Enterprise Risk Management

Your Risk Program Gets One Agenda Slot. Make It Count.

The constraint on enterprise risk management is not information. It is board attention, and most risk leaders spend theirs confirming what the committee already knew.

By Eric Kennedy · Tue Aug 25 2026 · 11 min read

A long boardroom table seen from overhead, lined with identical navy chairs and one gold chair at the head.

TL;DR

Board attention is the scarcest resource in enterprise risk management, and most risk programs are designed as though it were unlimited. In the 2025 Audit Committee Practices Report from Deloitte's Center for Board Effectiveness and the Center for Audit Quality, 63 percent of nonfinancial services companies assign ERM oversight to the audit committee, only 8 percent use a dedicated risk committee, and nearly half of all respondents report ERM sits on the quarterly meeting agenda, which means it is not a standing quarterly item for the rest. The same committee is also responsible for financial reporting, internal controls, external audit, internal audit, compliance, cybersecurity, and increasingly AI governance. A quarterly portfolio review spends that slot confirming what the committee already knew. Three questions earn the time instead: what changed, what could break the plan, and what needs a decision.

The Constraint Is Attention, Not Information

Ask a mid-market risk leader what limits their program and you will hear about resources, tooling, or executive buy-in. Rarely attention. Yet attention is the binding constraint, and it is the one nobody budgets for.

Most programs are built as though the audit committee will absorb whatever is put in front of it. A register grows to fifty or seventy lines because every line is defensible on its own. Heat maps get denser. Reporting packs get longer, because length reads as thoroughness and nobody was ever criticized for including something.

Then the meeting happens, the risk section runs its allotted time, directors nod, and the pack goes in the binder. Nothing changed. The program produced information and consumed attention, which is the wrong direction for the trade.

The scarce input is not what your team knows. It is how much of that a board can hold, question, and act on inside one segment of one meeting, a handful of times a year. Design for the wrong constraint and you get a program that is thorough and inert.

What Your Slot Is Actually Competing With

The competition is documented. The 2025 Audit Committee Practices Report, a joint effort between Deloitte's Center for Board Effectiveness and the Center for Audit Quality, surveyed 237 audit committee members. Beyond financial statements and internal control over financial reporting, their three top priorities were cybersecurity, ERM, and finance and internal audit talent.

On structure, 52 percent said the audit committee is responsible for ERM oversight, 28 percent the full board, and 19 percent a risk committee. The industry split is sharper. Financial services companies assign ERM to the audit committee only 21 percent of the time and to a dedicated risk committee 48 percent of the time, while among companies in other industries 63 percent assign it to the audit committee and only 8 percent use a risk committee.

If you are not a bank or an insurer, there is no separate venue for risk. There is the audit committee, and ERM is one item on it.

Now the cadence. Nearly half of all respondents reported that ERM is on the audit committee's quarterly meeting agenda. That is usually quoted as good news. Read it the other way: for the rest, ERM is not a standing quarterly item. The survey does not break out what those committees do instead, so the honest claim is about the absence of a fixed rhythm rather than a specific lower frequency.

Compare that to the neighbor on the same priority list. Cybersecurity was ranked in the top three by 93 percent of respondents, ranked first by 50 percent, and 71 percent said it is on the committee agenda every quarter. Both are named top-three priorities. One of them reliably gets the standing slot.

A caveat that belongs here rather than in a footnote. This sample is large and public: 89 percent are directors on US boards, 86 percent serve public company boards, and 72 percent serve companies above $2 billion in market capitalization. It is directional for the mid-market, not a measurement of it. The honest bridge is that if audit committees at $2 billion-plus companies, with dedicated staff and established reporting rhythms, are getting ERM in front of the board roughly quarterly at best, a $200 million company with a leaner committee and a part-time risk owner is not doing better.

Cybersecurity is on the audit committee agenda every quarter for 71 percent of respondents, while nearly half report enterprise risk management on the quarterly agenda.

The Directors Have Already Told You the Problem

Here is the part risk leaders should sit with.

The same survey asked members about strategies to improve meeting effectiveness. Sixty-nine percent felt at least one of the proposed strategies would improve their meetings. Thirty-one percent said none of them would. In a room full of experienced directors, roughly seven in ten think the meeting itself could be working better.

The themes they pointed to, published by Deloitte in a supplemental report drawn from member interviews, were better presentations, more discussion and engagement, and higher quality pre-reads. CAQ's own recommendation on the back of it is to build tight executive summaries and push detail into appendices, so meeting time goes to questions rather than to presenting.

Read that as a risk leader. Two of the three fixes directors named are requests to present less so there is room to talk. If you walk into your slot with thirty slides and a full portfolio walkthrough, you are doing the specific thing the audience has identified as the problem.

There is a real limit on how far to push this. The survey does not isolate ERM presentations, and the finding covers audit committee meetings generally. It does not prove risk reporting is the offender. But the risk section is rarely the short, discussion-heavy item on the agenda, and a risk leader who assumes the complaint is about somebody else's material is making an assumption, not an observation.

Stop Using the Slot to Review the Register

Consider what a standard quarterly ERM update contains. The top ten risks. Their ratings. Movement since last quarter, usually none. Mitigation status, usually in progress. A heat map that looks like the last heat map.

If the committee already knew that cyber, talent, and supply chain were the top three risks last quarter, and they remain the top three risks, the update has confirmed a prior. That is a status report. It is not oversight, and it is a poor use of a resource you get four times a year at most.

This is not an argument that the portfolio review is worthless. It is an argument against defaulting to it. There are cases where the full walkthrough is exactly right: a newly constituted committee, a new chair, the first year of a program, the aftermath of an acquisition that changed the risk profile, or a chair who asks for it. Outside those, a quarterly re-presentation of a stable register is the safest possible use of the slot and close to the least valuable.

An illustrative funnel narrowing from seventy-five register entries to one or two items that require a board decision.

Three Questions That Earn the Time

A simple filter, applied to every item before it goes in the pack. I call it the Agenda Test.

What changed? A new risk, a risk accelerating, an exposure that moved, a mitigation that failed, a dependency that appeared. Change is the reason to spend oversight time, because change is the thing the board cannot see from where it sits. Stability can be reported in the pre-read.

What could break the plan? Not every enterprise risk deserves board discussion. The ones that do are the ones capable of materially moving the strategy, the forecast, liquidity, covenant headroom, a transaction, or a commitment to a major customer. Tie the risk to the plan the board already approved, or it belongs in management's operating rhythm.

What needs a decision? Risk appetite. Capital. Funding for a mitigation nobody has funded. A strategy change. A transfer of ownership. Or the explicit acceptance of an exposure, which is a decision even though it looks like inaction.

If an item fails all three, it does not need the slot. Put it in the appendix and let a director who wants it find it there.

Three parallel questions, change, materiality and decision, each leading to board time, with items failing all three routed to an appendix.

The filter has a second use. It gives you language for saying no to your own stakeholders. When a function insists its risk belongs in front of the board, the question is not whether the risk is important. It is which of the three tests it passes.

Management Information, Oversight Information, and Decisions

Most weak risk reporting is a category error. Material that belongs to management gets presented to a board, and the board is asked to do something it should not be doing, which is managing.

Three categories, and each item belongs to exactly one.

Management information is the operating detail: control testing, remediation tracking, incident logs, the full register, KRI readings inside tolerance. This lives in the management risk committee and in the appendix. The board does not need routine line-by-line review of it, and leading with it signals that management is not handling it. A specific incident or control failure can of course warrant board attention on its own.

Board oversight information is what a director needs to discharge the duty without running the process: whether the risk process is working, whether the profile has shifted, whether the significant exposures are owned and funded, whether a KRI has breached tolerance and what happened next. This is the pre-read.

Board decisions are the items that require the board to act, because the choice sits above management's authority. This is the meeting.

Three columns separating management information, board oversight information and board decisions, with the destination for each noted beneath.

The practical test for the split is not whether the board formally acts. Directors also do real oversight work by challenging an assumption, pressing on a number, or asking for analysis nobody had planned to produce, and none of that ends in a resolution. The test is narrower and more useful: if discussion cannot change the outcome, it probably does not need meeting time. Information that only needs to be received can be delivered in writing.

That distinction also protects management. A board handed operating detail tends to start managing it, and the fastest way to invite that is to present the register line by line.

The Test

Look at the last time enterprise risk was discussed with your board.

What changed because that discussion happened?

Not what was covered. Not whether the pack was well received. What decision was made, what resource moved, what owner was assigned, what exposure was formally accepted, or what plan was altered.

If the answer is nothing, that is worth sitting with before concluding the board is disengaged. The board attended the meeting you designed. Nothing changed because nothing on the agenda required anything to change.

The slot is not the constraint you should be complaining about. It is the constraint you should be designing for.

Where to Start

Take your last board risk pack and mark each item against the three questions: what changed, what could break the plan, what needs a decision. Be strict. Most packs return two or three items that pass and a large remainder that does not. The remainder is not deleted, it is relocated to the appendix.

Then rebuild the next agenda from what survived. If it comes to two items and twenty minutes of discussion, that is a better meeting than forty slides and no decisions.

If you want an outside read on how your program is structured and where the reporting is going wrong, the ERM Program Diagnostic is a one-to-two-week, fixed-fee review built for mid-market organizations, and the fee is credited toward a larger engagement if you move forward. If your immediate question is narrower, and it is about what the pack itself should contain rather than what earns the slot, start with board-ready risk reporting.

Take the ERM Scorecard{.cta-primary} Explore the ERM Diagnostic{.cta-secondary}

Frequently Asked Questions

How often should the board review enterprise risk?

Quarterly is the common pattern, and it is roughly the ceiling rather than the norm. In the 2025 Audit Committee Practices Report, nearly half of the 237 audit committee members surveyed said ERM is on the audit committee's quarterly meeting agenda, which means it is not a standing quarterly item for the rest. The more useful question is not frequency but content. A quarterly slot spent confirming that the top risks are unchanged produces less oversight than two well-constructed discussions a year that each carry a decision.

Who owns enterprise risk oversight at the board level?

The audit committee, in most companies outside financial services. The 2025 Audit Committee Practices Report found 52 percent of respondents overall assign ERM oversight to the audit committee, 28 percent to the full board, and 19 percent to a risk committee. Among nonfinancial services companies specifically, 63 percent assign it to the audit committee and only 8 percent use a dedicated risk committee. Financial services is the exception, where 48 percent use a risk committee. For most mid-market companies the practical consequence is that ERM shares a committee with financial reporting, internal controls, external audit, internal audit, and compliance.

What should be in a board risk report versus a management risk report?

Management reports carry operating detail: the full register, control testing, remediation tracking, incident logs, and indicator readings inside tolerance. Board reports carry what a director needs to oversee without managing: whether the risk profile shifted, whether significant exposures are owned and funded, whether any indicator breached tolerance, and what decisions are required. A practical test is whether discussion could change the outcome. If it could not, the item is information and belongs in a pre-read or an appendix rather than in meeting time.

Why doesn't the board engage with our risk presentation?

Often because the presentation does not ask them to. A report that confirms the top risks are unchanged gives directors nothing to decide, and experienced directors respond to that by listening politely and moving on. It is worth noting that in the 2025 Audit Committee Practices Report, 69 percent of audit committee members felt at least one proposed strategy would improve their meetings, and the themes they raised were better presentations, more discussion, and higher quality pre-reads. Before concluding the board is disengaged, check whether the agenda required engagement.

What is the Agenda Test?

The Agenda Test is a three-question filter for deciding what enterprise risk content earns board meeting time. What changed, meaning a new risk, an accelerating risk, a moved exposure, a failed mitigation, or a new dependency. What could break the plan, meaning exposures capable of materially affecting strategy, forecast, liquidity, covenant headroom, a transaction, or a major customer commitment. And what needs a decision, meaning risk appetite, capital, mitigation funding, a strategy change, an ownership transfer, or the formal acceptance of an exposure. An item that fails all three belongs in the appendix.