Enterprise Risk Management
How to Run an Enterprise Risk Assessment That Changes a Decision
Most assessments produce a ranked list and change nothing. The fix is not a better scoring model. It is deciding what the assessment is for before anyone scores anything.
By Eric Kennedy · Thu Jul 30 2026 · 9 min read
TL;DR: An enterprise risk assessment is the process of identifying the risks that could affect a company's objectives, evaluating them consistently, and prioritizing which ones get attention. Most mid-market assessments follow that definition and still change nothing, because the effort goes into scoring rather than into the three things that determine whether the output gets used: naming the decision the assessment feeds, calibrating the scale to your actual numbers before anyone rates anything, and designing for honest participation. The academic evidence says the scoring itself carries far less information than people assume. This piece covers the five steps, what to do differently at each one, and how often to run it.
There is a version of this exercise almost every mid-market company has run. Someone circulates a spreadsheet. Function heads rate a list of risks on a five-point scale. The ratings get averaged, plotted on a red-amber-green grid, and presented once. Then the deck goes in a folder and the business carries on exactly as it would have.
The research says that outcome is the norm. In the AICPA and NC State ERM Initiative's 2025 State of Risk Oversight report, a survey of 273 U.S. organizations, only 11 percent of senior finance leaders said their risk management process provides a strategic advantage. Sixty-four percent reported no advantage or a minimal one. The assessments are happening. They are not paying for themselves.
The instinct is to blame the scoring model, so companies move from a 3x3 grid to a 5x5, add a velocity dimension, weight the categories. That is the wrong repair, and there is good evidence for why.
The scoring carries less information than you think
In 2008, Tony Cox published What's Wrong with Risk Matrices? in the journal Risk Analysis, examining the mathematical properties of the likelihood-by-impact grid that nearly every ERM program uses. The findings are uncomfortable and they have held up for close to two decades.
Put it in practical terms. Pick any two risks off your heat map and ask which one is bigger. Cox found that a typical matrix can answer that correctly and unambiguously for only a small fraction of randomly selected pairs, which he puts at under 10 percent. The grid collapses quantitatively different risks into the same cell, a problem he calls range compression. It can assign a higher qualitative rating to a quantitatively smaller risk, so the smaller exposure outranks the larger one. And where a risk's likelihood and severity are negatively correlated, which is to say the rare events are the severe ones, the matrix can produce worse-than-random prioritization. That last condition describes most of what keeps a board awake.
This does not mean throw the heat map away. Practitioners who have argued back at Cox make a fair point: the matrix was never meant to be a precision instrument, it produces ordinal information about relative priority, and it remains the most practical way to show a board where attention should go. That is the right way to hold it. The grid is a communication device. It is not a decision engine, and a program that treats it as one is building on something that cannot bear the weight.
Which reframes the whole exercise. If the scoring step carries limited information, the value of an assessment has to come from everything around it.
Step 1: Name the decision before you name the risks
The single most common defect in a mid-market assessment is that nobody can say what it is for. Ask why the company is running one and the answer is usually "the board asked" or "we do it every year." Neither is a decision.
Before anything else, write down the decisions the assessment is meant to inform, and put dates on them. Real examples: next year's capital allocation, whether to accept the customer concentration in the sales plan, whether the insurance program still matches the exposure, what goes in the audit plan, what the board needs to see in Q4. Those are decisions with owners and deadlines.
This single step changes what you assess. An assessment feeding capital allocation needs risks stated in dollars. An assessment feeding an audit plan needs risks tied to processes and controls. An assessment feeding a board agenda needs six risks, not sixty. Skipping this step is how companies end up with a comprehensive list that is useless for anything specific.
Step 2: Build the inventory from more than one direction
Risk identification done badly is a workshop where the loudest function names its favorite worries. Done well it triangulates.
Pull from four places. Internal evidence first: audit findings, incident and near-miss logs, customer complaints, insurance claims, the last three board decks. Then the leadership interviews, one on one rather than in a group, because the room suppresses the uncomfortable answer. Then the outside view: what has actually gone wrong at comparable companies in your industry, which is a better predictor than what your own team imagines might go wrong. Then the strategy itself, read line by line, asking what has to be true for each objective to land.
One technique is worth borrowing here, because it has an evidence base. Research by Mitchell, Russo and Pennington, popularized by Gary Klein in Harvard Business Review as the pre-mortem, found that framing an outcome as having already happened rather than as something that might happen improves people's ability to correctly identify reasons for it by roughly 30 percent. So do not ask leaders what could go wrong next year. Tell them it is eighteen months from now, the plan missed badly, and ask them to explain why. The grammar change does real work.
Step 3: Calibrate the scale before anyone scores
This is the step that separates an assessment that produces signal from one that produces noise, and it is the one most often skipped.
An impact scale labeled insignificant, minor, moderate, major, severe means nothing on its own. Two executives will read "major" completely differently, and when the ratings are averaged the disagreement disappears rather than surfacing. The fix is to anchor every level to numbers that are real for your company: a percentage of EBITDA, a number of days of production, a threshold of customer churn, a covenant. For a company doing $200 million in revenue, "major" might be an eight-figure EBITDA hit, a covenant breach, or the loss of a top-five customer. Write it down and put it in front of every participant before they rate anything.
Do the same for likelihood. "Possible" is not a probability. Convert the scale to frequencies people can reason about: once in twenty years, once in ten, once in five, annually, more than once a year. People are poor at abstract probability and considerably better at frequency.
Two more rules that cost nothing. Score both inherent and residual, because the gap between them is a direct read on how much your controls are actually doing, and it is often the most informative output of the whole exercise. And define what a rating means in terms of action, so that a rating of a given level triggers something specific rather than a color on a chart.
Step 4: Design for honest participation
An assessment is only as good as what people are willing to tell you, and the default design guarantees they will tell you very little.
Three things suppress honest input. Group workshops, where nobody wants to name the risk that belongs to the person sitting across the table. Attribution, where a rating can be traced back to whoever gave it. And no visible consequence, because after the first year of nothing happening, participation becomes a compliance exercise completed in four minutes on a Friday afternoon.
The counters are practical. Collect independent input before any group discussion, for the same anchoring reason the pre-mortem protocol requires silent writing before anyone speaks. Keep individual ratings confidential and report them in aggregate. Interview one to one where the risk is politically loaded. Give people a channel to name a risk that is not on your list, because the risks that are missing from the inventory are more dangerous than the ones that are mis-scored. And close the loop: tell every participant what happened as a result of last cycle's input, since nothing drives participation like evidence that the exercise mattered.
When I rebuilt the assessment process for the enterprise risk program at a Fortune 50 technology company, participation reached 99 percent. That number did not come from a better survey tool. It came from removing the reasons people had for not answering honestly, and from the output visibly reaching the CEO, the CFO and the board.
Step 5: Turn the output into owners, signals and dates
A ranked list is not a result. The assessment is finished when each risk that matters has four things attached: a named individual owner, not a committee or a function; a signal you will watch that would show the risk building before it lands; a review cadence; and a reporting line that says who hears about it and when.
That is the artifact worth producing, and it is the difference between a risk register and a risk program. It is also what makes the next assessment cheaper, because you are updating a live picture rather than starting from a blank page.
Then wire it back to Step 1. Take the decisions you named at the start and show, explicitly, what the assessment says about each one. If the assessment cannot change any decision on that list, it did not work, and that is worth knowing before you present it rather than after.
How often to run one
The annual full-scale assessment is a reasonable backbone and a poor complete answer. The NC State data shows why the once-a-year rhythm fails: 61 percent of organizations say key risks reach senior executives through ad hoc discussion at management meetings rather than through anything scheduled. The assessment is annual and the risk conversation is unstructured, so the two never meet.
A workable mid-market cadence is one full refresh a year timed to feed planning, a lighter quarterly review of the top risks and their signals, and a standing trigger that pulls a risk back onto the table when something material changes: an acquisition, a large customer win or loss, a new regulator, a leadership change. The trigger matters more than the calendar. Most risks that surprise a board were not missed by the assessment, they moved after it.
What good looks like
An enterprise risk assessment is working when three things are true. Leadership can name the top five risks without opening a document. Each one has a person attached and a signal being watched. And at least one real decision in the last year went differently because of what the assessment showed.
If none of those are true, the problem is almost never the scoring model.
Where to Start
If you want a structured read on where your current process stands, that is what the ERM diagnostic is built for: a short, fixed-fee review of your risk assessment, ownership, cadence and reporting, with findings credited toward any further work. If you would rather start with the reporting end, the scorecard gives you a tier-level read on whether your risk reporting would hold up in front of a board in about six minutes.
Explore the ERM Diagnostic{.cta-primary} Take the scorecard{.cta-secondary}
Frequently Asked Questions
What is an enterprise risk assessment?
An enterprise risk assessment is the process of identifying the risks that could affect an organization's objectives, evaluating them against a consistent scale, and prioritizing which ones receive management attention and resources. It typically produces a risk inventory or register with each risk rated for likelihood and impact, an assigned owner, and a planned response. Unlike a functional or project risk assessment, an enterprise assessment looks across the whole business, including strategic, operational, financial and compliance risks, and is intended to inform decisions made by executive leadership and the board.
How do you conduct an enterprise risk assessment?
Five steps. First, name the specific decisions the assessment is meant to inform, with dates, because that determines what you assess and how. Second, build the risk inventory from multiple directions: internal evidence such as audit findings and incident logs, one-to-one leadership interviews, what has gone wrong at comparable companies, and a line-by-line read of the strategy. Third, calibrate the rating scale to concrete thresholds for your company before anyone scores. Fourth, collect input independently and confidentially before any group discussion. Fifth, attach a named owner, a leading indicator, a review cadence and a reporting line to each risk that matters.
How often should a company do a risk assessment?
For most mid-market companies, a full refresh once a year timed to feed planning, plus a lighter quarterly review of the top risks and the signals attached to them. More important than the calendar is a standing trigger that brings a risk back onto the table when something material changes, such as an acquisition, the loss of a major customer, a new regulatory exposure, or a change in leadership. Most risks that surprise a board were correctly assessed at the time and then moved.
What is the difference between inherent risk and residual risk?
Inherent risk is the exposure before considering the controls and mitigations currently in place. Residual risk is the exposure that remains after they are accounted for. Scoring both matters because the gap between them is a direct measure of how much work your control environment is actually doing. A risk with a large gap depends heavily on controls that should be tested. A risk where inherent and residual are nearly identical is one where current mitigation is achieving little.
Are risk matrices and heat maps reliable?
They are useful for communication and limited for prioritization. Research published in Risk Analysis by Tony Cox in 2008 found that a typical risk matrix can correctly and unambiguously compare only a small fraction of randomly selected pairs of risks, that quantitatively different risks often collapse into the same cell, and that in cases where likelihood and severity are negatively correlated the matrix can produce worse-than-random prioritization. The practical conclusion is not to abandon heat maps, which remain the clearest way to show a board where attention should go, but to stop treating the grid as a decision engine and to invest instead in calibration, honest input and clear ownership.
Who should run an enterprise risk assessment?
Ownership should sit with management, most commonly the CFO in a mid-market company, because only management can accept a risk, fund a response or change a plan. [Internal audit can facilitate the process](/blog/erm-vs-internal-audit) and often has the best cross-functional view of the business, but should not own the risks or set risk appetite, since that would compromise its ability to provide independent assurance over the same process. Where the company lacks internal capacity, [an external facilitator](/blog/understanding-enterprise-risk-management-consulting) can run the mechanics while ownership stays with named executives.