EROM Chapter 4, Part 3: Drivers, Responses, Enterprise Roll-Up, and Portfolio Planning

Book: Enterprise Risk and Opportunity Management: Concepts and Step-by-Step Examples for Pioneering Scientific and Technical Organizations
Author: Allan S. Benjamin
ISBN: 9781119288428

The final third of Chapter 4 closes the loop: find what actually drives cumulative risk, propose mitigations and controls, compress results for executives, scale the process enterprise-wide, and reuse the same templates for early portfolio decisions. This is where EROM stops being an analysis exercise and starts steering resource choices.

Driver identification: what actually moves the needle

Table 4.14 implements the driver logic from section 3.6. For each top objective you test candidate scenario drivers by asking: if we remove this scenario (or combination), does the cumulative color change?

For strategic objective E(>10) #1 (discover how the universe works), cumulative known risk is yellow. Testing candidates:

  • Cryocooler delivery delay alone: stays yellow. Not a driver by itself.
  • Expert staff unavailability for review alone: stays yellow. Not a driver alone.
  • Both together: drops to green (tolerable). Combined scenario driver.

Constituent drivers under that combination include cryo schedule reserve, subcontractor management issues, brazed compressor performance, thermal vacuum testing of the cold head assembly, and cross-project competition for qualified review personnel. Each gets a “time to begin response” (mostly “now”) and “time to complete response” (6 months for the risk bundle).

On the opportunity side, the servicing retrofit scenario is a driver: remove it and cumulative opportunity falls from blue (significant) to beige (insignificant). Constituents include IR camera TRL, SLS/Orion docking readiness, predicted P(LOC), rendezvous cost, and congressional risk to other SLS/Orion missions.

Figures 4.13 and 4.14 turn these into matrix displays for executive briefings: scenario drivers vs. time criticality, then constituent drivers vs. time criticality.

Likelihood and impact templates

Table 4.15 applies the Chapter 3 ranking scales to individual scenarios for OMB A-123 reporting. Likelihood is high/medium/low relative to watch and response boundaries. Impact is high if the scenario sits in a driver and cumulative risk is red (or opportunity is blue), medium if marginal colors, low if not in any driver.

This connects federal compliance reporting to the EROM roll-up instead of treating likelihood and impact as standalone gut calls.

Mitigation, action, and internal control templates

Tables 4.16 and 4.17 start from driver constituents and propose responses plus controls.

Risk mitigation examples (hypothetical, for illustration):

ConstituentMitigationInternal control
Cryo schedule reserveBorrow personnel from Task X; approve overtime if neededMonitor Task X reserves; assign authority to shift staff
Subcontractor managementStrengthen sub team; increase oversightAcquirer concurrence on sub choices; penalties for underperformance; action item tracking
Brazed compressor performanceAdd modified brazing testsEscalation process for test facility allocation
Cold head thermal vac testAdd test with replacement valvesSame facility allocation control
Review personnel competitionEstablish project review priorityManager with authority over competing projects assigns staff

Opportunity action examples:

  • Increase priority of IR camera R&D (with TRL tracking protocol)
  • Increase SLS/Orion priority for retrofit mission (with launch-quality controls to build public support)
  • Factor economic trends into upgrade planning
  • For introduced risks you cannot mitigate directly, controls protect assumptions (rigorous PRA funding, UU reserves for P(LOC) and cost estimates, congressional education on SLS/Orion benefits)

Each control is tagged Assumption (protecting a premise behind the mitigation) or Deficiency (fixing a gap in current oversight). That distinction matters for auditors and for the Chapter 10 internal control integration Benjamin promises later.

Table 4.18 compresses everything into a high-level display suitable for a decision briefing: objective, cumulative risk/opportunity colors, drivers, proposed responses, and key controls on one view.

Scaling up: upward propagation and databases

Section 4.8 confronts scale honestly. The JWST demo uses 12 objectives. NASA’s 2014 Strategic Plan and 2015 Performance Plan listed 15 strategic objectives and hundreds of mid- and short-term performance goals. Full-scope EROM is a volume problem.

The solution is bottom-up template propagation:

  1. Every organizational unit builds its own objectives hierarchy, scenarios, indicators, and completed templates.
  2. Units pass templates upward. Each higher level compiles subordinate inputs into its own set.
  3. Vertical and horizontal communication stays open so interfaces stay consistent.
  4. The enterprise-wide level resolves assumption conflicts, interface disagreements, and conclusion mismatches.
  5. Completed enterprise templates flow back down for assent or dissent.

Figure 4.15 sketches this upward flow. Same format everywhere is non-negotiable. Creativity belongs in scenario identification, not in spreadsheet layout.

The templates feed an integrated EROM database at directorate, center, executive, and enterprise levels. Beyond raw risk/opportunity data, the database should track owners, involved entities, working groups, management boards, change plans, history, and status. That structure is what makes cross-cutting risks analyzable at portfolio scale instead of trapped in siloed registers.

Benjamin flags database challenges for extended enterprises with external partners. Later chapters return to best practices.

Portfolio planning: same templates, different inputs

Section 4.9 is easy to overlook but strategically important. The identical template set works for organizational planning when programs are still conceptual. What changes is the input source:

  • Risks, opportunities, indicators, and triggers come from historical analogs and expert judgment, not live program data.
  • Short-term objectives (≤1 year) usually drop out because milestones assume a defined design that does not exist yet.

If JWST were still a concept in the 1990s, the cryocooler-specific risks in Table 4.2 would not appear. You would not know the subsystem design. Cost and schedule reserve indicators would be inferred from Hubble experience and anticipated mission complexity, not GAO’s 2014 cryocooler tracking.

Table 4.19 shows the modified risk roll-up for that planning-mode case: cryocooler short-term rows gone, reserve indicators based on Hubble precedent (highlighted in the book). Other templates adjust the same way.

That means a agency can compare candidate portfolios (build JWST vs. accelerate Hubble upgrades vs. split funding across three medium missions) using the same cumulative risk/opportunity language before committing billions. Performance evaluation and strategic planning share one analytic grammar.

Closing thought

Chapter 4 is the longest in the book for good reason. It is the reference implementation. The JWST cryocooler thread alone teaches three things every TRIO risk manager should internalize: indicators need documented triggers, roll-up needs written rationale, and drivers emerge from combinations not singletons.

If you are implementing EROM, you will live in these templates. If you are auditing or overseeing a TRIO enterprise, ask whether the organization can produce Tables 4.7, 4.14, and 4.16 for its top objectives on demand. That is the difference between EROM as a framework slide and EROM as an operating system.


← Previous: EROM Chapter 4, Templates Part 2 · Next: EROM Chapter 5, Technical Centers →