Risk Strategy

The Day ERM Becomes Urgent

Five moments when a company can no longer rely on informal risk management, and what leadership should build first.

By Eric Kennedy · Tue Aug 04 2026 · 11 min read

The Day ERM Becomes Urgent

TL;DR

A buying trigger for enterprise risk management is a change in the business that makes informal risk management unreliable. Companies rarely formalize risk because they became persuaded by a framework; they do it because something changed. Five triggers recur especially often: new leadership, a decision that is hard to reverse, a near miss, an outside party raising the evidence standard, and growth past what one person can hold in their head. The near miss is the one most often wasted, because the research says surviving a close call tends to make an organization feel safer than it was.

A near miss should be the clearest possible argument for strengthening risk management. In practice it is often the moment an organization becomes less likely to act.

When the bad outcome does not arrive, leaders tend to read survival as evidence that the system worked, even when chance did most of the work. Robin Dillon and Catherine Tinsley tested this and published the results in Management Science. Across several experiments, participants evaluated near-miss outcomes more like successes than failures, and those who had near-miss information went on to choose the riskier option. The participants were not only students. NASA managers and contractors showed the same pattern. In later work, the same researchers found that these events lowered people's feelings of risk without changing what those people believed about the probability of the event. The feeling moved. The estimate did not.

That is worth sitting with, because it means the event most likely to justify a risk program is also the one most likely to be spent and forgotten.

Enterprise risk management is rarely a planned purchase. Almost nobody wakes up persuaded by a framework. Something changes, and the risk process that seemed adequate last quarter stops being adequate. What follows are five changes that commonly do it, what each one looks like from inside the business, the way management usually misreads it, and the one question worth asking when it happens.

Why companies wait, and what actually moves them

The reason to talk about triggers rather than arguments is that the arguments have already been made and they have not worked.

The AICPA and NC State 2025 State of Risk Oversight, a survey of 273 US organizations, found that only 32 percent of senior finance leaders describe their risk oversight as mature, and only 11 percent see their risk process as a strategic advantage. Those numbers have barely moved in years. More useful is the reason respondents gave. The leading barriers were competing priorities and insufficient resources, both at 41 percent. A lack of perceived value came third, at 29 percent.

For most companies this is not a disagreement about whether risk management is worth doing. It is a queue. Risk work sits below the things with deadlines and stays there until something moves it.

There is a second finding in the same survey that says more about these programs than the maturity numbers do. Only 27 percent of respondents said their risk process would help them identify and manage a significant event affecting reputation and brand. So the trade-off most companies are actually making is not between a good process and a busy quarter. It is between a process they do not fully trust and a busy quarter.

A trigger is what moves it. It reorders the priority and unlocks the resource in the same moment, which is why the CFO who declined this work in March signs off on it in September.

Five triggers that make enterprise risk management urgent: new leadership, a decision that is hard to reverse, a near miss, a change in the evidence standard, and outgrowing informal risk management.

Trigger 1: New leadership changes the questions

What changed. A new CFO, head of internal audit, or audit committee chair inherits a set of risk activities that nobody has ever had to explain end to end. There are reports. There is a register somewhere. There is an insurance renewal, a continuity binder, and a cyber assessment from two years ago. What there is not is a consolidated answer.

New leaders ask different questions than incumbents, and they ask them out loud, because they have no history to protect. Where is the enterprise view? Who owns this exposure? What has management already accepted on the company's behalf? What actually reaches the board?

The CFO seat turns over faster than the institutional memory around it. The Crist|Kolder Associates 2025 Volatility Report recorded 120 CFO changes across 664 Fortune 500 and S&P 500 companies last year, close to one company in five, with average tenure at 4.7 years. That is large-cap data and should not be read as a mid-market rate. It is directional, not representative. But the dynamic is not confined to the Fortune 500.

The dangerous interpretation. "There have been no surprises, so the process must be working." The absence of a bad quarter is not evidence of a functioning risk process. It is evidence of a quarter.

The first question to ask. Which material exposure could we not currently explain to the board with a named owner, a range of outcomes, and a threshold that would trigger escalation?

Trigger 2: The company makes a decision it cannot easily reverse

What changed. The company committed to something it will be living with for years. An acquisition, a new geography, a significant AI deployment, a large capital program, a customer or supplier concentration it has never carried before.

The useful distinction here is narrow and it gets missed constantly. Diligence tests the decision. Enterprise risk management governs the assumptions the decision continues to depend on. Those are different jobs and only one of them is usually staffed.

Diligence asks whether the deal is sound at signing. It does not answer who owns each assumption afterward, what would be visible first if one of them were wrong, or what the company does when that happens. A risk assessment run before the commitment can still change terms, sequencing, or the walk-away point. The same work run after implementation begins produces a status report.

The dangerous interpretation. "We ran diligence, so the risks are covered."

The first question to ask. For each assumption this decision depends on, who owns it, what would we see first if it were wrong, and how long before we would see it?

Trigger 3: A near miss gets read as proof the system works

What changed. A supplier nearly failed. A ransomware attempt got contained. A compliance issue surfaced and closed without penalty. A major customer threatened to leave and stayed. The loss did not happen.

This is the trigger from the opening and the one most often wasted. The reason is structural rather than careless: the event registers as a success, and success rarely prompts the same investigation that failure does.

Tinsley, Dillon, and Cronin drew a distinction that is worth borrowing. They separated what they called resilient near misses, where the organization escapes and reads the escape as evidence of its own durability, from vulnerable ones, where the closeness of the call stays visible. Resilient near misses reduced people's feelings of risk more than vulnerable ones did. Same event, different lesson, depending entirely on how it was understood.

The practical consequence in a mid-market company is specific. The near miss is usually resolved by one capable person doing something unscheduled. Nobody writes it down, because nothing broke. The organization keeps the same exposure and loses the only free warning it was going to get.

There is a genuine counterweight worth naming. Sometimes a near miss really does carry new information, and the right conclusion is that the control held. The problem is not that leaders draw the reassuring conclusion. It is that they draw it without checking.

The same researchers also found the fix, which is the most useful part of the work. In their second experiment, they report that the near-miss bias went away once probability information was made explicit and decision makers used it as the basis for their choice. Whatever the effect size in a real company, the direction is clear enough to act on: a short, honest reconstruction of what nearly happened and how close it came does most of the work.

The dangerous interpretation. "The team handled it."

The first question to ask. What prevented the loss: a designed control, an individual's intervention, or luck? If nobody can answer cleanly, treat it as luck until proven otherwise.

The same near miss read two ways: as a disaster that did not happen, which lowers felt risk, or as a disaster that almost happened, which keeps the exposure visible.

Trigger 4: The evidence standard changes

What changed. Somebody outside the management team stops accepting assurance and starts asking for proof.

It takes several forms and they are the same event underneath. A private equity sponsor arrives with a value creation plan and expects named ownership of the assumptions inside it. A new lender adds covenants. An insurer asks for evidence rather than a completed questionnaire. A large customer sends a security and resilience assessment. An auditor asks how management's risk conclusions were reached. A regulator asks what changed after the last finding.

The distance the company has to travel is not from "we do not manage this" to "we manage this." It is from "we believe this is being managed" to "here is who owns it, here is how we know, and here is what happens when it moves." That second statement is a different artifact, and most companies discover they cannot produce it on request.

For sponsor-backed companies, the operating risk inside a value creation plan is usually the version of this that bites first.

The dangerous interpretation. "This is a documentation exercise." Sometimes it is. More often the request exposes that the underlying ownership was never assigned, and the documentation cannot be produced because the thing it would describe does not exist.

The first question to ask. If this party asked us to demonstrate rather than assert, what could we hand them today?

Trigger 5: The company outgrows what one person can hold in their head

What changed. Nothing dramatic. That is what makes this the hardest one to see and the most common one in the mid-market.

At the smaller end of the mid-market, a CEO or CFO may still hold most of the risk picture personally. They know the suppliers, the key people, the customer concentration, the covenant headroom, the systems held together with goodwill. That is not informal in a bad way. It is efficient and it works.

As sites, systems, acquisitions, and layers of leadership accumulate, that model stops scaling, and it stops quietly. The picture is still complete somewhere in the organization, but it is now distributed across six people who do not routinely talk to each other, and no one of them can see all of it.

The failure mode is not that risks go unmanaged. It is that the connection between them goes unmanaged. The supplier that is slipping, the quality drift, and the rise in customer complaints are three signals of one problem sitting in three functions.

Four functions each see a separate signal, supplier lead times rising, the production schedule slipping, the defect rate increasing, and customer complaints accelerating, that together point to one exposure: major customer revenue at risk.

The dangerous interpretation. "We have a register, so we have a program." A register is an artifact. A program is an operating rhythm with named owners and an escalation path. The difference shows up the first time something moves between reviews.

The first question to ask. If a material exposure worsened this month, who would notice, who would they tell, and by what date would it reach an executive?

What urgency tempts companies to buy

Trigger-driven buying has a failure mode worth naming, because it works against you as the buyer. Urgency makes people buy the largest available thing. A board asks a hard question in March, and by June the company has a platform, a forty-risk heat map, and no more clarity than it started with.

None of those options are wrong in themselves. A platform is the right answer for a company that has an operating program and needs to scale it. A full-time risk leader is the right answer when the workload is genuinely continuous. A maturity assessment against a recognized framework is the right answer when the board needs a benchmark. The problem is sequence, not merit. Each is a good answer to a question the company has not yet asked precisely.

A comparison of what urgency tempts companies to buy against the six things the first 90 days should prove.

What the first 90 days should prove

Before committing to scope, technology, or headcount, six things are worth establishing. They are cheap to test and expensive to assume.

  1. Executives will participate candidly. Not attendance. Candor. If leaders will not say the uncomfortable thing in this format, no amount of process fixes it.
  2. Material exposures can be expressed in decision-relevant terms. A ranking is not decision-relevant. A range, a driver, and a threshold are.
  3. Every critical risk has a named owner who accepts it. Assignment is not ownership. Acceptance is.
  4. Escalation thresholds can be agreed in advance. A threshold set after the fact will be set to whatever avoids the conversation.
  5. One real management or board decision is improved. If the output cannot change a decision that was going to be made anyway, it is documentation.
  6. The operating cadence survives the project. The test is what happens in month four, not month three.

Prove those six and every subsequent purchase is smaller, better specified, and more likely to be used. That is the honest reason to start narrow. Not because narrow is virtuous, but because those six answers change what you should buy next.

If you want the longer version of how these pieces connect, the buyer's guide to enterprise risk management consulting covers evaluation and selection, and there is a separate breakdown of what this work typically costs.

Where to Start

If one of these five events has already happened at your company, the useful next step is not a proposal.

Tell me what changed. Two or three sentences is enough. I will come back with the first three questions I would ask before deciding whether a formal ERM effort is warranted, and if the answer is that you do not need one yet, I will say so.

If you would rather start anonymously, the KRG scorecard gives you a tier-level read in seven questions and about two minutes, with no email required to see your score.

Tell Me What Changed{.cta-primary} Take the Board-Reporting Scorecard{.cta-secondary}

Frequently Asked Questions

When should a mid-market company start enterprise risk management?

A mid-market company should formalize enterprise risk management when a change in the business makes informal risk management unreliable, not when it reaches a particular revenue threshold. The five most common triggers are a new CFO, head of internal audit, or audit committee chair; a decision that is hard to reverse such as an acquisition or major capital commitment; a near miss; an outside party such as a sponsor, lender, insurer, customer, or auditor raising the evidence standard; and growth past the point where one executive can hold the whole risk picture. Revenue matters mainly because it correlates with that last one.

Why do companies fail to act after a near miss?

Because near misses register as successes rather than failures. Research published in Management Science by Dillon and Tinsley found that people evaluate near-miss outcomes more like successes and subsequently choose riskier options, a pattern that held among NASA managers as well as students. Follow-on work found these events lower people's feelings of risk without changing what they believe about the probability of the event. The same researchers report that the effect went away in their experiment once probability information was made explicit and decision makers used it as the basis for their choice, which suggests the practical fix is reconstructing how close the call actually came rather than relying on the reassurance of having survived it.

Does a mid-market company need a chief risk officer?

Many mid-market companies do not need a full-time chief risk officer at the outset. The AICPA and NC State survey of 273 US organizations found 45 percent report having a chief risk officer or senior risk executive equivalent. What a company at this size needs first is a named owner, usually the CFO or a designated executive, a quarterly operating rhythm, and an escalation path. Whether that is built internally, with outside help, or through ongoing advisory support depends on how continuous the workload actually is.

What should a company build first when a trigger occurs?

Start with a focused diagnostic that establishes six things: whether executives will participate candidly, whether material exposures can be expressed in decision-relevant terms, whether every critical risk has an owner who accepts it, whether escalation thresholds can be agreed in advance, whether the output improves one real decision, and whether the cadence survives past the initial project. Proving those six makes every subsequent decision about software, headcount, and program scope substantially better informed, and it avoids the common pattern of buying the largest available solution under time pressure.

How is this different from a risk assessment?

A risk assessment produces a prioritized view of exposures at a point in time. The work described here is about whether the organization can act on that view: who owns each exposure, what threshold moves it, and how it reaches the people who decide. Many mid-market companies have run a credible assessment and still have no program, because the assessment was never connected to a decision or an owner.