Why ERM degenerates into reporting
The typical path: a register of 100-200 risks, a colored probability-impact map, a quarterly committee. A year on, one specialist updates the register, executives sign without reading, and real decisions — investments, product launches, supplier choices — are made with no reference to any of it. The system exists; the management does not.
The root cause: ERM designed for reports, not for decisions. The health check is simple: if all risk documents disappeared tomorrow, would a single management decision change? If not, it is imitation.
Four principles of a living system
- A risk exists for the sake of a decision. Every register line ends in a choice: accept, reduce (how and at what cost), transfer (insure), avoid. No decision — no line.
- Every risk has an owner with a budget. Not «the risk department», but the executive who controls the risk source and answers for the measures.
- Risk is measured in money and time. «High/medium/low» cannot be compared with the cost of mitigation; a money estimate can.
- The system is light. One register, one page per risk, one hour of leadership time per month. Anything heavier dies.
The register: 15 risks, not 150
A working register for a mid-sized company holds 10-20 leadership-level risks: production or IT stoppage, loss of key clients or channels, supply disruption, key-person risks, regulatory and sanction exposure, credit and currency, cyberattack, fire and accident, reputational crisis. Operational small stuff lives at department level. Each risk is one page: description, money estimate, owner, current measures, the decision, review date.
Owners and decisions
The monthly rhythm: one hour in the management meeting, three or four risks in rotation, and the owner reports not «risk status» but decision status: what was done, what changed in the estimate, what decision is needed. Quarterly — a full register review. That is enough; committees and a dedicated vertical are for large holdings and regulated industries.
Metrics instead of heat maps
A heat map is a snapshot of opinions. Management runs on numbers: cost of one day down per critical process, recovery times, revenue concentration by client and supplier, insurance coverage, mitigation delivered on time. These metrics belong on an executive screen and get compared month to month — our resilience dashboard does exactly that: a 0-100 index and traffic lights instead of a rainbow of squares.
The continuity link
Half of any serious register is stoppage risks: IT, production, supply, people. For those, mitigation number one is a working continuity loop: BIA, a recovery plan, exercises. Mature ERM and BCM are not two projects but one: the register says what to protect, continuity says how.
FAQ
Do we need a dedicated risk manager? A mid-sized business needs a part-time coordinator (method, calendar, register) with executive owners. A full function belongs in regulated industries or where investors require it.
Which standard should we follow? Borrow ideas from ISO 31000, but the standard is not the goal: no certificate substitutes for the «did decisions change» test.
How to sell ERM to the owner? Not in risk language — in money: «here are five scenarios, each costs us X, here is what we do to pay less». That is an investment conversation, not compliance.