Contact Us | Print Page | Sign In | Join Now
Ask the Experts
Blog Home All Blogs
Search all posts for:   

 

View all (37) posts »
 

What are some effective methods to report the status and/or results of ERM activities to management?

Posted By AFERM, Thursday, September 6, 2018
Updated: Monday, November 25, 2024

AFERM EXPERTS SAY...

Reporting will vary depending on leadership and how the audience best receives information.  However, reporting will likely focus on the accomplishments of the ERM program, particularly as it relates to enabling an agency effectively managing risk tolerances at the goal and objective levels and risk appetite at the agency level.  To accomplish this, agency leadership should view the risk tolerance of each objective and goal as a target measure of performance.

For example, an agency may leverage a risk tolerance scale of 1-10, with an objective risk tolerance determined to be a 4.  The goal of the ERM program is to ensure that there is the least amount of deviation of risk associated with that goal from the established threshold.  Further, consider a target with 10 rings, where the agency’s targeted risk tolerance is the fourth ring.  The agency’s actual results can then be overlaid on the target to view any potential deviation.  If the results are actually ranked at 5.5, the agency took on too much risk compared to its threshold; the risk response will need to be adjusted.  If the ranking is actually at a 3, the agency expended too much energy reducing the risk and can shift resource use to another focus area.  Ultimately, this representation allows for management to understand how well the ERM program is helping the organization in accomplishing its mission, goals, and objectives.

Additional methods used by agencies include storyboard or dashboard-style presentations capturing key risk metrics for a portfolio of risks, or at a more granular level by program or individual risk.  This can be facilitated through user developed applications based on Microsoft Office Suite tools, or through more advanced governance, risk and compliance (GRC) automated solutions that have built in analytics and reporting capabilities.  We have also seen other informative communication strategies where agencies use a newsletter campaign to broadly distribute important updates, useful tips, and planned implementation details to risk stakeholders on a frequent, recurring basis.  The goal being to help make informed decisions and keep ERM on the forefront through proactive engagement.

This post has not been tagged.

Permalink | Comments (0)
 
© Copyright 2014-2024 AFERM. All Rights Reserved.
Association for Federal Enterprise Risk Management
1050 Connecticut Ave NW, PO Box 66281 | Washington, DC 20035-6281
Contact Us | | Privacy Notice
Request Organization Information
DUNS: 045074054 | CAGE Code: 7PL42
Association for Federal Enterprise Risk Management is a registered 501(c)(3) non-profit organization. Contributions to AFERM are tax deductible to the extent permitted by law. Membership dues and event registration fees are not considered contributions.