← University
Building an Enterprise Risk Framework
0 of 6

A regional non-profit organization in southern Alberta that provides employment training and supportive housing services has operated for 22 years, growing from a small charitable initiative into an organization with an annual operating budget of $4.8 million, 47 full-time staff, and 3 service locations across 2 municipalities. The organization holds service contracts with 2 provincial ministries, receives funding from 4 corporate donors and a community foundation, and maintains a portfolio of 6 residential properties that house program participants. Its board of directors consists of 9 volunteer members drawn from the local business, legal, and social services communities.

During a board governance review conducted in response to concerns raised by the organization's external auditor, directors discovered that risk management across the organization existed in disconnected pockets with no coordinating structure. The finance team maintained a spreadsheet tracking accounts receivable aging and cash flow projections. The housing program manager kept an informal log of building maintenance issues and tenant complaints. The human resources coordinator had developed a checklist for workplace safety incidents. The information technology contractor who visited twice monthly had flagged cybersecurity vulnerabilities in 3 separate reports over 18 months without receiving a formal response from management. None of these activities connected to one another, to the organization's strategic plan, or to regular board deliberations.

The governance review also revealed that 2 of the organization's ministry contracts contained new provisions requiring funded agencies to demonstrate formalized risk management practices by the next contract renewal period, now 14 months away. The board chair, a retired manufacturing executive, recalled that the company where she had spent her career had implemented an enterprise risk management framework after a supply chain crisis, but she was uncertain how such an approach would translate to a non-profit context with different stakeholders, funding structures, and accountability relationships.

The executive director, who had led the organization for 8 years, acknowledged that risk conversations tended to arise only after problems materialized rather than through any systematic anticipation. A recent incident illustrated the point: a data breach affecting 340 client records had prompted a reactive scramble rather than an execution of pre-established protocols, because no such protocols existed. Staff members in different departments had responded based on their own judgment, with inconsistent messaging to affected clients and no clear escalation path to the board.

The board directed the executive director to develop a proposal for implementing an enterprise-wide approach to risk management, with attention to available frameworks, governance structures, resource requirements, and the cultural changes necessary to embed risk awareness throughout the organization.

Common ERM Implementation Failures and How to Avoid Them

Enterprise risk management represents one of the most powerful tools available to Canadian organizations seeking to navigate uncertainty, protect stakeholder value, and position themselves for sustainable growth. Yet despite decades of refinement in frameworks, standards, and methodologies, the implementation of enterprise risk management programs fails with remarkable frequency. Studies consistently suggest that between forty and seventy percent of enterprise risk management initiatives either fail outright or deliver significantly less value than anticipated. For Canadian small and medium-sized businesses, non-profit organizations, and professional services firms, these failures carry particularly acute consequences because resources invested in failed implementations cannot easily be recovered, and the organizational appetite for attempting another risk management initiative typically diminishes substantially after an initial failure.

Understanding why enterprise risk management implementations fail requires examining both the technical and human dimensions of organizational change. The technical failures often receive the most attention because they are easier to identify and discuss. Software systems prove incompatible with existing infrastructure. Risk taxonomies fail to capture the actual risks facing the organization. Reporting mechanisms generate data that nobody uses. These technical failures, however, almost always trace back to more fundamental human and organizational failures that precede them. The most sophisticated risk management software in the world cannot compensate for an organization that has not genuinely committed to embedding risk thinking into its operations, governance, and culture.

The International Organization for Standardization's ISO 31000:2018 Risk Management Guidelines, as of the date of authorship, provides a principles-based framework that emphasizes integration, structured approaches, customization, inclusiveness, and continuous improvement. The Committee of Sponsoring Organizations of the Treadway Commission framework, commonly known as COSO ERM, offers a more detailed component-based approach that many larger Canadian organizations adopt. Both frameworks acknowledge, either explicitly or implicitly, that implementation represents the critical challenge. Having an elegant framework document sitting in a shared drive accomplishes nothing if the organization does not genuinely operationalize its principles. Canadian organizations operating under federal regulatory oversight, such as those in financial services regulated by the Office of the Superintendent of Financial Institutions, or those in sectors governed by provincial securities regulators, often find that regulatory expectations push them toward formal enterprise risk management adoption. Yet even regulatory pressure does not guarantee successful implementation.

The first and perhaps most consequential failure mode involves treating enterprise risk management as a compliance exercise rather than a value-creation tool. This failure manifests when organizations approach risk management primarily as something they must do to satisfy regulators, auditors, or governance requirements rather than something that genuinely helps them make better decisions. The symptoms of this failure mode are unmistakable. Risk registers become elaborate exercises in documentation that nobody consults when making actual business decisions. Risk assessments occur on annual cycles disconnected from operational reality. Risk reports flow upward to boards and committees but generate no meaningful discussion or action. Staff members responsible for risk management spend their time producing reports rather than engaging with operational leaders about emerging threats and opportunities.

Organizations falling into this compliance trap often exhibit a pattern where risk management activities intensify immediately before board meetings, regulatory examinations, or audit cycles, then diminish to minimal levels in the intervening periods. This pattern reveals that the organization has failed to integrate risk thinking into ongoing operations and instead treats risk management as a periodic exercise in documentation production. Canadian non-profit organizations sometimes fall into a variant of this pattern where risk management activities concentrate around annual insurance renewals or funding applications rather than operating as continuous processes supporting organizational resilience.

Avoiding this failure requires organizational leaders to articulate clearly and consistently that enterprise risk management exists to improve decision-making across the organization, not merely to satisfy external requirements. This articulation must come from the highest levels of governance and must be reinforced through observable behaviour. When board members ask probing questions about risk implications of strategic proposals, when executives reference risk considerations in explaining decisions, and when operational managers describe how risk thinking shaped their choices, the organization demonstrates genuine integration rather than compliance theatre.

A second common failure involves attempting to implement enterprise risk management without adequate executive sponsorship and governance commitment. Enterprise risk management touches every part of an organization and requires coordination across functional silos, allocation of resources to risk activities, and willingness to make decisions differently than the organization has made them historically. Without sustained commitment from the board of directors and senior executive team, implementation efforts inevitably stall when they encounter the natural organizational resistance that accompanies any significant change initiative.

Inadequate sponsorship often manifests through delegation patterns. An organization might assign enterprise risk management implementation to a mid-level manager or small team without providing them the authority, resources, or access needed to effect genuine organizational change. These individuals find themselves unable to compel busy operational leaders to participate meaningfully in risk assessment activities. They cannot secure budget for necessary technology investments or training programs. They cannot escalate concerns to executive levels when they observe risk management principles being ignored. Eventually, they either abandon the effort or produce a superficial implementation that satisfies documentation requirements while failing to change organizational behaviour.

Canadian professional services firms, including accounting practices, engineering consultancies, and legal organizations, sometimes exhibit a variant of this failure where partnership governance structures distribute authority so widely that no individual partner feels empowered to champion enterprise risk management implementation across the entire organization. Each practice group or office location may develop its own risk management approaches, resulting in fragmentation rather than enterprise-wide integration.

Successful implementations require visible, sustained executive sponsorship where senior leaders consistently communicate the importance of enterprise risk management, allocate necessary resources, participate personally in key risk activities, and hold others accountable for meaningful engagement. Governance structures must include clear risk oversight responsibilities at the board level, with appropriate committee mandates and reporting relationships that ensure risk considerations inform strategic decisions.

A third failure mode involves selecting or designing risk management frameworks that do not fit the organization's actual operations, culture, and capabilities. Organizations sometimes adopt sophisticated frameworks designed for large multinational corporations without adapting them for their own scale, complexity, and resource constraints. A twelve-person professional services firm in Saskatoon does not need the same risk infrastructure as a major national financial institution. Attempting to implement such infrastructure creates administrative burden disproportionate to any value generated, breeds frustration among staff required to participate in elaborate processes that feel disconnected from their actual work, and ultimately leads to abandonment or superficial compliance.

The opposite error also occurs. Organizations sometimes adopt risk management approaches so minimal that they fail to capture genuinely material risks or provide meaningful support for decision-making. A construction company operating across multiple provinces with hundreds of employees and complex supply chain relationships cannot manage enterprise risk through an annual meeting where managers discuss whatever concerns come to mind. The scale and complexity of operations demand more structured approaches.

Finding appropriate fit requires honest assessment of organizational characteristics including size, geographic scope, regulatory environment, risk complexity, available resources, and existing organizational culture. Canadian resource extraction companies operating in remote locations face risk profiles fundamentally different from urban professional services firms. Healthcare organizations must address patient safety, privacy, and regulatory compliance considerations that differ substantially from risks facing manufacturing operations. Non-profit organizations dependent on government funding face risks around policy changes, funding cycles, and stakeholder relationships that commercial enterprises do not encounter in the same way.

Customization should preserve core risk management principles while adapting specific processes, tools, and governance structures to organizational realities. A small non-profit might implement enterprise risk management through quarterly discussions among senior staff using a simple spreadsheet-based risk register, while a larger construction company might require dedicated risk personnel, specialized software, and formal committee structures. Both approaches can embody sound risk management principles while reflecting very different operational contexts.

A fourth failure mode involves treating risk identification and assessment as primarily technical exercises divorced from the judgment and experience of people who actually understand organizational operations. This failure often occurs when organizations hire external consultants or assign technically skilled analysts to conduct risk assessments without adequate involvement from operational leaders who understand how the organization actually functions, what keeps them awake at night professionally, and what contextual factors shape the likelihood and impact of various risk events.

Risk assessments produced through primarily technical processes often generate comprehensive-looking documents that fail to capture the most significant risks facing the organization. The assessments may identify generic risks common to all organizations of a certain type while missing specific risks arising from particular strategies, relationships, geographic exposures, or operational approaches unique to the organization. They may assess likelihood and impact using standardized criteria that do not reflect organizational realities. They may fail to identify risk interdependencies and cascading effects that operational leaders would recognize immediately if asked the right questions.

Consider a scenario involving a mid-sized manufacturing company headquartered in Hamilton with production facilities there and in Calgary. The company produces specialized components for the automotive and aerospace sectors, operating with approximately three hundred employees across both locations. Following pressure from its primary automotive customer to demonstrate formal risk management capabilities, the company's board directed management to implement an enterprise risk management program.

Management engaged a consulting firm to conduct an initial risk assessment and design an appropriate framework. The consultants worked primarily with the chief financial officer and human resources director, interviewing each operational leader once for approximately forty-five minutes. They produced a comprehensive risk register identifying over one hundred risks organized into categories including strategic, operational, financial, compliance, and reputational. Each risk was assessed using a standard five-by-five likelihood and impact matrix. The final report included a heat map showing risk distribution, recommended risk response strategies, and a proposed governance structure.

The implementation proceeded according to the consultants' recommendations. A risk committee was established with the chief financial officer as chair. Quarterly risk reporting was instituted. Risk owners were assigned for each identified risk. Department heads were required to review and update their assigned risks before each quarterly committee meeting.

Within eighteen months, the enterprise risk management program had become an administrative exercise that consumed significant staff time without generating meaningful value. Department heads completed their quarterly risk updates in fifteen to twenty minutes immediately before deadlines, making minimal changes to assessments. The risk committee meetings lasted approximately thirty minutes, during which the chief financial officer reviewed the heat map, noted any changes from the previous quarter, and adjourned. No operational decisions referenced risk register contents. When a significant quality issue emerged affecting a major automotive customer, the response was entirely ad hoc despite quality risks appearing on the risk register.

The failure in this scenario traced to several interrelated causes. The initial risk assessment process did not engage operational leaders deeply enough to capture their understanding of genuine organizational risks. The brief interviews generated generic risk categories rather than specific, contextual risk understanding. The consulting firm applied a standardized methodology without adequate customization for the organization's specific operations, customer relationships, and competitive environment. The assigned risk owners never understood why they were assigned particular risks or how they were expected to manage them. The governance structure placed risk oversight with a chief financial officer whose primary focus lay elsewhere and who treated risk committee responsibilities as administrative overhead rather than strategic priority.

What this scenario reveals is that successful enterprise risk management implementation requires genuine organizational engagement from the earliest stages. Risk identification must draw on the knowledge and experience of people throughout the organization who understand operations at granular levels. The initial investment in engaging operational leaders yields risk assessments that actually capture organizational reality rather than generic risk categories. When people throughout the organization participate meaningfully in risk identification, they develop ownership over the resulting framework and understand their role in managing identified risks.

The scenario also demonstrates the importance of governance structures that place risk oversight with individuals who have both authority and genuine commitment to making risk management succeed. Assigning oversight responsibilities to already-overburdened executives as additional duties virtually guarantees that risk management becomes a lower priority squeezed into whatever time remains after more pressing demands receive attention.

A fifth failure mode involves implementing enterprise risk management as a one-time project rather than an ongoing organizational capability. Organizations sometimes invest significant resources in initial implementation, producing risk frameworks, governance structures, risk registers, and reporting mechanisms, then declare implementation complete and move organizational attention elsewhere. Without sustained focus, the initial implementation deteriorates. Risk registers become outdated as organizational circumstances change. Governance processes become routine exercises rather than genuine oversight mechanisms. Staff members who participated in initial implementation leave the organization, taking institutional knowledge with them.

Enterprise risk management must be understood as a permanent organizational function requiring ongoing investment, not a project with a defined end date. Risk environments evolve continuously. New risks emerge while others diminish. Organizational strategies change, creating new risk exposures. Regulatory requirements shift. Technological developments create both new risks and new risk management capabilities. An enterprise risk management framework appropriate for an organization in 2024 may require substantial revision by 2026 to remain effective.

Sustaining enterprise risk management capabilities requires embedding risk responsibilities into job descriptions and performance expectations across the organization. It requires ongoing training and awareness activities that reinforce risk thinking and build capabilities over time. It requires governance attention that treats risk oversight as a permanent agenda item rather than an occasional topic. It requires periodic review and refresh of risk frameworks, taxonomies, and processes to ensure continued relevance.

Canadian organizations operating in sectors experiencing rapid change face particular challenges in maintaining current risk frameworks. The transition toward renewable energy affects organizations throughout resource extraction, utilities, and related sectors. Technological change including artificial intelligence capabilities affects professional services, manufacturing, and virtually every sector. Evolving privacy requirements under the Personal Information Protection and Electronic Documents Act at the federal level and equivalent provincial statutes, as of the date of authorship, create compliance challenges requiring ongoing attention. Organizations cannot address these evolving risk landscapes through static frameworks developed years earlier.

A sixth failure mode involves failing to connect enterprise risk management to strategic planning and decision-making processes. Even organizations with well-designed risk frameworks and strong governance commitment sometimes fail to integrate risk considerations into the actual decisions that shape organizational direction. Strategic planning processes proceed without systematic consideration of risk implications. Major initiatives launch without formal risk assessment. Investment decisions reflect opportunity analysis without corresponding risk analysis.

This integration failure often results from organizational design that separates risk management from strategy functions. When risk resides in compliance or finance functions disconnected from strategic planning, the risk perspective may simply not appear when strategy discussions occur. Even when risk representatives participate in strategy discussions, they may be positioned as after-the-fact reviewers rather than integral participants in strategy development.

Genuine integration requires risk considerations to inform strategic choices from their earliest stages. When organizations evaluate potential acquisitions, enter new markets, develop new products, or undertake major capital investments, risk assessment should proceed alongside opportunity assessment. This does not mean that organizations should avoid all risks or select only the lowest-risk alternatives. Rather, it means that risk-informed decision-making considers both upside potential and downside exposure, enabling conscious choices about which risks to accept, which to mitigate, and which to avoid entirely.

Organizations seeking to improve risk integration into strategic processes should examine their strategic planning cycles and identify specific points where risk assessment can add value. Major strategic initiatives should include formal risk assessment as a standard component of the approval process. Post-implementation reviews should evaluate whether anticipated risks materialized and whether risk responses proved effective. These practices embed risk thinking into organizational routines rather than treating it as a separate administrative function.

The application of these lessons requires Canadian organizations to approach enterprise risk management implementation with clear-eyed understanding of common failure modes and conscious strategies to avoid them. Organizations should begin by ensuring genuine executive commitment exists before launching implementation efforts. They should design frameworks appropriate to their scale, complexity, and operational context rather than adopting sophisticated approaches that exceed their needs or minimal approaches that fail to capture material risks. They should engage operational leaders deeply in risk identification to capture genuine organizational knowledge rather than producing generic risk categories. They should establish governance structures that place risk oversight with individuals possessing both authority and commitment. They should plan for ongoing capability maintenance rather than treating implementation as a one-time project. They should consciously integrate risk considerations into strategic planning and major decision-making processes.

Organizations can evaluate their current enterprise risk management approaches against these failure modes through structured self-assessment. Leaders should ask whether risk management activities generate genuine value for operational decisions or primarily satisfy compliance requirements. They should examine whether executive sponsorship remains active and visible or has diminished since initial implementation. They should consider whether their framework fits organizational scale and complexity. They should evaluate whether risk registers reflect genuine operational knowledge or generic categories. They should assess whether risk management receives sustained attention or operates cyclically around governance calendar events. They should determine whether strategic decisions systematically incorporate risk considerations.

Documentation supporting enterprise risk management should include not only the framework itself and resulting risk registers but also records demonstrating ongoing engagement. Meeting minutes should reflect substantive discussion rather than perfunctory review. Risk assessments should show evolution over time as organizational circumstances change. Training records should demonstrate ongoing capability development. Strategic proposals should include explicit risk analysis. These documentation practices both support continuous improvement and demonstrate to external stakeholders that enterprise risk management operates as a genuine organizational capability.

Canadian organizations that navigate these implementation challenges successfully position themselves to realize the genuine value that enterprise risk management can deliver. They make better strategic decisions informed by systematic consideration of both opportunities and risks. They respond more effectively to emerging threats because they have developed organizational capabilities for risk identification and response. They build stakeholder confidence through demonstrated risk management maturity. They meet regulatory and contractual requirements not through compliance theatre but through genuinely embedded risk thinking. The investment in avoiding common implementation failures pays returns throughout organizational operations for years following successful implementation.

Continue with University access

This lesson is part of a $149 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options