← University
Building an Enterprise Risk Framework
0 of 6

A regional non-profit organization in southern Alberta that provides employment training and supportive housing services has operated for 22 years, growing from a small charitable initiative into an organization with an annual operating budget of $4.8 million, 47 full-time staff, and 3 service locations across 2 municipalities. The organization holds service contracts with 2 provincial ministries, receives funding from 4 corporate donors and a community foundation, and maintains a portfolio of 6 residential properties that house program participants. Its board of directors consists of 9 volunteer members drawn from the local business, legal, and social services communities.

During a board governance review conducted in response to concerns raised by the organization's external auditor, directors discovered that risk management across the organization existed in disconnected pockets with no coordinating structure. The finance team maintained a spreadsheet tracking accounts receivable aging and cash flow projections. The housing program manager kept an informal log of building maintenance issues and tenant complaints. The human resources coordinator had developed a checklist for workplace safety incidents. The information technology contractor who visited twice monthly had flagged cybersecurity vulnerabilities in 3 separate reports over 18 months without receiving a formal response from management. None of these activities connected to one another, to the organization's strategic plan, or to regular board deliberations.

The governance review also revealed that 2 of the organization's ministry contracts contained new provisions requiring funded agencies to demonstrate formalized risk management practices by the next contract renewal period, now 14 months away. The board chair, a retired manufacturing executive, recalled that the company where she had spent her career had implemented an enterprise risk management framework after a supply chain crisis, but she was uncertain how such an approach would translate to a non-profit context with different stakeholders, funding structures, and accountability relationships.

The executive director, who had led the organization for 8 years, acknowledged that risk conversations tended to arise only after problems materialized rather than through any systematic anticipation. A recent incident illustrated the point: a data breach affecting 340 client records had prompted a reactive scramble rather than an execution of pre-established protocols, because no such protocols existed. Staff members in different departments had responded based on their own judgment, with inconsistent messaging to affected clients and no clear escalation path to the board.

The board directed the executive director to develop a proposal for implementing an enterprise-wide approach to risk management, with attention to available frameworks, governance structures, resource requirements, and the cultural changes necessary to embed risk awareness throughout the organization.

What Enterprise Risk Management Is and How It Differs From Operational Risk Control

Enterprise risk management represents a fundamental shift in how organizations understand, anticipate, and respond to uncertainty. Where traditional approaches to risk have focused on identifying and controlling specific hazards within discrete operational areas, enterprise risk management takes a panoramic view, treating risk as an organization-wide phenomenon that demands coordinated attention from leadership at every level. This distinction matters profoundly for Canadian organizations of all sizes, from sole proprietorships navigating regulatory compliance to mid-sized manufacturers managing supply chain vulnerabilities, to non-profits stewarding donor funds while pursuing ambitious social missions. Understanding what enterprise risk management actually is, and how it differs from the operational risk controls most organizations already have in place, forms the essential foundation for building a framework that protects organizational value while enabling strategic growth.

The concept of enterprise risk management emerged from a recognition that organizations were failing not because they lacked risk controls, but because their risk controls operated in silos that prevented them from seeing how different risks interacted, amplified each other, or created systemic vulnerabilities that no single department could address. A construction company might have excellent safety protocols on its job sites, rigorous contract review processes, and comprehensive insurance coverage, yet still face existential threats because no one was examining how a skilled labour shortage, rising material costs, and delayed municipal permitting might combine to undermine project profitability across the entire portfolio. Enterprise risk management addresses this gap by establishing structures and processes that allow organizations to identify, assess, and respond to risks in an integrated manner, considering both the likelihood of various events and their potential impact on strategic objectives.

The foundation of enterprise risk management in Canada draws from several internationally recognized frameworks, most notably the Committee of Sponsoring Organizations of the Treadway Commission framework, commonly known as COSO, and the ISO 31000 standard for risk management. As of the date of authorship, ISO 31000:2018 remains the current version of this international standard and provides principles and guidelines that Canadian organizations across all sectors have adopted. These frameworks share a common philosophy: risk management should not be a separate function bolted onto organizational operations but rather should be embedded in governance, strategy setting, planning, management, reporting, policies, values, and culture. For Canadian organizations operating across multiple provincial jurisdictions, these frameworks provide a common language and methodology that transcends the variations between common law provinces and Quebec's civil law system, while still allowing for adaptation to specific regulatory environments.

Canadian regulatory bodies have increasingly embraced enterprise risk management principles, though the specific requirements vary significantly by sector. Financial institutions supervised by the Office of the Superintendent of Financial Institutions face explicit expectations around enterprise-wide risk governance, while organizations in other sectors may encounter enterprise risk concepts through corporate governance guidelines, industry-specific regulations, or contractual requirements from larger partners and clients. The Canadian Securities Administrators have issued guidance that touches on enterprise risk considerations for publicly traded companies, but the principles apply equally to private enterprises, cooperatives, and non-profit organizations that recognize the value of systematic risk governance. What unites these various applications is an understanding that boards of directors and senior management bear responsibility not just for managing individual risks but for ensuring that the organization maintains an appropriate overall risk profile aligned with its strategic objectives and stakeholder expectations.

The distinction between enterprise risk management and operational risk control deserves careful examination because confusion on this point undermines many organizations' efforts to implement comprehensive risk frameworks. Operational risk control encompasses the policies, procedures, and practices that organizations use to prevent, detect, and respond to specific adverse events within their day-to-day operations. A restaurant implements food safety protocols to prevent contamination incidents. A law firm maintains conflict checking procedures to avoid representing adverse parties. A manufacturing facility conducts equipment maintenance to prevent breakdowns that would halt production. These controls are essential, and no enterprise risk management framework can succeed without a foundation of effective operational controls. However, operational risk control alone cannot provide the strategic perspective that enterprise risk management offers.

Consider the fundamental differences in scope, perspective, and purpose. Operational risk control typically focuses on preventing negative outcomes within defined processes or activities, asking questions like what could go wrong with this specific operation and how do we prevent it. Enterprise risk management expands this lens to consider how risks across the entire organization interact, how the organization's risk profile aligns with its strategic objectives, and how much risk the organization should accept in pursuit of its goals. Where operational risk control tends to be defensive, seeking to prevent harm, enterprise risk management encompasses both the downside of risk and the upside, recognizing that excessive risk aversion can be just as damaging as inadequate risk controls. A technology company that refuses to invest in new product development because of uncertainty about market acceptance may face a greater strategic risk from obsolescence than it would from a failed product launch.

The temporal orientation also differs markedly between these two approaches. Operational risk controls tend to focus on current processes and near-term threats, ensuring that today's activities proceed safely and effectively. Enterprise risk management extends the horizon considerably further, asking what risks might emerge over the next three, five, or ten years, and how current strategic decisions might create or mitigate those future risks. For Canadian organizations facing long-term shifts in workforce demographics, technological disruption, climate-related physical and transition risks, and evolving regulatory expectations, this forward-looking perspective proves invaluable. A construction company evaluating whether to expand into modular building techniques must consider not just the immediate operational risks of learning new methods but also the strategic risk of being left behind if the market shifts decisively toward these approaches.

Governance structures surrounding enterprise risk management differ substantially from those appropriate for operational risk control. Operational controls typically reside with line management and functional specialists, accountants manage financial controls, safety officers manage workplace hazard controls, and IT staff manage cybersecurity controls. Enterprise risk management, by contrast, requires engagement from the board of directors and senior executive team, who must set risk appetite, allocate resources to risk management activities, and ensure that risk considerations inform strategic decision-making. This does not mean that operational managers become irrelevant to enterprise risk management; rather, their insights feed into a broader process that aggregates, analyzes, and acts on risk information across the organization. For smaller organizations that may lack formal board structures, the principle still applies: whoever holds strategic decision-making authority must engage with enterprise risk considerations rather than delegating risk thinking entirely to operational managers.

The cultural implications of enterprise risk management extend well beyond governance structures. Organizations that embrace enterprise risk management cultivate environments where discussing uncertainty, acknowledging potential failures, and questioning assumptions become valued rather than discouraged. This represents a significant shift for many Canadian organizations where historical cultures may have emphasized confident optimism and penalized those who raised concerns about potential problems. The practical reality is that organizations cannot manage risks they refuse to acknowledge, and enterprise risk management demands honest assessment of vulnerabilities alongside celebration of strengths. Building this culture requires consistent messaging from leadership, demonstrated willingness to hear bad news without punishing messengers, and systems that reward thoughtful risk identification rather than only successful risk avoidance.

Understanding how Canadian organizations actually encounter these concepts in practice helps clarify their significance. Many organizations first engage with enterprise risk thinking when external stakeholders demand it. A mid-sized manufacturer seeking financing from a major bank may discover that the bank's credit assessment includes questions about how the company identifies and manages strategic risks. A non-profit applying for significant foundation funding may encounter grant requirements that include demonstrating board-level risk oversight. A professional services firm pursuing government contracts may find that procurement processes increasingly evaluate bidders' risk management capabilities. These external demands often catalyze internal reflection about whether existing operational controls, however robust, actually constitute a coherent approach to managing organizational risk.

Other organizations arrive at enterprise risk management through painful experience, having suffered losses that operational controls failed to prevent because the threat emerged from the interaction of multiple factors that no single control addressed. The construction company that lost multiple bids because its estimating, procurement, and project management functions operated independently and made assumptions that conflicted with each other exemplifies this pattern. Each function had its own risk controls, but no mechanism existed to ensure coordination or to identify when individual reasonable decisions combined to create organizational vulnerability. Enterprise risk management provides the framework for recognizing these cross-functional risks and addressing them before they manifest as losses.

Common misunderstandings about enterprise risk management impede effective implementation. Perhaps the most pervasive is the belief that enterprise risk management means creating a risk management department and delegating all risk responsibility to it. While larger organizations may indeed employ dedicated risk management professionals, enterprise risk management fundamentally requires distributed ownership with coordinated oversight. Risk identification must occur throughout the organization, wherever employees, managers, and leaders encounter uncertainty or potential adverse events. The risk management function, where one exists, serves to facilitate, aggregate, analyze, and report rather than to own all risk on behalf of the organization. Smaller organizations without dedicated risk personnel can still implement enterprise risk management principles by ensuring that leadership regularly convenes to discuss risks across functional areas and that strategic planning explicitly incorporates risk considerations.

Another misunderstanding conflates enterprise risk management with insurance purchasing. Insurance represents one possible response to certain categories of risk, those that involve potential financial losses from identified perils, but enterprise risk management encompasses far more. Some significant risks prove difficult or impossible to insure, reputational damage from ethical lapses, strategic obsolescence from technological change, or organizational dysfunction from poor leadership decisions resist transfer through conventional insurance products. Moreover, enterprise risk management addresses opportunity risk, the danger that an organization might miss chances to create value because it failed to recognize and act on emerging possibilities. Insurance provides no protection against opportunities forgone. Effective enterprise risk management positions insurance as one tool among many, valuable for appropriate risks but insufficient as a comprehensive risk strategy.

The relationship between enterprise risk management and compliance obligations generates additional confusion. Organizations subject to regulatory oversight sometimes equate risk management with compliance, viewing both as defensive necessities imposed by external authorities. While compliance with applicable laws and regulations certainly constitutes an element of risk management, reducing enterprise risk management to compliance dramatically undersells its potential value. Compliance represents a minimum standard, what the organization must do to avoid sanctions. Enterprise risk management asks a broader question: what should the organization do to protect and create value for its stakeholders? A construction company compliant with all applicable safety regulations has met its legal obligations but has not necessarily optimized its approach to workforce health and safety if additional voluntary measures might reduce injuries, improve worker retention, and enhance the company's reputation as an employer of choice.

A detailed examination of how these concepts play out in real organizational contexts illuminates their practical significance. Consider a mid-sized healthcare services organization based in Edmonton that provides home care, rehabilitation services, and staffing to long-term care facilities across Alberta and into Saskatchewan. The organization employs approximately two hundred staff, including registered nurses, licensed practical nurses, health care aides, rehabilitation professionals, and administrative personnel. It operates in a sector characterized by significant regulatory oversight, chronic workforce shortages, demanding physical and emotional work, and clients who depend heavily on service continuity. The organization has maintained stable operations for fifteen years and has recently begun exploring expansion into British Columbia.

The organization has long maintained operational risk controls appropriate to its activities. Clinical policies address medication administration, infection control, documentation requirements, and professional scope of practice. Human resources policies cover hiring verification, performance management, and workplace conduct. Financial controls ensure appropriate authorization for expenditures, accurate payroll processing, and timely billing. Safety protocols address the hazards inherent in providing care in diverse home environments, from lifting and transferring clients to responding to behavioural challenges. These controls developed over time in response to regulatory requirements, professional standards, organizational learning from incidents, and insurance company recommendations. They are well documented, regularly reviewed, and generally followed by staff.

Despite these robust operational controls, the organization's executive director and board began recognizing gaps in their approach to risk. Succession planning emerged as a significant concern when the clinical director, who had built many of the organization's most important programs, announced plans to retire within eighteen months. No internal candidate appeared prepared to assume this role, and the market for experienced healthcare managers had grown intensely competitive. The organization's expansion plans raised questions about whether existing systems and controls would function effectively in a new provincial jurisdiction with different regulatory frameworks. Meanwhile, a major client that accounted for nearly thirty percent of revenue had begun signalling dissatisfaction with service consistency, creating anxiety about potential contract loss. Each of these challenges fell outside the scope of any existing operational control. They were strategic and organizational rather than operational and process-oriented.

The board engaged an external consultant to facilitate development of an enterprise risk management framework. The initial exercise involved identifying risks across all organizational functions and assessing them according to likelihood and potential impact. This process revealed that the organization had numerous well-controlled operational risks where existing protocols provided adequate protection, but several strategic and organizational risks had received minimal systematic attention. Beyond the immediate concerns about succession and client retention, the assessment identified workforce recruitment and retention as a pervasive risk affecting service capacity, service quality, and organizational culture. It highlighted the organization's heavy reliance on referrals from a small number of health authority partners, creating concentration risk that could materialize if any partner shifted its service model. It noted cybersecurity vulnerabilities in systems containing sensitive health information, vulnerabilities that existing IT controls addressed only partially.

Perhaps most significantly, the enterprise risk assessment revealed how these various risks interconnected in ways that no operational control addressed. Workforce challenges made succession planning more difficult because fewer internal candidates gained the experience necessary for leadership roles, while also straining existing employees and contributing to burnout. Client dissatisfaction partially stemmed from workforce challenges that created inconsistent staffing. Expansion into British Columbia would exacerbate workforce pressures while creating additional regulatory compliance requirements during a period when leadership capacity was already constrained by succession uncertainties. Viewing these risks in isolation, as operational controls encouraged, obscured the systemic pattern. Only by examining them together could the organization recognize that its fundamental challenge was organizational capacity, the ability to attract, develop, and retain people capable of delivering and leading high-quality care.

This recognition transformed the organization's strategic priorities. Rather than treating succession planning as a human resources project and client retention as a sales problem and expansion planning as an operational matter, the board and executive team began addressing these as interconnected elements of a single organizational challenge. They delayed expansion timelines until leadership transitions stabilized. They invested in career development programs that would create internal succession candidates for multiple roles while simultaneously improving retention. They renegotiated service agreements to reduce the scope of commitments to the dissatisfied client, accepting some revenue reduction in exchange for more achievable expectations. They strengthened relationships with multiple health authority partners to reduce concentration risk. These decisions emerged from enterprise-level thinking about risk and strategy, not from any operational control system.

The implications of this scenario extend well beyond healthcare or any single industry. The pattern it illustrates, robust operational controls coexisting with unaddressed strategic and organizational risks, appears across Canadian sectors. Resource extraction companies may maintain excellent safety records while facing existential questions about long-term commodity demand and regulatory environments. Non-profit organizations may deliver programs effectively while governance weaknesses create vulnerability to leadership transitions or stakeholder conflicts. Professional services firms may manage client relationship risks skillfully while technological disruption threatens their fundamental business model. In each case, operational excellence provides necessary but insufficient protection, and enterprise risk management offers the broader perspective required to identify and address strategic vulnerabilities.

The scenario also reveals that enterprise risk management does not replace operational risk control but rather supplements and directs it. The healthcare organization's clinical policies, financial controls, and safety protocols remained essential throughout its enterprise risk journey. What changed was the strategic context within which those controls operated and the organization's ability to allocate resources and attention appropriately across different categories of risk. Enterprise risk management enabled the organization to recognize that additional investment in clinical documentation protocols, while valuable, mattered less than investment in leadership development given the organization's actual risk profile. Without enterprise risk perspective, the organization might have continued refining operational controls while strategic risks accumulated unaddressed.

Organizations seeking to apply these insights should begin with honest assessment of their current state. What operational risk controls currently exist, and how effective are they? Who holds responsibility for thinking about risks that cross functional boundaries or extend beyond immediate operational concerns? How does risk information flow to those who make strategic decisions? Does the organization's culture encourage candid discussion of uncertainty and potential failures? These questions establish baseline understanding that informs subsequent framework development.

Several specific inquiries help organizations distinguish between their operational risk controls and their enterprise risk management capabilities. Consider whether anyone in the organization systematically considers how different risks might interact or amplify each other. Ask whether strategic planning processes explicitly incorporate risk assessment or whether strategy and risk operate as separate conversations. Examine whether board or senior leadership agendas regularly include discussion of emerging risks beyond immediate operational concerns. Investigate whether the organization has articulated its risk appetite, the amount and types of risk it is willing to accept in pursuit of its objectives. If these activities occur regularly and systematically, the organization likely has at least foundational enterprise risk management capabilities. If they occur sporadically or not at all, the organization primarily relies on operational risk controls, regardless of how sophisticated those controls may be.

Documentation requirements differ between operational risk control and enterprise risk management, though both demand appropriate records. Operational controls typically generate compliance records, safety inspection logs, financial reconciliations, contract review checklists, and similar documentation demonstrating that specified procedures were followed. Enterprise risk management generates strategic documentation, risk assessment reports, board meeting minutes reflecting risk discussions, statements of risk appetite and tolerance, and records of how risk considerations influenced strategic decisions. Organizations building enterprise risk frameworks should consider what documentation they currently maintain and what additional records might demonstrate enterprise-level risk governance to stakeholders including insurers, lenders, regulators, and potential acquirers.

The verification question, ensuring that documented policies translate into actual practice, applies across both domains but manifests differently at each level. Operational control verification typically involves auditing whether specific procedures were followed in specific instances. Enterprise risk management verification asks whether the organization's governance structures actually function as intended, whether information flows appropriately, whether leadership engages meaningfully with risk, and whether enterprise risk considerations actually influence organizational decisions. This higher-level verification often requires qualitative assessment alongside quantitative measures, examining not just what happened but how and why decisions were made.

Enterprise risk management represents neither a bureaucratic burden nor a theoretical abstraction for Canadian organizations willing to engage with it seriously. It offers practical value: better decisions about resource allocation, earlier awareness of emerging threats, more thoughtful pursuit of opportunities, and greater organizational resilience when adverse events occur. The distinction from operational risk control matters because organizations that mistake the latter for the former leave themselves vulnerable to precisely the kinds of systemic risks that operational thinking cannot address. As Canadian organizations navigate an environment characterized by technological acceleration, demographic shifts, climate transitions, and ongoing economic uncertainty, enterprise risk management provides the framework for seeing risks whole rather than in fragments, for connecting strategic ambition to risk reality, and for building organizations capable of thriving amid uncertainty rather than merely surviving it.

Continue with University access

This lesson is part of a $149 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options