Office of Financial Management
Link to OFM website survey.
| More

This division is now part of the Department of Enterprise Services. Learn more…

Home » Risk Management » Agency enterprise risk management

Enterprise risk management

Risk can be created by any event or outcome that has the potential to interfere with an agency’s ability to achieve its mission on time.

Enterprise Risk Management (ERM) is the discipline and its associated processes of applying a risk evaluation to each agency goal, identifying root causes of these risks, determining—as an enterprise—what changes (i.e. risk treatments) are best to address the root causes, and then monitoring the success of the risk treatments. Treatments can include:

For example, insurance transfers the possible cost of risk to the insurance company. An early resolution program minimizes the cost of negligence by resolving claims before they become lawsuits. Changing a policy and procedure so that employees know what to do in certain situations can prevent negative outcomes. Abandoning an activity that had resulted in injury eliminates the risk posed by the activity.

How do you get there?

  1. Gather a focus group consisting of a risk savvy person from each area (division, department or function) of your agency.
  2. Brainstorm and list any event (risk) that could interfere with the ability to carry out your agency's mission.
  3. Prioritize the risks from high to low.
  4. Identify and develop responses for the high risks first.
  5. Establish an aggressive time line and designate accountable personnel to help ensure the risk responses are carried out.
  6. Identify and develop responses for the moderate and low risks and carry out step 5 above for them.

When you have completed steps 1 through 6 you have started the ERM process

What else can be done to move closer to ERM?

Useful resources