ERM Implementation: The 5-Stage Maturity Model (Chapter 21)
Book: Enterprise Risk Management: From Incentives to Controls
Author: James Lam
ISBN: 978-1-118-41361-6
Chapter 21 is where the book shifts from theory to action. Confucius said knowledge is useless if you don’t use it. Lam agrees. This chapter is about turning ERM concepts into real programs.
The GE Capital Story
Lam’s defining ERM moment happened at GE Capital Markets Services in 1993. He was hired as CRO during an aggressive startup phase. He spent months building the hard side: policies, limits, models, systems, and reporting.
The traders didn’t cooperate. They’d never worked in a controlled environment. They entered only 80-90% of their trades. Morning risk reports were full of errors.
When Lam confronted the head trader, the response was blunt: “We know our portfolio. We don’t need your system. We’ll enter trades when we have free time.”
Lam told the group president he couldn’t do his job without trader cooperation. The president’s response changed everything. He shut down all business operations for two days. Every employee went through a risk management boot camp at GE’s Crotonville training center. They reviewed every ERM policy, why it existed, and who was accountable.
The president’s message was clear: we run this business in a risk-controlled environment. If traders don’t change, we change the traders.
After that, compliance hit 100%. The group captured 25% market share with zero policy violations. Lam won GE’s Pinnacle award. The lesson: you need both the hard side (systems, policies) and the soft side (culture, tone from the top).
Why ERM Pays Off
Lam cites research showing better governance and ERM link to better financial results:
- McKinsey (2002): 60% of institutional investors avoid companies with poor governance. Investors pay a 12-30% premium for well-governed firms.
- Brown & Caylor (2004): Companies in the top governance percentile earned 7.91% higher returns than industry averages. Board composition was the single biggest factor.
- Hoyt & Liebenberg (2009): ERM programs at insurers were associated with a 16.5% equity premium and lower return volatility.
- S&P (2010): During the 2008 crisis, insurers with “excellent” ERM scores lost 30% in stock value vs. 60% for “weak” ERM firms. In 2009, excellent firms gained 10% while weak firms lost 10%.
Four Building Blocks
ERM implementation rests on four questions:
- Governance (Who?) Who provides risk oversight and makes critical decisions?
- Risk Assessment (How ex-ante?) What analytical input supports those decisions?
- Risk Management (What?) What specific decisions shape the risk/return profile?
- Reporting & Monitoring (How ex-post?) How does the company track results and create feedback loops?
Updated Definitions
- Risk: A variable that can cause deviation from expected outcomes and affect business objectives.
- ERM: An integrated process for managing enterprise-wide risks (strategic, financial, operational, compliance, reputational) to maximize firm value.
Governance Details
Board risk committees, ERM policies, and risk-compensation linkage are key. Compensation systems are one of the most powerful levers for risk culture. If bonuses depend on short-term earnings or stock price, executives will take excessive risks. Fix this with long-term risk-adjusted metrics, vesting schedules matched to risk duration, and claw-back provisions for tail losses.
Risk Assessment Pitfalls
Major risk events usually come from a confluence of interrelated risks, not one isolated problem. Companies must integrate market, credit, and operational risk analyses. And they must stress-test model assumptions. Correlations approach one during market stress. Diversification benefits disappear when you need them most.
Risk Management Role
Business units make most risk decisions. The risk function supports them with analytics and provides independent assessment. A common solution: solid reporting line from CRO to CEO, dotted line to the board. Under extreme circumstances (fraud, excessive risk taking), the dotted line becomes solid so the CRO can escalate without fear.
Reporting Feedback Loops
“What gets measured gets managed.” But boards are often unhappy with risk reports. Too qualitative or too quantitative. Too focused on past trends.
Lam’s example: earnings-at-risk analysis at the start of a period identifies key drivers (business targets, interest rates, oil prices) that could cause a $1/share loss vs. $3 expected earnings. At period end, earnings attribution shows what actually happened. Over time, the goal is to shrink the gap from unforeseen factors.
The ERM Maturity Model
ERM is a multi-year journey. Lam’s five-stage model helps companies figure out where they are and where they’re going:
Stage 1: Definition and Planning (White Belt), ~20% of companies
6-12 months. Research requirements, brief the board, appoint a CRO, form a task force, benchmark peers, assess current capabilities, define scope and vision, build a risk taxonomy.
Stage 2: Early Development (Yellow Belt), ~40% of companies
1-2 years. Write the ERM policy (the most important step), perform annual risk assessments, coordinate risk/audit/compliance, train the board and employees, establish risk functions in business units.
A standard ERM policy includes: executive summary, risk philosophy, governance structure, risk tolerance levels, ERM framework/processes, and risk categories/definitions.
Stage 3: Standard Practice (Green Belt), ~20% of companies
1-3 years. Quarterly/monthly risk assessments, loss-event databases, KRIs with monthly enterprise reporting, integrated credit/market/operational models, risk-adjusted performance measurement.
Stage 4: Business Integration (Brown Belt), ~15% of companies
2-4 years. Economic capital allocation, cost of risk in pricing, risk reviews in new business approval, automated dashboards, trigger points for timely decisions, feedback loops, risk-compensation linkage.
Stage 5: Business Optimization (Black Belt), ~5% of companies
Ongoing. Strategic risk in ERM, ERM in strategic planning, resource allocation at the efficient frontier, risk transparency to stakeholders, helping customers manage their risks.
Other Maturity Models
McKinsey has a four-stage model (initial transparency → systemic risk reduction → competitive with industry → risk-adjusted performance focus). Deloitte has five stages (reactive planning → siloed → comprehensive → integrated → optimized).
Risk Culture
Lam gets asked about good vs. bad risk culture all the time. His answer:
- Typical culture: People do the right thing when policies and controls are in place.
- Good culture: People do the right thing even when policies and controls are NOT in place.
- Bad culture: People don’t do the right thing regardless of policies and controls.
The 2008 crisis was largely a culture failure. Investment banks went from private partnerships (where partners’ capital was on the line) to public companies (where shareholders bore the losses).
Assess culture through: tone from the top, risk awareness, incentive alignment, change management, and communication/escalation practices.
What’s Next
Chapters 22 through 25 drill into each building block: the board’s role, risk assessment, risk-based decision making, and dashboard reporting.
Previous: Everlast Financial Case Study | Next: Board Role in ERM