1
ENTERPRISE RISK MANAGEMENT (ERM) PAPER
Enterprise Risk Management (ERM) is a specific process used by companies to identify and
prioritize risk using tools called, “heat maps.” These “heat maps” are used to display the severity
of the risk’s impact on an organization as well as the likelihood of the risk occurring (Merchant,
2012). Enterprise Risk Management involves planning and organizing activities within an
organization to ensure that all risks, including accidental, financial, strategic and operational
risks are taken into consideration to protect a company’s wellbeing. ERM is typically made up of
eight interrelated components all of which may be slightly different based on the organization’s
management approach and processes. There eight aspects that make up the COSO (2004) model
of ERM are as follows: internal environment, objective setting, event identification, risk
assessment, risk response, control activities, information and communication and monitoring
(Anderson, 2017).
Enterprise Risk Management is comprised of good risks, bad risks, known risks and
misperceived risks. An essential part of ERM involves weighing good risks versus bad risks for a
company. Good risks are usually those opportunities that are ideally going to ultimately help the
firm prosper and grow. These types of risks have a high probability of happening and also will
create a positive impact on the organization as they will position the company in an
advantageous manner. The use of risk management can also be utilized to help the firm make the
most of the economic business advantage that said risk would create (Nocco & Stulz, 2006). One
example of a good risk would be a merger that’s in the best interest of the company and would
allow the resources for the company to expand into other geographical locations and yield more
overall revenue. On the contrary, bad risks are typically defined as those opportunities that have
a high likelihood of happening, but also have a negative impact on the organization which can