
What Is Enterprise Risk Management (ERM)?
What Is Enterprise Risk Management (ERM)?
Monday, 24 August 2026
What is enterprise risk management?
Start with an example. An agency runs three programs. Each has its own risk register, each rates its main risk as moderate, and each depends on the same ageing payments platform and the same small team of people who understand it. Read separately, nothing looks alarming. Read together, one system failure or two resignations take down all three at once. No individual register was wrong. The concentration was simply invisible because nobody was looking across.
Closing that blind spot is the purpose of ERM. It manages risk to the organisation’s objectives as a whole, rather than leaving each division to manage its own in isolation, so that concentrations, dependencies and shared exposures become visible to the people making decisions. The definition underneath it matters too. ISO 31000:2018 defines risk as the effect of uncertainty on objectives, and notes that the effect can be positive, negative or both. Risk is therefore not a synonym for bad news. An organisation that never misses a target is probably not attempting enough.
The strategic dimension is what distinguishes ERM from a well maintained hazard list. The COSO enterprise risk management framework positions ERM around integrating risk with strategy and performance, on the reasoning that the most consequential risk an organisation faces is often the possibility that its strategy is the wrong one, not that a control will fail. Registers of operational hazards rarely capture that. ERM is meant to.
How is ERM different from traditional risk management?
Four differences do most of the work. Traditional risk management is organised by function, with finance, work health and safety, information technology and legal each maintaining their own view, while ERM aggregates to an enterprise picture. Traditional practice tends to focus on preventing loss, while ERM covers both threat and opportunity. Traditional practice often runs as a periodic compliance exercise, while ERM is meant to inform decisions as they are made. And traditional practice usually stops at the organisational boundary, while ERM has to account for risks shared with partners and suppliers who are outside your control but inside your exposure.
The practical test is simple. If your risk register is reviewed quarterly, filed, and has no observable effect on where money and people go, you have risk reporting rather than risk management. The register is an artefact of ERM, not the thing itself.
Is enterprise risk management mandatory in Australia?
For much of the public sector, risk oversight is a legal duty rather than good practice. Section 16 of the Public Governance, Performance and Accountability Act 2013 (PGPA Act) requires the accountable authority of a Commonwealth entity to establish and maintain an appropriate system of risk oversight, management and internal control. The Commonwealth Risk Management Policy supports that section with nine elements that non corporate Commonwealth entities must comply with, beginning with the requirement that risk management is embedded into decision making, and covering risk frameworks and appetite statements, culture, defined responsibilities, periodic review of control effectiveness, shared risks, emerging risks, capability and regular review of the approach itself.
Two qualifications matter before anyone applies this beyond its scope. Corporate Commonwealth entities are not required to comply with the policy, though they are encouraged to align with it as good practice, and state and territory entities operate under their own arrangements rather than this one. The framework also continues to develop. In 2025 the Department of Finance launched a Commonwealth Risk Management Framework bringing together the policy areas responsible for risk to improve the handling of shared and common risks, which introduces no new requirements but does consolidate where the existing ones sit. Private sector organisations have no equivalent statutory duty of this kind, though directors’ duties, work health and safety law and sector regulation create obligations of their own.
What does ERM look like when it fails?
The failure is rarely an absent framework. It is a framework that exists and does not reach decisions. Reviewing five years of its own audits, the Australian National Audit Office (ANAO) found that 94 per cent of its audits examined risk management and 67 per cent of those findings were mixed or negative, with roughly a fifth of all its recommendations relating to risk. It also found a positive relationship between risk management findings and overall audit conclusions, meaning entities that manage risk well tend to be assessed well overall.
One of its case studies makes the pattern concrete. Examining the temporary expansion of telehealth services during COVID-19, the ANAO found the health department advised the minister on the costs but on only some of the benefits and risks, and did not use the required risk potential assessment tool for policy options above $30 million during the relevant period. Nobody had abolished risk management. The information simply did not arrive with the decision, which is the same outcome from the decision maker’s point of view.
The other consistent weak point is shared risk, which the ANAO identifies as a particular area of weakness. Shared risks often have no obvious owner, are influenced by several parties and land differently on each of them. In its examination of welfare payment accuracy and timeliness, only one of five bilateral service arrangements between the two responsible agencies referred to risk management at all, and no joint risk register existed. Risks that sit between organisations are the ones most likely to be nobody’s job.
How do you make ERM actually work?
A few things separate a functioning system from a documented one. Write a risk appetite statement specific enough to settle an argument, since a statement that every option satisfies is decoration. Put risk on the paper that goes to the decision maker, in the business case and the policy proposal, rather than in a parallel document nobody reads at the same time. Give every control a named owner who reports on whether it is actually working, because an unowned control is an assumption. Name shared risks explicitly with the partner organisation and agree who holds what, ideally in the agreement itself. Then check periodically whether anything you learned changed what you do, which is the step most often skipped.
Culture determines whether any of that survives contact with a bad quarter. A framework requiring escalation is worth nothing if the person who escalates is treated as an obstacle. Senior leaders decide this by what they reward, not by what the policy says, and staff calibrate accordingly within about a fortnight.
The hardest part for senior leaders is not building the framework, which can be bought or copied. It is exercising judgement about which risks genuinely threaten the objectives, deciding what level of exposure is worth accepting to achieve something, and holding that position when a minister, a board or a media cycle applies pressure in the opposite direction. Working through those judgements is what AcademyGlobal (AG) designed its Strategic Risk Management for Senior Public Sector Leaders training around, using the risk decisions participants are currently carrying rather than generic scenarios.
The question worth asking of your own arrangements is not whether a framework exists. It is whether anyone made a different decision last quarter because of it.
Frequently asked questions
What is the difference between ERM and risk management?
Scope and purpose. Traditional risk management handles risks within a function, such as finance or safety, while ERM aggregates risk across the organisation and connects it to strategic objectives. ERM also treats opportunity alongside threat, whereas functional risk management usually concentrates on preventing loss.
What is the difference between ISO 31000 and COSO ERM?
Both are widely used and broadly compatible. ISO 31000 is an international standard offering principles, a framework and a process applicable to any organisation, and it is guidance rather than a certifiable requirement. The COSO framework comes from a governance and internal control tradition and puts more emphasis on integration with strategy and performance.
Who is responsible for enterprise risk management?
Ultimately the accountable authority or board, who own the system of risk oversight and set risk appetite. A chief risk officer, where one exists, designs and supports the framework rather than owning the risks. Individual risks sit with named risk owners, and controls with named control owners, which is what makes accountability real.
What is a risk appetite statement?
A statement of how much risk, and which types, an organisation is willing to accept to achieve its objectives, supported by tolerances that make it operational. A useful one distinguishes between categories, since most organisations are legitimately more tolerant of delivery risk than of safety or integrity risk.
How often should risks be reviewed?
Frequency should follow the nature, speed and severity of the risk rather than the calendar. Fast moving risks need attention between scheduled reviews, and the trigger for review should include events as well as dates. Quarterly review of everything at the same cadence usually means fast risks are reviewed too late and stable ones too often.
References
Australian Government Department of Finance. Commonwealth Risk Management Policy.
Australian Government Department of Finance (2025). Launch of the Commonwealth Risk Management Framework.
Australian National Audit Office. Insights: Audit Lessons, Risk Management.
Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management: Integrating with Strategy and Performance.
International Organization for Standardization. ISO 31000:2018 Risk management: Guidelines.