← University
Building an Enterprise Risk Framework
0 of 6

A regional non-profit organization in southern Alberta that provides employment training and supportive housing services has operated for 22 years, growing from a small charitable initiative into an organization with an annual operating budget of $4.8 million, 47 full-time staff, and 3 service locations across 2 municipalities. The organization holds service contracts with 2 provincial ministries, receives funding from 4 corporate donors and a community foundation, and maintains a portfolio of 6 residential properties that house program participants. Its board of directors consists of 9 volunteer members drawn from the local business, legal, and social services communities.

During a board governance review conducted in response to concerns raised by the organization's external auditor, directors discovered that risk management across the organization existed in disconnected pockets with no coordinating structure. The finance team maintained a spreadsheet tracking accounts receivable aging and cash flow projections. The housing program manager kept an informal log of building maintenance issues and tenant complaints. The human resources coordinator had developed a checklist for workplace safety incidents. The information technology contractor who visited twice monthly had flagged cybersecurity vulnerabilities in 3 separate reports over 18 months without receiving a formal response from management. None of these activities connected to one another, to the organization's strategic plan, or to regular board deliberations.

The governance review also revealed that 2 of the organization's ministry contracts contained new provisions requiring funded agencies to demonstrate formalized risk management practices by the next contract renewal period, now 14 months away. The board chair, a retired manufacturing executive, recalled that the company where she had spent her career had implemented an enterprise risk management framework after a supply chain crisis, but she was uncertain how such an approach would translate to a non-profit context with different stakeholders, funding structures, and accountability relationships.

The executive director, who had led the organization for 8 years, acknowledged that risk conversations tended to arise only after problems materialized rather than through any systematic anticipation. A recent incident illustrated the point: a data breach affecting 340 client records had prompted a reactive scramble rather than an execution of pre-established protocols, because no such protocols existed. Staff members in different departments had responded based on their own judgment, with inconsistent messaging to affected clients and no clear escalation path to the board.

The board directed the executive director to develop a proposal for implementing an enterprise-wide approach to risk management, with attention to available frameworks, governance structures, resource requirements, and the cultural changes necessary to embed risk awareness throughout the organization.

Designing the Framework: Components, Governance, and Ownership

Every organization, whether it generates revenue through commercial operations or pursues a charitable mission, operates within an environment of uncertainty. That uncertainty manifests in countless ways: a key supplier fails to deliver materials on schedule, a cybersecurity breach exposes client data, a change in federal regulation renders a core business process non-compliant, or a trusted employee departs without warning, taking institutional knowledge with them. Managing these uncertainties systematically rather than reactively requires more than good intentions or periodic attention when problems arise. It requires a structured approach that embeds risk awareness into the fabric of organizational decision-making. This structured approach is what practitioners call an enterprise risk management framework, and designing one effectively demands careful attention to its components, the governance structures that support it, and the ownership arrangements that ensure accountability.

The foundation of any enterprise risk management framework rests on the recognition that risks do not exist in isolation. A threat to operational continuity might simultaneously implicate financial stability, regulatory compliance, and reputational standing. Treating these concerns in disconnected silos, where the finance team worries about credit risk while operations focuses on supply chain disruption and human resources monitors workplace safety incidents, creates gaps through which significant exposures can slip undetected. The enterprise approach acknowledges that risks interact, compound, and sometimes offset one another in ways that demand integrated visibility. Standards bodies have codified this insight into formal frameworks that Canadian organizations increasingly adopt. The International Organization for Standardization published ISO 31000, which as of the date of authorship provides principles, a framework, and a process for managing risk that apply across sectors, geographies, and organizational sizes. The Committee of Sponsoring Organizations of the Treadway Commission, commonly known as COSO, developed its Enterprise Risk Management framework, which integrates with internal control considerations and has found particular traction among organizations with significant financial reporting obligations. Neither framework prescribes a single correct structure, recognizing that effective risk management must adapt to organizational context, but both emphasize certain irreducible elements: establishing objectives against which risks can be assessed, identifying events that might affect those objectives, analyzing the likelihood and impact of those events, determining appropriate responses, implementing controls, and maintaining ongoing monitoring and communication.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $149 course — purchasing unlocks it, or sign in if you already have access.