We see our email boxes filling up, our calendars overrun with meetings, and we struggle to manage all of the demands on our time. It is difficult to focus on the vital few when there is a constant barrage of urgent issues competing for your attention. Even on days when you answer dozens of emails and make countless decisions, you still feel like you have not moved the needle.
You begin to realize that you need an organizing principle — one that aligns you and your company around what is critically important. A well-run Enterprise Risk Management (ERM) program provides this clarity and ensures that you have the focus necessary to move your company, business unit, department, or simply yourself forward in the most effective way.
When evaluating your ERM, it should be understood that this is not a legal or compliance exercise. This is a strategic process that should align your budgets, staffing matrices, and, at its core, how you and everyone else in the company allots their time.
You have heard the adage: if everything is important, then nothing is important. We need data and math to help determine how we are going to organize ourselves.
"The essence of mathematics is not to make simple things complicated, but to make complicated things simple."
— S. GudderThe Four Categories of Risk
When we have completed the data exercise, our risks and opportunities will be divided into four categories. This division creates the alignment of budget, time, and overall resources. We achieve this alignment by identifying at what level team members will be tasked with understanding what is occurring, and to what level of detail.
The organization's focus should be on items in the Improve category, which should receive resources, budget, and the attention of the most senior leaders. The management team should track and remain aware of what falls into both the Improve and Monitor categories — though not with equal weight. Items in the Monitor category are the likely risks that could derail the organization in the future and warrant a watchful eye.
Individual subject matter practitioners and departments should maintain awareness of all four risk types, but again not equally. Their calendars, hiring decisions, budgets, and overall attention should be scaled based on the seriousness of the risk. Items in the Operate and Tolerate categories do not require the same focus — and that is precisely the point.
Aligning the Organization by Level
You want the board and audit committee to be briefed on the most critical issues you are working on, but they do not need to crowd their agenda with a review of nascent risks — the items that fall into the Operate category. More importantly, this structure drives the time and focus at each level of the organization. Your goal is to prevent the loudest person or group from dominating your executives' agenda with an issue that the data says should be in the Tolerate category.
If the organization is planning a new product launch, significant M&A activity, or a push into a new geography, potential risks and opportunities should be brought forward and weighted to ensure they receive the necessary attention as part of the larger business plan. It is a significant mistake to confine your cybersecurity risks and legal exposure to your ERM in isolation. It would be a missed opportunity to create alignment on where the organization is headed overall.