Enterprise Risk Management (ERM) is a structured, organisation-wide approach to identifying, assessing, prioritising, and mitigating risks that could affect an entity’s objectives. It integrates financial, operational, strategic, compliance, and reputational risk into a single governance framework with defined ownership and reporting. Established frameworks such as COSO ERM and ISO 31000 provide the reference models.
Content
- ERM aggregates disparate risk types into a unified register with clear ownership, tolerance thresholds, and board-level reporting. Standards such as COSO ERM and ISO 31000 codify the process from risk identification through monitoring.