Some of or all of the challenges listed may be what your company is experiencing. It is extremely difficult for an organization to function optimally when risk mitigation units (e.g., Audit, Safety and Security, Business Continuity, Compliance, Risk Management) operate as siloed, stand-alone entities. This is because these types of frameworks or processes are often self-focused and pay insufficient attention to emerging hazards. A Unified Risk Oversight™ (URO) approach provides a more collaborative and cost-effective risk mitigation strategy. (See a quick definition and infographic on URO here.)
We find the ERM programs that do work are multi-dimensional, operationally integrated and relevantly informed by cross-functional subject matter expertise. They include:
As part of your URO approach, consider forming an Operational Risk Leadership Advisory Committee or Council (ORLAC). An ORLAC is a chartered, cross-functional executive appointed, all-hazards risk leadership governance team that prioritizes the organization’s operational risk management strategy. At an operational level, emerging risks can often be identified earlier than compiling lists of risks at the enterprise management level. This body of informed leaders will bolster the higher-level enterprise risk initiative and remove unneeded redundancies based on risk exposures and threat priorities. The role of the ORLAC is to serve as an oversight counsel. It is not meant to handle all risks or to serve as the primary driver for organizational restructuring. Its purpose is to ensure that all existing risk mitigation activities are mapped to the accepted risk registry.
There are some definite benefits of an ORLAC. Persistent URO governance is achieved because subject matter expert business leaders and section chiefs can evaluate, prioritize and resource mitigation options for both emerging and residual threats. It can correct the course for efforts that did not connect ERM for emerging and fast onset of risks, especially at the operational levels.
Answer provided by Francis D’Addario, Faculty, Security Executive Council and Kathleen Kotwica, EVP and Chief Knowledge Strategist, Security Executive Council.