Many enterprise risk management teams are at an inflection point as they aim to  become strategic partners to the business. Some corporates are finding that ERM can add more value to the business by sitting within functions like corporate strategy or internal audit. - At a recent meeting of  NeuGroup for Enterprise Risk Management , two members who recently experienced a shift in reportingâone to internal audit and the other to corporate strategyâcompared their approaches and the impact on their ability to add value.
The case for strategy. Last year, the head of corporate strategy at one member company assumed responsibility for the companyâs ERM team due to a push from the CFO to make the function more strategic.
- The strategy leader had no previous experience in risk management but was tasked to bring his broader view to a function that had up to this point been entirely tactical.
- He now sorts all risks into three buckets: enterprise-level risks, audits and compliance, with audit as an independent function and compliance sitting within the legal department. This frees up time for the ERM team to âtake on a few select enterprise strategic issues that cannot be adequately managed by other functions.â
- Though the new structure is still in its first stages, the ERM team has kick-started comprehensive sustainability risk tracking, including short-term reputational risks and long-term economic impacts.
- There were two big reasons for the move, he said: âNumber one: relevance. Is the function helping with managing risks that are relevant to todayâs environment in todayâs world?
- âThe second, I call outcome orientation,â he said. âYou had functions for a long time focused more on process without thinking holistically about the outcomes and the value derived from the process.â
The case for audit. One member who recently conducted a study of peers found that 40% of audit teams own their companiesâ ERM programs, and most members at the meeting shared that they report to internal audit.
- NeuGroupâs managing director of research and insight Nilly Essaides said that while moving ERM to reside within internal audit could potentially lead to an overly compliance-related focus, it all depends on whether IA has expanded to a broader risk perspective. âHowever, there is the risk that in some circumstances, IA is not a truly strategic partner and will therefore change the approach of ERM,â she said.
- One member who heads her companyâs audit team took on enterprise risk management when the chief accounting officer, who also headed the ERM team, left the company. It was more of a tactical decision at the start but led to a value-adding supervisory role.
- âThey thought IA was a perfect fit, since we have a large view of the companyâs risk: strategic, financial, operational, etc.,â the member said.
- âWhat Iâve now done with the process is we facilitate it, but our executive leadership team owns the risks. So they have to present those risks and mitigation plans to our audit committee.
- âIâve moved the activity to be owned more by the business, so theyâre accountable for those risks.â
Other options, dotted lines. Others at the meeting also recently moved the position of the companyâs risk management team, some with a more complex structure.
- One ERM head now reports to the chief risk officer at the company, who has helped her think more strategically about how risk management ties into the companyâs global operations. She now has quarterly calls with risk leaders for each team within the company, and said the âopen dialogue allows us to challenge each other.â
- Another companyâs ERM function is housed within finance, but has a âdotted lineâ to the head of compliance.
- âI thought [ERM] should be directly under me, but this setup is actually better,â the companyâs compliance head said. âFrom a personnel perspective, itâs hard to ask 20-25 non-lawyer finance types to be in legal, and weâve also now been able to straddle the major functions of what an ERM team is âsupposedâ to do.
- âOn compliance matters, [ERM] works at my direction, but they also have a lot of involvement in dealing with financial risks and operational risks, which would be more under the CFO; so they have a foot in both worlds. Though a dotted line is always a little bit of extra work, Iâve been really happy with the coverage.â
- One member agreed that having a dotted line connecting ERM to multiple functions can be very beneficial. At his company, ERM sits in internal audit, but has a dotted line to financial strategy and the CFO.
- âItâs been a fantastic complement,â he said. âWe also work closely with our compliance office under the legal team, and itâs a great relationship. We do a lot of partner audits and reporting, and fundamentally, Iâve found to be a very good pairing.â