The importance of enterprise risk management is that it is now legally and commercially enforced rather than merely advisable. Delaware courts hold directors personally liable when no board-level system monitors mission-critical risk, the SEC requires registrants to disclose their risk processes, and rating agencies score risk management directly.
Blue Bell Creameries shipped listeria-contaminated ice cream that killed three people in 2015. On June 19, 2019, the Delaware Supreme Court reinstated claims against its directors in Marchand v. Barnhill, holding that the board had no system at all for monitoring food safety.
| Importance of Enterprise Risk Management: Key Takeaways |
| The importance of enterprise risk management is now enforceable. Delaware courts treat a board-level system for monitoring mission-critical risk as a duty, not a best practice. |
| Blue Bell Creameries lost Marchand v. Barnhill in June 2019 because no board-level food safety monitoring existed, after a listeria outbreak that killed three people in 2015. |
| Boeing directors settled Caremark claims for $237.5 million, approved in 2022 and reported as the largest settlement of its kind in Delaware history. |
| Since fiscal years ending on or after December 15, 2023, SEC Item 106 requires registrants to describe their cyber risk processes and their board’s oversight of them. |
| COSO ERM has five components and twenty principles under the 2017 update. The eight-component version most articles still cite was superseded nearly a decade ago. |
| The academic evidence linking ERM to firm value is genuinely mixed, so build the business case on legal, regulatory and rating exposure rather than on a promised valuation premium. |
The detail that decided it was administrative. Management received ten listeria reports in the year before the outbreak and none reached the board, whose minutes never mentioned the subject. The company had food safety staff, and it had no board-level risk oversight.
Two years later the same doctrine reached a far larger balance sheet. Boeing’s directors settled derivative claims over 737 MAX safety oversight for $237.5 million, a figure approved in 2022 and widely reported as the largest Caremark settlement in Delaware history.

Figure 1. The cost of having risk staff but no board-level risk system.
What ERM Is, and What It Replaced
Before the case for it, the definition. Enterprise risk management is the practice of managing risk across an entire organization against a single set of criteria, owned at board level, instead of each function keeping its own private list on its own private scale.
The contrast that matters is with the silo model. In a siloed organization, treasury manages financial exposure, IT manages cyber, operations manages safety, and nobody holds the aggregate or can say which exposure is largest. Our integrated risk management approach guide walks through the shift.
| Dimension | Siloed risk management | Enterprise risk management |
| Ownership | Each function owns its own list | Board owns the aggregate, functions own the entries |
| Scale | Incompatible scoring per department | One impact and likelihood scale across the entity |
| Aggregation | No view of combined exposure | Correlated and concentrated exposures are visible |
| Trigger for action | Whoever notices escalates informally | Defined thresholds route to a named decision owner |
| Evidence produced | Spreadsheets held locally | Dated, approved artifacts a court or regulator can read |
That last row is where the argument of this article begins. The difference between the two columns is no longer a maturity preference, because three separate forces now inspect the right-hand column and impose consequences when they find the left-hand one. That gap is the shortest statement of the importance of enterprise risk management.
Why the Importance of Enterprise Risk Management Is Now a Legal Question
Directors have owed a duty of oversight since the Caremark decision in 1996, but for two decades it was close to unenforceable. Marchand changed the practical position by finding that a board must make a good-faith effort to monitor risks that are central to the business.
The doctrinal test is narrow and specific. Courts ask whether a board-level reporting system existed for the company’s mission-critical risk, and whether the board used it. A well-documented oversight record is now a defense, and its absence is close to the whole case.
Reading the Delaware decisions that survived a motion to dismiss, a consistent evidentiary checklist emerges. It is worth treating that checklist as the list of documents your own board would have to produce on short notice, because that is exactly what it is:
- A committee or board agenda item dedicated to the mission-critical risk, not folded into general operations
- Minutes showing the topic was actually discussed, with dates
- A reporting line that carries bad news upward without management filtering it
- Evidence the board responded when a red flag arrived, rather than noting it
- Charter language assigning the risk to a named committee
Note what is absent from that list. No court asks which framework you adopted, how elegant the heat map is, or whether the register runs to 40 lines or 400. The continuing Boeing litigation turned on whether directors had a system and used it. The importance of enterprise risk management in a courtroom is procedural: evidence that oversight happened, not the label on the framework.

Figure 2. Two decades in which ERM moved from guidance to duty.
The Regulator’s Version: Risk Process Became a Disclosure Item
Litigation punishes failure after the fact. Disclosure rules do something different and arguably more demanding, by forcing companies to describe the process in advance and in writing, where investors and enforcement staff can later compare that description against what the company actually did.
The clearest US example arrived in July 2023, when the SEC adopted its cybersecurity disclosure rules. Item 106 of Regulation S-K requires registrants to describe their processes for assessing and managing material cyber risk, and to describe the board’s oversight of those risks.
The compliance date bites from fiscal years ending on or after December 15, 2023, per the SEC’s own small entity compliance guide. A company with no describable process must now either build one or disclose its absence to the market.
Surveys of what large filers actually wrote show the practical effect. A review of S&P 100 cybersecurity disclosures found companies leaning heavily on named frameworks to demonstrate their process, which is why running a NIST CSF risk assessment now has a disclosure payoff.
The direction of travel is wider than cyber alone. NIST added a Govern function when it published Cybersecurity Framework 2.0 in February 2024, placing it at the center of the other five, and continuity standards such as ISO 22301 already require organizational context before any planning starts. For disclosure teams, the importance of enterprise risk management is that it supplies the process there is now a legal duty to describe.
What Capital Markets Actually Pay For
The third force is pricing, and it moves faster than either of the others. Rating agencies have treated risk management as a rating input for two decades, which means a weak program shows up in the cost of capital long before it ever shows up in a courtroom.
S&P Global Ratings began folding enterprise risk management into insurance ratings in 2005 and still carries it in its insurers rating methodology, assessing risk culture and governance, risk controls, emerging risk preparation and strategic risk management as distinct scored elements.
| Channel | Who enforces it | What it inspects |
| Legal | Delaware Court of Chancery and Supreme Court | Whether a board-level monitoring system existed for mission-critical risk, and whether it was used |
| Regulatory | SEC, under Item 106 of Regulation S-K | The described process for assessing material cyber risk plus board oversight of it |
| Capital | S&P Global Ratings and peer agencies | Risk culture, controls, emerging risk preparation and strategic risk management |
| Assurance | External audit and internal audit under the Three Lines Model | Whether stated controls operate and whether second line challenge is real |
Those four rows are the honest business case. Each one names an enforcer, a document they read and a consequence, which is a stronger argument for a board than any claim about culture. The Three Lines Model published by the IIA sets out the accountability split in the final row. Read together, they show the importance of enterprise risk management being priced by outsiders whether or not the board prices it internally.
The Honest Read on ERM and Shareholder Value
Here we part company with most articles on this topic, including the earlier version of this page. The claim that ERM reliably protects and enhances shareholder value gets repeated everywhere, and the underlying research does not support stating it that plainly.
The most cited supportive study is Hoyt and Liebenberg’s The Value of Enterprise Risk Management in the Journal of Risk and Insurance, which found US insurers with more mature ERM programs showed significantly higher firm value and lower earnings volatility.
The wider literature is less tidy. Later studies across different markets and periods report positive, null and negative associations between ERM adoption and firm value, and the spread is wide enough that the honest summary is unsettled rather than proven.
Part of the problem is measurement. Studies disagree on what counts as having ERM, some using the appointment of a chief risk officer as the proxy, which captures a job title rather than a functioning program. The working paper version is explicit about these limits.
So we make a narrower claim and stand behind it. ERM does not guarantee a valuation premium, and it does reliably reduce a specific, documented set of exposures: personal director liability, disclosure failure, and rating downgrades tied to governance. Our advantages and disadvantages of risk management post sizes both sides. That narrower claim is still a strong case for the importance of enterprise risk management, because downside protection is what courts, regulators, and rating agencies actually test.
Where the Importance of Enterprise Risk Management Shows Up in Practice
Bridging from the case to the work: a program that would satisfy a court, a regulator and a rating analyst produces a specific short list of artifacts. If your ERM effort is not generating these, it is generating activity instead of evidence.

Figure 3. Most programs stall at stage two, where a register exists only to satisfy an auditor.
| Artifact | What it proves | Who asks for it |
| Approved risk criteria | Severity thresholds were agreed before scoring, by a body that can bind the entity | Auditors and rating analysts |
| Board or committee charter | A named body owns the mission-critical risk | Plaintiffs’ counsel in a Caremark claim |
| Dated minutes on key risks | The board used the system rather than merely having it | Delaware courts |
| Documented escalation route | Bad news travels upward without management filtering | Regulators and internal audit |
| Described risk process | The organization can state how it assesses material risk | SEC filers under Item 106 |
| Aggregated exposure view | Correlated exposures across silos are visible to leadership | The board and the CFO |
Each artifact has an owner and a cadence, and the sequence matters. Criteria come first, which is why we treat the first step in the risk management process as scope, context and criteria rather than jumping to a list of risks.
Reporting is where most programs lose the board. A register nobody reads is not oversight evidence, so the output has to be a small number of tracked indicators with thresholds, which is the job of key risk indicators and a working ERM dashboard.
Appetite is what converts all of it into decisions. A statement setting out how much of each exposure the organization will accept turns scoring into direction rather than commentary, and our risk appetite statement examples plus the sector-specific versions show how the drafting works. Run this way, the importance of enterprise risk management stops being an abstraction and becomes a set of documents a director can point to under oath.
Choosing a Framework Without Getting Lost in Them
Framework choice absorbs far more program time than it deserves, often several months of committee debate. The major frameworks agree on the substance almost entirely, so the practical question is narrower: which vocabulary do your board, your auditor and your regulator already speak fluently?
One correction first, because it propagates through most articles on this subject. COSO ERM has five components and twenty principles under the 2017 update, Integrating with Strategy and Performance. The eight-component cube belongs to the 2004 framework it replaced.

Figure 4. The eight-component cube was superseded in 2017. Citing it dates a program instantly.
| Framework | What it is built for | Choose it when |
| COSO ERM 2017 | Governance-led ERM tied to strategy and performance | You report to a US board or audit committee |
| ISO 31000:2018 | A principles-based process any entity can apply | You want a process standard rather than a governance model |
| NIST SP 800-39 | Framing, assessing, responding to and monitoring information risk | Your mission-critical risk is technology or data |
| NIST CSF 2.0 | Cyber outcomes organized under six functions including Govern | You must describe a cyber process under SEC Item 106 |
| COBIT | Governance of enterprise IT, published by ISACA | IT governance and audit are the binding constraint |
The COSO and ISO choice is the one clients ask about most, and it is largely a false dilemma. We compare them directly in ISO 31000 vs COSO ERM and again in COSO ERM vs ISO 31000 standards, and most mature programs end up running one as the spine and borrowing from the other.
Pick the vocabulary, then stop revisiting the decision every planning cycle. The COSO ERM five components and twenty principles guide and our ISO 31000 explainer cover each standard in depth, while the enterprise risk management framework build guide walks through assembling one. Framework debates matter far less to the importance of enterprise risk management than a working escalation path does.
Frequently Asked Questions About the Importance of Enterprise Risk Management
Why is enterprise risk management important for a board of directors?
Because Delaware courts treat board-level monitoring of mission-critical risk as a fiduciary duty. Marchand v. Barnhill in 2019 and the Boeing settlement approved in 2022 both turned on whether a reporting system existed and whether directors used it, not on program sophistication. That legal exposure, more than any efficiency argument, is the importance of enterprise risk management at board level.
What is the difference between ERM and traditional risk management?
Traditional risk management runs inside each function on its own scale, so nobody holds the aggregate. ERM applies one set of criteria across the entity with board-level ownership, which makes correlated and concentrated exposures visible. Our risk management process guide covers the mechanics.
Does enterprise risk management actually increase shareholder value?
The evidence is mixed. Hoyt and Liebenberg found higher value and lower earnings volatility among US insurers with mature programs, while later studies across other markets report null and negative results. Build the case on liability and disclosure exposure instead of a promised premium. In short, the importance of enterprise risk management rests more safely on loss avoidance than on a promised valuation premium.
How many components does the COSO ERM framework have?
Five, with twenty principles beneath them, under the 2017 update. The eight-component cube that appears in most older articles is the superseded 2004 framework. Citing the wrong version signals to an auditor that the program has not been refreshed in a decade.
Who should own enterprise risk management in an organization?
The board owns oversight and a named committee should carry that duty in its charter, while management owns the process and individual functions own the risks themselves. The IIA Three Lines Model sets out the split between ownership, oversight and independent assurance.
What does an effective ERM program produce?
Approved risk criteria, a committee charter naming the risk owner, dated minutes showing the board engaged, a documented escalation route, and an aggregated exposure view. Everything else is supporting work around those five. A risk management plan records the method and the reporting cadence.
Is ERM only relevant to large public companies?
No, though the enforcement channels differ by size. Private and mid-sized organizations rarely face Caremark claims, but they do face lender covenants, insurer questionnaires and customer due diligence packs that ask the same underlying questions about process, ownership and escalation.
Seven Traps That Derail ERM Programs
These are the patterns we get called in to fix, and they share a family resemblance. Every one of them produces a steady stream of activity that looks like a program from the inside, while leaving the organization exposed on exactly the tests that actually get applied.
| Trap | Why it happens | The fix |
| Framework shopping | The team debates COSO against ISO for months | Pick the vocabulary the board already uses and move on |
| Register as the deliverable | Length feels like progress | Judge the program on criteria, owners and escalation instead |
| Board pack with no thresholds | Reporting shows scores, not breaches | Report only indicators that crossed a defined limit |
| Risk function owns the risks | Functions delegate rather than accept ownership | Name a business owner on every entry and publish the list |
| Citing COSO 2004 | Content was copied from older sources | Move to five components and twenty principles |
| Value case built on a premium | The business case promises a valuation uplift | Rebuild it on liability, disclosure and rating exposure |
| Minutes that record attendance only | Nobody drafts for a future reader | Record what was discussed, decided and challenged, with dates |
The fifth row deserves emphasis because it is so cheaply fixed and so revealing. An organization still describing eight components is telling an auditor that nobody has read the current framework, which fairly invites questions about what else went unrefreshed for a decade.
The sixth row is the costliest in the long run. A business case promising a valuation premium sets up the program to be judged against a benchmark the research does not support, and the first CFO who checks the literature will defund it.
What Boards Will Expect by 2029
Three changes are already visible in the mandates we are asked to work against this year, and they point the same way. Each one narrows the gap between having a risk program and being able to prove you had it on a particular date.
Disclosure will keep widening well beyond cyber. The SEC template of describing a process plus the board’s oversight of it transfers cleanly to operational resilience and third-party concentration, and drafting teams are already reusing the Item 106 structure for other risk categories.
Evidence will get timestamped. The defensible artifact is shifting from a document that exists to a record showing when a threshold was crossed, who was told and what they decided, which is a reporting requirement rather than a framework one.
Expect assurance to follow. Internal audit functions are moving from testing whether a register exists to testing whether escalation actually fired when criteria were breached, and that is a harder test that most current ERM software is only starting to support.
If your board has asked what your ERM program would look like in a deposition, that is the right question and it deserves a documented answer. We assess programs against the COSO 2017 components and the oversight record a court would actually read. Look through our services, then start a conversation and bring your last four board packs. The importance of enterprise risk management is that, when that question arrives, the answer already exists in writing.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.