é É « » à è ù ç ô é
ERM: definition & meaning (enterprise risk management)
‹ Go back | Glossary

ERM: definition & meaning (enterprise risk management)

What is ERM (Enterprise Risk Management)?

Enterprise Risk Management (ERM) is a structured, organization-wide framework for identifying, assessing, prioritizing, managing, and monitoring all categories of risk that could affect the achievement of strategic, operational, reporting, and compliance objectives. ERM treats risk holistically — as interconnected across the enterprise — rather than managing risk categories in isolation.

The COSO ERM Framework

COSO published its ERM framework in 2004, updated in 2017 to integrate strategy and performance. The framework organizes ERM across five components: governance and culture, strategy and objective-setting, performance (risk identification and assessment), review and revision, and information, communication, and reporting.

ERM vs. Internal Control

Internal control is the mechanism through which risks are mitigated. ERM is the broader governance process through which risks are identified and management decides which to accept, avoid, reduce, or transfer. Internal audit independently evaluates both — whether the ERM process is functioning, and whether the controls it relies on are operating as designed.

ERM in practice

A mature ERM program maintains a risk register documenting material organizational risks, assigned ownership, likelihood and impact ratings, and the controls management has implemented. See: risk management — definition and strategies.

ERM and Supervizor

Supervizor strengthens the monitoring component of ERM by providing continuous, data-driven evidence of where financial risks are actually concentrating — giving risk management teams real transaction data rather than periodic assessments. The AI Insights module surfaces risk trends and patterns that feed directly into the risk register.

Related Supervizor pages

Risk management — definition and strategies

AI Insights — risk trends and prioritization

AI & Controls — continuous risk monitoring

Compliance — risk-based control testing