Organizational Aspects of Enterprise Risk Management
摘要
For successful implementation, enterprise risk management (ERM) must be well organized. That means that specific ERM tasks in the operational ERM process must be assigned to specific positions in a firm and organized into a specific process over time. The idea of ERM organization is closely related to the theoretical concept of risk governance, which aims to solve agency problems resulting from ERM. Depending on the regulatory requirements, size, and complexity of a firm, the relevant ERM actors (which include risk owners, risk managers, and management accountants) and approaches for implementing ERM vary. A firm’s risk managers can take on different roles, such as compliance champions or business partners, depending on the main ERM relations of the firm. Especially in larger companies, many different functions are involved in ERM. The three lines (of defense) model can be used for an efficient and effective task sharing of these functions. Overall, ERM implementation can achieve different maturity levels in corporate practice.