← University
Enterprise Risk Management: Comprehensive Program
0 of 9

A mid-sized industrial equipment manufacturer headquartered in southern Ontario had operated for 22 years with what its leadership considered adequate risk management practices. The finance department handled insurance renewals and credit risk, the operations manager oversaw workplace safety, in-house counsel reviewed contracts and regulatory filings, and the executive team addressed strategic concerns as they arose in quarterly planning sessions. Each function performed its work competently within its domain, and for 2 decades this arrangement seemed sufficient for a company that had grown from a 15-person shop to an organization employing 340 workers across 3 facilities.

The fragility of this arrangement became apparent when a supplier quality failure triggered a cascade that no single department had anticipated. A defective component incorporated into equipment shipped to 47 customers across 4 provinces led to a product recall, which generated media coverage that prompted regulatory inquiries, which revealed documentation gaps that exposed the company to penalties, which spooked the company's primary lender during a refinancing negotiation for a planned expansion. Within 8 weeks, what began as a quality control issue had touched every dimension of organizational risk simultaneously. The financial exposure exceeded $4.2 million before stabilizing, but the more troubling revelation was that warning signs had existed in purchasing data, quality metrics, and supplier audit reports that different departments had each possessed but none had connected.

The board of directors, comprising 7 members including 3 independent directors, requested a comprehensive assessment of how the organization identified, evaluated, and responded to risk. The chief executive officer and the chief financial officer were tasked with developing an integrated enterprise risk management program that would provide the board with meaningful oversight capability while translating risk considerations into operational decision-making across all business units. The organization had no dedicated risk management function, no formal risk appetite statement, and no systematic process for surfacing risks before they materialized as crises.

The company now faces fundamental questions about framework selection, governance architecture, identification methodologies, assessment approaches, and how to mature its capabilities over time. It must determine how to establish risk appetite boundaries that actually influence behaviour on the shop floor and in procurement decisions, how to integrate risk thinking into strategic planning for the expansion that remains a priority, and how to build board oversight structures that provide genuine visibility rather than compliance theatre. The leadership team has committed to developing an ERM program but has limited internal expertise and must determine what genuine maturity in enterprise risk management looks like for an organization of its scale and complexity.

The ERM Landscape in Canada: Standards, Expectations, and the Regulatory Environment

Enterprise risk management represents one of the most significant evolutions in how Canadian organizations approach uncertainty, opportunity, and strategic planning. For decades, organizations treated risk as something to be handled in silos—financial risks by the finance department, safety risks by operations, legal risks by counsel—with little coordination or strategic oversight. This fragmented approach, while better than ignoring risk entirely, created dangerous blind spots where interconnected risks could cascade through an organization before anyone recognized the pattern. Enterprise risk management emerged as a discipline precisely because modern organizations operate in environments where a supply chain disruption in one region can trigger reputational damage, regulatory scrutiny, and financial losses simultaneously. Canadian businesses, non-profits, and public sector organizations now operate within a complex web of expectations that demand integrated, proactive approaches to identifying, assessing, and responding to risk across every dimension of their operations.

The Canadian landscape for enterprise risk management draws from international standards while reflecting distinctly Canadian regulatory expectations and business realities. The International Organization for Standardization published ISO 31000, titled "Risk management — Guidelines," which has become the foundational reference point for risk management practice worldwide and holds particular significance in Canada. As of the date of authorship, the current version of ISO 31000, published in 2018, provides principles and guidelines that Canadian organizations across sectors have adopted either formally or informally as their framework for approaching risk. This standard does not prescribe specific practices or create compliance requirements in itself, but rather offers a common language and conceptual framework that Canadian regulators, industry associations, and professional bodies have incorporated into their own expectations. The standard emphasizes that risk management should be integrated into governance and decision-making, structured and comprehensive while remaining customized to the organization's context, inclusive of stakeholder perspectives, dynamic and responsive to change, based on the best available information, considerate of human and cultural factors, and committed to continuous improvement. Understanding these principles matters for Canadian organizations because they underpin the specific requirements that do carry legal or regulatory weight across federal and provincial jurisdictions.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $249 course — purchasing unlocks it, or sign in if you already have access.