Steps in the Enterprise Risk Management (ERM) Process

Identify Risks
The first step in the ERM process is to identify the potential risks (and opportunities) that may affect the organization鈥檚 objectives. This step involves recognizing聽internal and external risks that may arise from various sources such as operations, financial, regulatory, legal, reputational and strategic risks.聽Identifying new risks is key to managing what is on the horizon.

A graphic showing the typical steps involved in the ERM process.

Assess Risks
After identifying the risks, the next step is to assess their likelihood and potential impact on the organization鈥檚 objectives. This step involves analyzing the risks in terms of their probability of occurrence, potential impact, the speed (or velocity) that the risk might affect the organization聽and the adequacy of the organization鈥檚 current controls to mitigate those risks.

Prioritize Risks
Based on the risk assessment, the next step is to prioritize the risks based on their level of importance to the organization鈥檚 objectives. This step involves determining which risks require immediate attention and which risks can be managed over the long term.

Develop Risk Mitigation Strategies
After prioritizing the risks, the next step is to develop risk management strategies that align with the organization鈥檚 objectives. This step involves developing a risk management plan that outlines how the organization will mitigate, avoid, transfer聽or accept each risk.

Implement Risk Mitigation Strategies
The next step is to implement the risk mitigation strategies identified in the previous step. This step involves putting in place the necessary processes, policies and procedures to manage the risks identified.

Report, Monitor and Review
The final step in the ERM process is to report, monitor聽and review the effectiveness of the risk management strategies implemented. This step involves continuously monitoring the risks, evaluating the effectiveness of the risk management strategies, adjusting the strategies as necessary and reporting the results in a timely manner to be useful in strategic planning.