EROM Chapter 3, Part 2: Scenarios, Leading Indicators, and Response Options
Book: Enterprise Risk and Opportunity Management: Concepts and Step-by-Step Examples for Pioneering Scientific and Technical Organizations
Author: Allan S. Benjamin
ISBN: 9781119288428
The second half of Chapter 3 walks through the analysis pipeline in detail: writing scenarios, picking indicators, setting triggers, rolling up cumulative risk, finding drivers, and choosing responses. It ends with a frank comparison to COSO and the GAO Green Book. This is the chapter where theory becomes procedure.
Scenarios: the grammar of risk and opportunity
Once tolerances are set, the EROM team develops scenario statements and leading indicators for every entity in the objectives hierarchy. Lower levels assign scenarios from experience and expert judgment. Higher levels add scenarios rolled up from below.
NASA’s risk scenario format (which Benjamin adopts) has four core elements plus a fifth for planning:
- Condition: the fact-based situation causing concern.
- Departure event: a possible change from the baseline plan.
- Entity (optional): primary resources affected.
- Consequence: credible negative impacts on performance.
- Affected objective(s): where in the hierarchy the hit lands.
Opportunity scenarios add an action (required to realize the gain) and a benefit instead of a consequence. The action element is not optional for opportunities. You cannot separate “something good might happen” from “we would need to do X to capture it.”
Each scenario also gets a narrative field: context, contributing factors, uncertainties, consequence ranges, and recommended responses from the identifier. The person who spots the issue often has the best fix. Capture that expertise before it walks out the door.
Benjamin provides a three-level taxonomy (mission type, event type, specific category) to help teams brainstorm scenarios they would otherwise miss and to spot cross-cutting issues.
Leading indicators: what to watch
Leading indicators infer whether objectives will succeed on time. During planning they help pick among candidate goals. During evaluation they show whether projections still hold.
Good indicators need three properties:
- Quantifiability: measurable status.
- Correlatability: direct link to objective success likelihood.
- Actionability: at least some indicators can be influenced when concern rises.
Lagging indicators count too. Past missed milestones predict future misses. Table 3.1 in the book maps indicator examples across categories like new technology, mandated performance, financial, workforce, legal/reputational, and partnerships, with internal vs. external sources noted.
Indicators get watch triggers and response triggers, mirroring the tolerance boundaries from section 3.3. They can be positively or negatively correlated with risk (remaining cost reserve moves opposite to expenditure-to-date). Figure 3.8 in the book shows the mirror-image logic.
Unknown and underappreciated (UU) risks
Known scenarios do not cover everything. Benjamin treats UU risk factors as leading indicators in their own right. The big ones:
- System complexity and tight coupling at interfaces
- Scaling beyond validated domain knowledge
- Fundamentally new technology or new application of existing tech
- Management priorities that shortchange safety and reliability
- Hierarchical management that blocks two-way information flow
- Weak oversight across distributed suppliers
- Schedule and budget pressure beyond comfort levels
- Major external events (administration changes, geopolitical shocks)
Table 3.2 gives rough ratios of UU failure probability to known failure probability at initial operation, calibrated against launch vehicle history. A well-managed, mildly pressured program might see a ratio near 1. Extreme pressure with hierarchical management and novel tech can push the ratio toward 9. These are order-of-magnitude guides, not precision forecasts, but they tell you when UU exposure deserves a separate roll-up track.
Cumulative risk and finding drivers
Cumulative risk for an objective accumulates all relevant leading indicator statuses (value plus trend). The roll-up logic is the heart of EROM.
When cumulative risk goes intolerable or cumulative opportunity goes significant, you look for drivers: the elements that flip the color from green to yellow or red. A driver might be a departure event, an underlying cause, a leading indicator, an unprotected assumption, or a missing internal control. Combinations count. Remove one driver at a time through the roll-up process and see if the top objective changes color.
Scenario drivers are the higher-level version: whole scenarios whose removal changes the cumulative picture. Federal agencies must report top risk scenarios under OMB Circulars A-11 and A-123 anyway. EROM ties that reporting to the objectives hierarchy instead of treating it as a standalone compliance exercise.
Likelihood, impact, and response options
OMB A-123 wants high/medium/low likelihood and impact. Benjamin argues that generic likelihood language works for fraud and routine schedule slips but not for mission-critical TRIO work. Better to define likelihood relative to the decision maker’s watch and response boundaries. If tolerance for critical mission loss is 1 in 100, a scenario at that level is “high.”
Impact ties to whether the scenario appears in a scenario driver and what color the cumulative risk/opportunity shows at the top.
Response options span design changes, retrofits, procedure updates, management changes, partnerships, and outreach to funding authorities. Every option rests on assumptions. Internal controls exist largely to keep those assumptions valid. Leveson’s safety-focused list (hazard paths, control effectiveness, operational context, development environment, organizational control structure) generalizes across cost, schedule, acquisition, and institutional domains.
Evaluating options means re-running the full pipeline with modified scenarios, indicators, and triggers until cumulative risk, opportunity, and implementation cost balance.
How this differs from COSO
Section 3.6.6 is worth reading twice. COSO treats internal control as an input to ERM but not necessarily an output. COSO internal control focuses on operations, reporting, and compliance objectives, not strategic ones. COSO does not require a portfolio view of risk or opportunity identification.
Benjamin’s position: EROM and internal controls are fully integrated. Strategic risks drive control design. Controls protect the assumptions behind risk drivers.
The GAO Green Book sits in the middle: it folds strategic objectives into operational objectives, so integration is tighter than COSO but still emphasizes day-to-day fraud and transparency. OMB A-123 asks agencies to start with COSO’s operational focus and mature toward strategic integration over time.
For TRIO enterprises whose missions can fail catastrophically, Benjamin’s integrated model is the one that matches the stakes.
← Previous: EROM Chapter 3, Process Overview Part 1 · Next: EROM Chapter 4, Templates Part 1 →