Companies see need to manage risks, but they’re slow to act

Please note: This item is from our archives and was published in 2018. It is provided for historical reference. The content may be out of date and links may no longer function.

Nine years ago, just 9% of companies claimed to have a complete enterprise risk management (ERM) process. Today a larger percentage of companies (31%) describe their ERM processes as complete.

While there has been progress, there’s still some work to do for many companies, according to an annual survey released Tuesday by North Carolina State University and the American Institute of CPAs. The survey polled 474 finance executives in business and industry, mainly from North American companies.

One example of concern: Enterprise risk management continues to be viewed more as a compliance exercise than one that produces strategic value, according to Mark Beasley, CPA, the director of North Carolina State’s ERM Initiative. That’s despite growing concern about the complexity of the risk environment and a reprioritisation of the top risks on the minds of finance decision-makers. The level of worry about risks has risen in three of the past four years in the survey

Companies are struggling to create mature ERM practices despite the perception that the volume and complexity of risk was increasing mostly or extensively — a view held by 60% of respondents.

Twenty-two per cent rate their organisation’s risk management oversight as mature or robust.

Meanwhile, there’s more evidence revealing a disconnect in the way companies are prioritising risk: About half of companies provide written reports to senior executives at least annually to communicate about risks, and that percentage jumps to 82% for public companies.

“They’re providing written reports, but [the reports are] based on a fairly immature process,” Beasley said.

More companies are paying attention to ERM, the data show, but they are not necessarily structured in the way they plan to respond to risk events on the horizon. Thirty-one per cent say they have a complete ERM process in place, compared with 28% last year and 23% in 2012.

Additionally, a growing number of companies have appointed a chief risk officer or equivalent, and more organisations have a management-level risk committee than in the past: 59% in the current survey, compared with 30% in 2010.

So, ERM has gradually gotten more important, even if it remains somewhat informal. “Companies are putting their telescope on it, but it’s been gradual,” Beasley said.

Rapid changes to business

Another survey shows that specific risks faced by companies are changing. The top risk for several years in a survey North Carolina State conducted with consulting firm Protiviti was related to economic conditions. In the most recent version, released in December, economic conditions fell to eighth on a list of concerns, and regulation — regularly a top worry of finance executives — fell to fourth.

The top risk in the Protiviti survey was potential business disruption from rapid innovation.

“They’re afraid they’ll be totally blindsided by some competitor, and it may not be an existing competitor,” Beasley said. “It may be something that happens out of the blue.”

The updated Committee of Sponsoring Organizations of the Treadway Commission (COSO) ERM framework could help nudge companies in the right direction, Beasley said. That framework, released in September, specifically mentions a tie-in between risk and strategy.

One call to action in the North Carolina State-AICPA survey is to find ways to connect risk management and strategic planning. Beasley said companies have pockets of sophisticated risk management in place — such as airlines for compliance with air-traffic rules, or banks for loan defaults — but a large segment of organisations in the survey still have a long way to go in making their ERM process holistic.

“They are embracing that they need to be doing more on risk management,” Beasley said. “But as far having detailed processes and building out their risk infrastructure, it’s happening slowly.”

Neil Amato (Neil.Amato@aicpa-cima.com) is an FM magazine senior editor.

Up Next

With greenhouse gas reporting, sizable gaps persist

By Bryan Strickland
September 5, 2025
Large companies in the UK are making progress as more sustainability reporting requirements approach, but they could face significant challenges when seeking assistance from smaller companies in their supply chain.
Advertisement

LATEST STORIES

With greenhouse gas reporting, sizable gaps persist

Accountability: Inescapable, challenging, and valuable

US business outlook brightens somewhat despite trade, inflation concerns

Elevating productivity through strategic business partnering

Mark Koziel Q&A: Talent, sense of community, profession opportunities

Advertisement
Read the latest FM digital edition, exclusively for CIMA members and AICPA members who hold the CGMA designation.
Advertisement

Related Articles

Image of AI-generated woman's face.
Shadow AI emerges as significant cybersecurity threat