Contact Us | Print Page | Sign In | Join Now
Ask the Experts
Blog Home All Blogs
Search all posts for:   

 

View all (37) posts »
 

How long does it take to implement a fully compliant ERM program?

Posted By AFERM, Thursday, September 6, 2018
Updated: Monday, November 25, 2024

AFERM EXPERTS SAY...

This question touches on an important distinction within ERM program implementation.  There is a significant difference between a fully compliant ERM program and a fully capable ERM program.  Compliance focuses on the contents of an ERM program, while capability focuses on what an ERM program can achieve.

A fully compliant ERM program can be established in 1-2 years, seeking to institute an Enterprise Risk Board, a governance structure, risk appetite statement, updated Statement of Assurance, risk profile, etc.  It is not as easy to build an ERM program that is mature, fully functioning, integrated, and outcome-oriented.  In a smaller, less complex agency with leadership buy-in, this could range from 5-7 years.  However, in a larger, complex, decentralized agency, it could take 5-10+ years.  It is important that agencies not be discouraged by those projections.  Effective ERM is meant to be a long-term, evolving endeavor.

This post has not been tagged.

Permalink | Comments (0)
 
© Copyright 2014-2024 AFERM. All Rights Reserved.
Association for Federal Enterprise Risk Management
1050 Connecticut Ave NW, PO Box 66281 | Washington, DC 20035-6281
Contact Us | | Privacy Notice
Request Organization Information
DUNS: 045074054 | CAGE Code: 7PL42
Association for Federal Enterprise Risk Management is a registered 501(c)(3) non-profit organization. Contributions to AFERM are tax deductible to the extent permitted by law. Membership dues and event registration fees are not considered contributions.