How to Develop an Enterprise Risk Management Framework

Photo of author
Written By Chris Ekai

Developing an enterprise risk management framework means building five things in sequence: a board mandate with named owners, a risk appetite and taxonomy, a scored risk register, funded treatments wired to controls, and a monitoring and reporting rhythm. COSO ERM 2017 and ISO 31000:2018 supply the reference models, and a first register is realistic in 90 days.

From late 2021 until November 2, 2024, a single Macy’s accounting employee intentionally concealed small-parcel delivery expenses through false entries, roughly $151 million in total. The retailer found the trail while closing its third-quarter books and had to delay its earnings release.

Macy’s Form 8-K of December 11, 2024 reported the independent investigation’s finding, and CEO Tony Spring told analysts the employee acted alone and sought no personal gain. One person defeated a Fortune 500 control environment for three years because nothing downstream was checking.

Enterprise Risk Management Framework: Key Takeaways
Developing an enterprise risk management framework runs five build stages: mandate and team, appetite and taxonomy, register and assessment, treatment and controls, then monitoring and reporting.
Macy’s disclosed in November 2024 that one employee concealed $151 million in delivery expenses for three years, the textbook cost of an unwired monitoring component.
Only 32% of 273 US organizations rate their risk oversight mature, and 41% name competing priorities as the main barrier, per the 2025 AICPA and NC State survey.
COSO ERM 2017 (five components, 20 principles) and ISO 31000:2018 are the two reference models; NIST IR 8286, COBIT 2019, and the RIMS Risk Maturity Model cover specialist needs.
A first scored register is realistic within 90 days of the board mandate, and a full operating rhythm inside 12 months on the staged plan in this guide.
Organizations that wire risk exposure into capital allocation decisions remain a 30% minority, which is exactly the integration an ERM framework exists to deliver.

That is the case for an enterprise risk management framework rather than a binder of policies. This guide walks through the five build stages, the reference models to borrow from, and the artifacts each stage must leave behind, so the monitoring gap that caught Macy’s never opens in your ledger.

Enterprise risk management framework case study: the Macy's disclosure in four numbers

Figure 1. The Macy’s disclosure in four numbers. Sources: Macy’s Form 8-K, December 11, 2024; CNBC; NPR.

What an Enterprise Risk Management Framework Actually Contains

An enterprise risk management framework is the standing structure that connects risk activity to decisions: who owns which risks, how they get scored, what appetite bounds them, and which reports reach the board. Our overview of what enterprise risk management means covers the discipline; this page covers the build.

The distinction from a process matters in practice. The risk management lifecycle describes the repeating loop of identify, assess, treat, and monitor, while the enterprise risk management framework is the scaffolding around that loop: governance, appetite, taxonomy, roles, and reporting lines that survive staff turnover.

COSO’s ERM framework, updated in 2017 as Enterprise Risk Management: Integrating with Strategy and Performance, organizes all of it into five components and 20 principles. Our component-by-component breakdown goes deep; the table below shows what each component demands in artifacts.

COSO component What it governs What you can show an auditor
Governance and culture Board oversight, operating structures, tone, talent Charter, committee minutes, tone-from-the-top communications
Strategy and objective-setting Appetite, strategy alignment, business objectives Approved risk appetite statement tied to strategy documents
Performance Identification, assessment, prioritization, responses Scored risk register with named owners and treatment plans
Review and revision Assessing change, reviewing risk and performance Annual enterprise risk management framework review notes and revision log
Information, communication, reporting Data, channels, reporting on risk and culture Quarterly board risk pack and KRI dashboard extracts

COSO’s 20 principles read like an audit program on purpose. Principle 7 defines appetite, principle 10 identifies risk, principle 20 reports on risk and culture, and examiners increasingly cite principle numbers in findings, which makes the numbering a shared language between risk teams and their auditors.

ISO 31000:2018 reaches the same destination with different vocabulary: principles, framework, and process, with leadership and commitment at the center. Our guide to what ISO 31000 covers maps its clauses, and the two models blend well because neither is certifiable.

Whichever reference you pick, the test of an enterprise risk management framework is the same. Every risk that can move your income statement has a named owner, a current score, a funded response, and an indicator someone reads before quarter close, with evidence of all four.

Why Enterprise Risk Management Frameworks Fail Before They Start

Most organizations do not lack risk documents; they lack the wiring between them, and the survey data shows how common the gap is. In the 2025 AICPA and NC State State of Risk Oversight survey, 61% of 273 US finance leaders said risk volume and complexity rose sharply, yet only 32% rate their oversight mature.

The same study names the killer: 41% cite competing priorities and resource constraints as the main barrier, and just 30% integrate risk exposure into capital allocation decisions. An enterprise risk management framework that never touches the budget cycle is a framework in name only.

Enterprise risk management framework maturity versus rising risk exposure in US organizations

Figure 2. Exposure is rising faster than enterprise risk management framework maturity in US organizations. Source: AICPA and NC State ERM Initiative, 2025 State of Risk Oversight.

Reputation shows the integration gap from another angle. Just 27% of the surveyed leaders say their ERM process helps manage reputation-impacting risks, even though reputation is the exposure boards ask about most, and the one Macy’s spent December 2024 repairing.

Macy’s makes the abstraction concrete. The company had controls, auditors, and policies, yet a lone employee’s false entries in one expense line ran for three years because the monitoring component was not wired to the anomaly it should have caught, exactly the connection a working enterprise risk management framework exists to force.

We see the pattern repeatedly in enterprise risk management framework reviews: the documents pass inspection individually while the connections between them fail. The appetite statement never constrains a deal, the register never reaches the audit committee, and the KRIs never trigger anything, so the enterprise risk management framework exists everywhere except in decisions.

Choose Your Reference Model First

Before building anything, pick the reference model your regulators and auditors already speak. The choice shapes vocabulary, component names, and what examiners will ask for, and it is far cheaper to decide now than to translate the whole register later.

Reference model Steward Strongest fit Watch out for
COSO ERM 2017 COSO (five sponsoring bodies) US public companies, SOX-trained boards and audit committees Heavy to implement in full; 20 principles invite box-checking
ISO 31000:2018 ISO Global operations, any sector or size; pairs with ISO management systems Deliberately generic; you supply all specificity
NIST IR 8286 + CSF 2.0 NIST Wiring cyber risk into enterprise reporting, US federal suppliers Cyber-centered; needs a general model around it
COBIT 2019 ISACA IT governance and technology-heavy enterprises Framed for IT; business units find it foreign
RIMS Risk Maturity Model RIMS Scoring current maturity and setting improvement targets An assessment yardstick, never a complete build recipe

Two pairings cover most US organizations. Public companies usually anchor on the COSO ERM framework for board familiarity, then borrow the process discipline of ISO 31000; technology-led firms add NIST IR 8286, revised in December 2025 to align with CSF 2.0, for the cyber-to-enterprise bridge.

COBIT 2019 earns its slot where IT governance dominates the risk profile, and the RIMS Risk Maturity Model works best as a before-and-after yardstick around any of the others. Blending is normal; auditors care about coverage and evidence, never brand loyalty.

A common blend in practice: COSO component names for board reporting, the ISO 31000 process clauses for the working method, and NIST vocabulary inside the technology register. Documented in one page, the mapping costs an afternoon and saves every future audit conversation.

The head-term guide to our enterprise risk management framework coverage compares these models component by component. Whichever you choose, hold the vocabulary steady afterward, because renaming components mid-build is how steering committees lose an entire working quarter to relabeling exercises.

The Five-Stage Build: From Mandate to Operating Rhythm

With a reference model chosen, the build itself runs five overlapping stages. The timeline below is the realistic mid-market pace: a first scored register inside 90 days, a full operating rhythm inside 12 months, and no stage waiting for the previous one to finish completely.

Two rules keep the plan honest. Stages overlap by design, because appetite drafting informs workshops and register findings refine appetite, and every stage ends by producing an artifact the next stage consumes, which is how you know it actually finished.

12-month enterprise risk management framework build plan with overlapping stages

Figure 3. A 12-month enterprise risk management framework build with overlapping stages. Illustrative plan based on the staged sequence in this guide.

Stage 1: Secure the Mandate and Build the Team (Weeks 0-6)

Nothing durable gets built on borrowed authority. Ask the board or executive committee for a one-page mandate that names the accountable executive, the steering committee, the reporting cadence, and the first-year scope, because that page settles every turf argument the next eleven months will produce.

  • Scope for year one: which entities, risk categories, and decisions the enterprise risk management framework covers first
  • Names: the accountable executive, steering committee seats, and the board reporting line
  • Cadence: steering committee monthly, board quarterly, full enterprise risk management framework review annually
  • Authority: who may accept a red risk, and who signs appetite exceptions

Write it as one page and date it. The mandate is the artifact Stage 5’s annual review re-approves, and the page auditors ask for first when they test governance, so brevity with signatures beats a long policy nobody actually signed.

Staff the steering committee with operators who own profit and loss, systems, and people, plus finance, legal, and technology. The three lines of defense model and the IIA’s Three Lines Model position everyone: management owns risk, the risk function coordinates method, internal audit stays out of the build so it can review it later.

Role Accountability in the enterprise risk management framework build
Board or risk committee Approves mandate, appetite, and the annual enterprise risk management framework review; receives the quarterly risk pack
Accountable executive (CRO, CFO, or COO) Owns the build plan, chairs the steering committee, reports progress to the board
Business unit leaders Own their risks and treatments; supply workshop participants who run the processes
Risk function (even one person) Sets method, keeps the register, challenges scores, assembles reporting
Internal audit Stays independent of the build; audits the enterprise risk management framework once it runs

Stage 2: Set Appetite and Build the Taxonomy (Weeks 4-16)

Appetite comes before identification, because appetite decides what matters. Draft it in measurable bands using our board-ready appetite statement guide and the sector examples, and keep the appetite, tolerance, and capacity distinctions straight, since boards sign the first and management works the second.

The taxonomy is the enterprise risk management framework’s filing system: the fixed set of categories every risk lands in, so two plants never log the same exposure under different names. Six to nine top-level categories cover most organizations, each split one level down and no further at this stage.

Category Typical second level Example appetite band
Strategic Market shifts, M&A, product bets, reputation Moderate: accepted with board visibility
Operational Process failure, safety, supply chain, fraud Low: active reduction funded
Financial Credit, liquidity, market, reporting accuracy Low: hard tolerance limits
Technology and cyber Availability, security, data, vendor concentration Low: KRI thresholds enforced
Compliance and legal Regulatory change, contracts, licensing Minimal: zero tolerance for breaches
People Key-person loss, talent, conduct, culture Moderate: succession plans required
External and environmental Natural events, geopolitical shifts, economic cycles, ESG expectations Moderate: scenario plans maintained

The Macy’s entry belongs under financial reporting accuracy with a fraud cross-reference, which is the point of the exercise. A taxonomy that forces the awkward what-if conversations during design is doing its job before a single risk is formally scored.

Freeze the taxonomy under change control once workshops begin. Every category edit after that point reshuffles scores and dashboards downstream, so route changes through the steering committee with an effective date, and never let each workshop rename its own world.

Stage 3: Populate and Score the Register (Weeks 10-28)

Identification workshops now fill the taxonomy with real exposures. Run them with the people who operate the processes, use the prompt sets in our risk identification tools and techniques guide, and log everything in a register built on the fields auditors expect.

  • Pull three years of incidents, near misses, write-offs, and insurance claims before the first workshop
  • Flag every single point of failure: sole vendors, key people, one warehouse, one payment processor
  • Interview the board and executives separately; strategic risks rarely surface in operational workshops
  • Cross-check the draft register against the taxonomy for empty categories, which usually mean blind spots
  • Ask every workshop the Macy’s question: which numbers here does only one person ever touch?

Facilitate for candor. Run workshops without the department head in the room at least once, promise anonymity for the first draft, and write risks in the participants’ words before polishing, because sanitized language at this stage becomes institutional blindness later.

Score likelihood and impact against criteria agreed before the workshops, on a five-by-five matrix for the first pass, with IEC 31010:2019 supplying heavier techniques where single numbers carry weight. The output is a ranked queue, and the ranking is only credible if nobody scored their own risk unchallenged.

Score twice and label which is which. Inherent scores justify why a control exists, residual scores drive today’s ranking, and mixing the two in one column is the fastest way to make a register unusable for the capital conversation in the next section.

Use the register template if you are starting from a blank sheet. A workable first register holds 25 to 60 enterprise-level risks; three hundred rows at this stage means the taxonomy failed or the workshops never climbed out of the weeds.

A Worked Register Entry to Copy

Abstract fields become clear the moment one risk is written out properly. The entry below takes the Macy’s-style exposure, concealment capacity in a single expense line, and shows the wording a working register would carry for it, field by field, scored and owned.

Register field Entry for the concealed-expense risk
Risk name Material misstatement through manipulation of a single expense account with one preparer and no independent reconciliation
Category Financial: reporting accuracy, cross-referenced to operational fraud
Cause and effect Cause: single-preparer access, no rotation. Effect: restated results, delayed filings, audit and legal cost, credibility damage
Scores Inherent: likelihood 4, impact 4. Residual after controls: likelihood 2, impact 4, amber band
Treatment Reduce: preparer rotation, independent monthly reconciliation, anomaly analytics on expense variance. Owner: corporate controller
Monitoring KRI: unreconciled variance days open; red at 20 days; breach escalates to the CFO the same week

Notice the altitude: specific enough to name the ledger behavior, general enough to survive reorganizations. Sixty entries at this quality beat three hundred at the one-word level, and they are what Stage 5’s indicators attach to when monitoring starts running for real.

Stage 4: Fund Treatments and Wire the Controls (Weeks 20-40)

Every red and amber risk now gets a documented decision: accept inside appetite, avoid, reduce, or transfer. Each choice cites the appetite line that authorizes it, carries a named owner and budget, and lands in the plan the steering committee tracks to a date.

Wiring means the control cannot fail silently. Macy’s teaches the lesson: a reconciliation someone must sign, an anomaly report someone must read, and an escalation that fires without human goodwill are what separate a control environment from a control document.

Balance the control mix deliberately. Preventive controls stop the event, detective controls find it fast, and directive controls tell people what to do, and Macy’s shows why the detective layer deserves equal budget: prevention failed quietly for three years while nothing was looking.

Transfer needs the same wiring as any control. Map every major policy to the register entries it covers, diary the renewal dates against treatment reviews, and read exclusions in the room with the risk owner, because sublimits discovered at claim time are Stage 4 failures.

Test before declaring victory. A restore that has never run, a fallback kit nobody drilled, and a second signature nobody checks are props, and the risk management lifecycle guide covers the treatment mechanics in clause-level depth for teams that want the full method.

Stage 5: Stand Up Monitoring and Reporting (Weeks 30-52)

Monitoring converts the register from a record into an instrument. Pick key risk indicators for every top risk, borrow tested definitions from the 150-indicator KRI library, and set green, amber, and red thresholds that trace to the appetite bands from Stage 2.

Indicator (example set) Green Amber Red
Unreconciled expense variance, days open Under 10 10 to 20 Over 20
Top-10 risks with treatments past due Zero 1 to 2 3 or more
Single-source vendors without exit plans Under 5% 5 to 10% Over 10%
KRIs breaching threshold two straight months Zero 1 2 or more
Register entries older than their review date Under 5% 5 to 15% Over 15%
Identification workshops held against annual plan 100% 80 to 99% Below 80%
  • A red threshold held two consecutive periods goes to the accountable executive with a dated plan
  • Any new single point of failure discovered in operations reopens identification for that category
  • A control test failure downgrades the risk’s status until the retest passes
  • Two amber quarters on one indicator force a treatment review, never a third quarter of watching

Report on one page: trend against appetite, threshold breaches, and the single decision requested. The formats in our board-ready ERM dashboards and KRI dashboard examples translate register data into that language, and our guide on register update cadence keeps the underlying data honest between meetings.

Cadence beats volume in reporting. Monthly for the risk function, quarterly for the board, annually for the full enterprise risk management framework review, and out-of-cycle the moment a red threshold or a material incident fires, with each level receiving less detail and more decision.

The 90-Day Compressed Version for Smaller Organizations

Smaller organizations can compress the whole sequence into a quarter without losing the discipline. The table shows the honest minimum: one page of appetite, a 25-risk register, five indicators, and a leadership review that meets on a fixed schedule every quarter.

Weeks Action Artifact produced
1-2 Executive sponsor named; one-page mandate signed Mandate memo
3-4 Appetite bands drafted for six taxonomy categories One-page appetite statement
5-8 Two identification workshops plus incident-history review Draft 25-risk register
9-10 Scoring session with challenge; top ten ranked Scored register and ranked queue
11-12 Treatments funded for reds; five KRIs defined Treatment plan and KRI sheet
13 First leadership risk review runs the full agenda One-page risk report

Everything else, software, maturity models, deeper quantification, can wait for year two. What cannot wait is the habit: the same one-page report, the same challenge questions, and the same review date every quarter, because the rhythm is the enterprise risk management framework in miniature.

Wiring the Enterprise Risk Management Framework Into Decisions That Move Money

An enterprise risk management framework proves itself in the budget cycle, and most have never been there. Only 30% of surveyed organizations integrate risk exposure into capital allocation, which means seven in ten build business cases with no reference to the register their own risk team maintains.

Three wiring points close that gap. Capital requests above a threshold cite the register entries they raise or retire; the annual plan allocates treatment budgets against the ranked queue; and M&A or new-market proposals attach an appetite check the board can see before approval.

Regulation is pushing the same direction. The SEC’s cybersecurity disclosure rules require public companies to describe risk management processes and board oversight in annual reports, and disclosure written from a live enterprise risk management framework reads visibly better than disclosure drafted around the absence of one.

Private companies feel the same pull through counterparties. Lenders price credit against risk governance, cyber insurers demand control evidence at renewal, and enterprise customers send diligence questionnaires that quote framework language, so the register increasingly earns revenue as well as protecting it.

Tooling comes last, on purpose. Choose from our ERM platform comparison only after Stage 5 runs manually for a quarter, because software accelerates a working enterprise risk management framework and embalms a broken one; the same sequencing logic applies to the tech-risk stack in our IT risk management lifecycle guide.

Seven Traps That Derail Enterprise Risk Management Framework Rollouts

The failure patterns repeat across sectors and sizes, and most of them trace back to a stage that was skipped or rushed early in the build. Each row names the trap, the stage where it takes root, and the correction that has worked in practice.

Trap Where it starts Correction
Framework launched by memo, not mandate Stage 1 skipped One-page board mandate naming the accountable executive and cadence
Appetite written after the register Stage 2 out of order Draft appetite first; scores need bands to mean anything
Risks named at one-word altitude Stage 3 workshops with executives only Name the asset, vendor, process, or ledger line that actually fails
Every risk scored, treatments unfunded Stage 4 never resourced No red risk leaves the meeting without an owner, budget, and date
KRIs chosen because data was handy Stage 5 built backward Derive indicators from appetite bands, then find or build the data
Board pack lists 40 risks a quarter Reporting built to show effort One page: trend, breaches, and the one decision being requested
Software bought before the method works Tooling as a substitute for design Run one manual quarter, then buy against proven requirements

The Enterprise Risk Management Framework Questions Boards and Executives Keep Asking

What are the components of an enterprise risk management framework?

COSO’s 2017 model names five: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication, and reporting, expanded through 20 principles. ISO 31000 wraps similar content in leadership, integration, design, implementation, evaluation, and improvement; both reduce to owners, appetite, register, controls, and reporting.

How long does it take to develop an enterprise risk management framework?

Plan on a first scored register inside 90 days and a full operating rhythm, monitoring and board reporting included, inside 12 months. Organizations rarely fail on speed; they fail by launching everything at once instead of running the five stages in overlapping sequence.

Should an enterprise risk management framework follow COSO or ISO 31000?

US public companies usually anchor on COSO because boards and auditors already speak it, then borrow ISO 31000’s process discipline. Neither is certifiable, so blending carries no compliance penalty, and examiners test evidence and coverage rather than which logo sits on the binder.

How much does an enterprise risk management framework cost to build?

The dominant cost is people time: a part-time accountable executive, a coordinator, and workshop hours across the business, with software optional in year one. The 2025 AICPA and NC State survey found 41% of organizations citing competing priorities as the barrier, so the honest budget line is attention.

Who should own the enterprise risk management framework?

One accountable executive owns the enterprise risk management framework, typically the CRO where the role exists, otherwise the CFO or COO, with the board approving mandate and appetite. Individual risks belong to the leaders who run the affected processes, and internal audit reviews the enterprise risk management framework without helping to build it.

How does an enterprise risk management framework differ from a risk management policy?

The policy is one artifact inside the enterprise risk management framework: the rules document stating principles, appetite authority, and responsibilities. The enterprise risk management framework is the working system around it, including the register, taxonomy, KRIs, committee cadence, and reporting, which is why organizations with excellent policies still fail audits on evidence.

Can a small company run an enterprise risk management framework?

Yes, scaled honestly: a 25-risk register, one page of appetite bands, a quarterly leadership review, and five KRIs deliver the full loop without a risk department. The five stages compress to a single quarter, and the discipline of named owners and review dates matters more than any of the paperwork volume.

How do you measure whether an enterprise risk management framework works?

Track usage, not existence: the share of capital requests citing register entries, treatments closed by their dates, KRI breaches escalated on time, and surprises that bypassed the register entirely. The RIMS Risk Maturity Model provides an external yardstick, and a falling surprise count is the measure boards actually feel.

The Regulatory and Technology Horizon

Expect disclosure pressure to keep compounding. The SEC’s process-description requirements already read like an enterprise risk management framework audit for public companies, and the same expectations flow down to private firms through lenders, insurers, and enterprise customers who now ask for register extracts during diligence.

AI will land on both sides of your enterprise risk management framework within a budget cycle. Gartner’s $6.37 trillion 2026 IT spending forecast is pushing model inventories into risk registers, while the same tooling starts drafting anomaly reports of the kind that would have caught a three-year expense concealment in month two.

The revision cadence of the reference models has quickened too, with NIST refreshing the IR 8286 series in December 2025 to track CSF 2.0. Treat your enterprise risk management framework the same way: an annual review with a revision log, because an enterprise risk management framework that cannot change is just next year’s audit finding.

Treat maturity as a curve you re-score annually. The RIMS model gives you the yardstick, the revision log gives you the trail, and a board that watches the score move stops asking whether the enterprise risk management framework is worth its annual budget.

Start with the mandate page and the 90-day register, and the rest follows the sequence above. We build enterprise risk management frameworks with boards and risk teams through our advisory services, so if the build needs a second pair of hands, contact us and we will walk your draft mandate through the five stages together.