Enterprise Risk Assessment: A Practical Guide (Chapter 23)
Book: Enterprise Risk Management: From Incentives to Controls
Author: James Lam
ISBN: 978-1-118-41361-6
Chapter 23 is the how-to guide for risk assessment. Not every risk can be modeled. Risk assessments fill the gap by identifying, quantifying, and prioritizing key risks so the board and management can make better decisions.
A 2013 KPMG survey of 1,000 C-level executives found 80% perform some form of risk assessment. But only 34% align assessments across all risk and control functions to build a complete risk profile.
Seven Steps of a Risk Assessment
- Establish business context (objectives, regulations)
- Identify key risks (positive or negative impact on objectives)
- Evaluate probability and severity
- Evaluate control effectiveness
- Determine risk management strategies and action plans
- Prioritize top risks for deeper analysis
- Provide ongoing reporting and monitoring
Four Phases
Phase 1: Foundation Setting
Get executive sponsorship first. Without a CEO, CFO, or CRO backing the process, business managers won’t give candid input.
Alliant Energy example: Chief Audit Officer Joel Schmidt runs annual risk assessments plus monthly outlook discussions with the VP of Strategy and Risk and the board (roughly eight times per year). Risk assessment becomes the basis for operations.
Key roles: project sponsor, project manager, subject matter experts, trained facilitator, risk analysts.
Build a risk taxonomy with standard categories (strategic, business, financial, operational, legal/compliance) and clear definitions of probability, severity, and tolerance levels.
Tools matter. Senior executives think in stories, not templates. Use open-ended interview questions for them. Use structured workshops for business units.
Common pitfalls:
- No senior management participation
- Too few resources (superficial assessments) or too many (one bank used 20+ staff for nine months and produced thick binders nobody read)
- Insufficient preparation and training
Phase 2: Risk Identification, Assessment, and Prioritization
Deliverables: top-down assessments from executives, bottom-up assessments from business units, risk maps, and a prioritized top-10 enterprise risks.
Rating scales (examples from the book):
Probability: Very Low (<5%), Low (5-20%), Medium (20-50%), High (50-95%), Very High (>95%) within one year.
Severity: Very Low (immaterial) through Very High (very significant impact on reputation, earnings, or objectives).
Control Effectiveness: Highly Effective (within tolerances, tested, performance-based metrics) through Needs Significant Improvement (major exceptions, no controls).
Root causes vs. consequences: Define risks by root cause, not outcome. You can’t directly control “production errors” but you can improve automation and training. You can’t control your debt rating but you can manage equity levels.
Prioritization: One asset management firm identified 700+ risks. The board can’t review 700 risks. Pick a top-10 for enterprise focus. Business units can track their own granular lists.
Phase 3: Deep Dives, Quantification, and Management
For the top-10 risks, go deeper: more granular assessments, external benchmarking, process maps, independent auditor input, control testing.
Set risk tolerance levels and track KRIs against them.
Develop risk management strategies (avoid, mitigate, transfer, accept) with clear action plans and accountabilities. Risk acceptance must include pricing the cost of risk into products and services.
Total cost of risk = expected loss + unexpected loss (economic capital) + transfer costs + administrative costs.
Common pitfalls:
- No prioritization (trying to build KRIs for everything)
- All qualitative, no quantification
- Reports that sit on shelves until the next cycle
Phase 4: Business and ERM Integration
Risk assessment shouldn’t be a standalone annual exercise. Integrate it into:
- Strategic planning (business objectives drive assessments; assessments inform strategy tradeoffs)
- Business processes (pricing, new products, M&A, project management, capital allocation)
- Operations (process maps showing where risks and losses occur)
- Scenario analysis and stress testing (multiple simultaneous risk events, not just single risks)
- Dashboard reporting (integrated performance and risk views)
- Loss/event databases (capture every material loss for post-mortems and trend analysis)
- Risk escalation policies (explicit triggers and notification criteria so bad news travels up)
Common pitfalls:
- Integration only in back-end reporting, not front-end planning
- No change management agenda
Best Practice Examples
Bank of America built a SharePoint-based risk assessment system with multi-level access. Employees enter risk data that aggregates into senior management reports.
Global Risk Report (World Economic Forum): Since 2004, 580 experts collaborate annually. The 2011 report integrated diverse opinions into “Core Global Risks” with severity/likelihood diagrams and interconnection maps. The 2007 report flagged “blow up in asset prices/excessive indebtedness” before the 2008 housing crisis.
Self-Evaluation Checklist
Lam provides a two-dimensional self-assessment:
- Development and maturity of risk assessment standards
- Integration and application of results into business decisions
Score each dimension 10-50. Plot on a matrix:
- Beginners: Low on both. Opportunity to build foundations.
- Intellectuals: High maturity, low integration. Great tools but disconnected from business. Focus on integration.
- Expedients: High integration, low maturity. Practical but reinventing the wheel each cycle. Focus on standardization.
- Advanced Practitioners: High on both. Keep updating best practices.
The Bottom Line
Risk assessment only creates value when it leads to action. Executive sponsorship, consistent standards, top-10 prioritization, quantification, and integration with strategy and operations are what separate useful assessments from compliance theater.
Previous: Board Role in ERM | Next: Risk-Based Decision Making