistake to confine your cybersecurity risks and legal exposure to your ERM in isolation. It would be a missed opportunity to create alignment on where the organization is headed overall.

The ERM Formula

Applying the Math

Once we have organized our data, we can apply the math. The equation for ERM continues to evolve, but the best formula is:

Risk Equation Probability × (Severity + Velocity) = Risk

Although mathematical, there is a subjective element: each organization must decide how to distribute points and weighting to each variable. The scales below represent one such framework — each organization must decide how best to capture and reflect its own risk profile.

Severity Rating Scale

Estimated total impact of risk on the business — including out-of-pocket costs (fines, penalties), soft costs (brand damage, reputational effects, employee distraction), and lost sales.

Score 1 2 3 4 5
Impact Level No cost to business; no operational impact Total cost = 1–3% of annual sales and/or limited operational impact Total cost = 3–5% of annual sales and/or some damage at customer/partner level Total cost = 5–10% of annual sales and/or severe impact on business performance Total cost >10% of annual sales and/or catastrophic impact on business performance

Probability Rating Scale

Estimated likelihood that the risk will occur within the calendar year.

Score 1 2 3 4 5
Likelihood < 5% 5–15% 15–50% 50–90% > 90%

Velocity Rating Scale

How quickly the risk's severity will be experienced by the organization after the risk event occurs.

Score 1 2 3 4 5
Speed of Impact Severity experienced slowly over 3+ years after occurrence Severity experienced within 1–3 years after occurrence Severity experienced within the next year after occurrence Severity experienced within 6 months after occurrence Severity experienced very rapidly after occurrence, with little or no warning — near-instantaneous

Maintaining a Rigorous Risk Registry

It is very important that your organization continues to analyze its ERM on an ongoing basis. If done appropriately, those risks in the Improve category should not dramatically change from quarter to quarter. Change that happens too frequently would whipsaw an organization and make focus and planning impossible. That said, the organization should always be challenging its assumptions.

In order to maintain a good registry of risks, we recommend that the group administering the risk process look both internally and externally to develop a tight Quarterly Risk Profile. Specifically, we recommend they do the following three things:

1

Quarterly interviews of functional leads — HR, IT, legal, internal audit, and others — to determine what they are seeing as the top risks from within their domains.

2

Scout externally at conferences and in white papers for risks that other organizations are noting, particularly those in adjacent industries or similar regulatory environments.

3

Evaluate whether new risks affecting a single group warrant testing across the broader team — a risk that appears isolated may signal a systemic vulnerability.

The Quarterly Risk Profile should be a tight document — likely no greater than five pages in length — distributed to the management team or business unit, depending on the size of your organization. Your organization should consider the risks quarterly at its management team meeting and then assign points to determine if one of the new risks should fall within the matrix. This should be considered very carefully, as any additions or subtractions should lead to discussions of budget dollars, human resources, and the organization's time.


Through determined focus on a rigorous ERM, a company can benefit from the ability to respond thoughtfully to risks as they present themselves. But it should also be able to alleviate the burden on emails, calendars, and agendas — items in the Tolerate or Operate categories do not require the same focus and attention. By decluttering the organizational landscape, you are naturally creating discipline that will ultimately lead to a more responsive and dynamic company.

And more importantly — it will get you home in time for dinner.


1 The group that should administer the ERM process is out of scope for the purposes of this article, but an organization should carefully consider who is responsible, as that decision sends a significant signal as to the importance of the overall process.

This publication is for informational purposes only and does not constitute legal advice. No reader should act, or refrain from acting, with respect to any particular legal matter on the basis of this publication without seeking counsel in the relevant jurisdiction.

About the Author

Daniel Garen, JD, LLM

Founder & Principal · Pivot Point Compliance Management

More than 25 years building, transforming, and defending compliance programs across life sciences, financial services, and technology. Former Chief Compliance Officer for Siemens Healthcare, Wright Medical (Warburg Pincus), and Vivint Smart Home (Blackstone). 10 government enforcement matters resolved with a 100% resolution rate across FDA, DOJ, OIG-HHS, FTC, and SEC. Runner-Up, Innovative Lawyer of the Year — Financial Times, 2020. Admitted to practice before the U.S. Supreme Court.

Ready to build a program
that actually works?

Let's start with a conversation about where you are and where you need to be.

Schedule a Conversation →