Enterprise Risk Management (ERM), or Enterprise Risk Management, is a system that identifies, assesses, manages, and controls risks that may affect an organization's success. It involves every level of the organization, from the Board of Directors down to operational staff. BCP GURU provides ERM system implementation in accordance with the COSO ERM 2017 framework and ISO 31000:2018, along with the development of ERM Software Solutions for end-to-end risk management.
The COSO ERM Framework, "Enterprise Risk Management — Integrating with Strategy and Performance," consists of 5 main Components:
Component
คำอธิบาย
1. Governance & Culture
Governance structure and risk culture
2. Strategy & Objective-Setting
Linking risk with strategy and objectives
3. Performance
Identifying, assessing, prioritizing, and responding to risk
4. Review & Revision
Reviewing risk performance
5. Information, Communication & Reporting
Communicating and reporting risk
ISO 31000 is an international standard for risk management, consisting of 3 elements:
ประเภท
ตัวอย่าง
Strategic Risk
Market changes, Disruptive technology, Competitors
Operational Risk
Internal processes, IT systems, Personnel, Supply Chain
Financial Risk
Exchange rate, Liquidity, Credit
Compliance Risk
Laws, Regulations, Standards, Contracts
ESG / Sustainability Risk
Climate Risk, Social License, Governance Failure
Emerging Risk
AI & Automation, Cybersecurity, Geopolitical, Pandemic
The ERM process recommended by BCP GURU:
ขั้นตอน
รายละเอียด
เครื่องมือ
1. Risk Identification
Identify risks through Workshop, SWOT, PESTLE
Risk Workshop, Brainstorming
2. Risk Assessment
Assess Likelihood x Impact = Risk Score
Risk Matrix (5x5)
3. Risk Treatment
Define measures: Avoid, Mitigate, Transfer, Accept
Risk Treatment Plan
4. Monitoring
Monitor via KRI and Risk Dashboard
KRI, Dashboard
5. Reporting
Report to Risk Committee / Board
Risk Report