Risk management controls exposure; it does not remove it. Hold that idea and the definition, the measures and the two COSO frameworks fall into place.
The BASK definition
Risk Management is the identification, assessment and prioritization of risks, and the application of resources to minimize, monitor and control the probability and impact of those risks.
- It is not eliminating all exposure to loss. That overstates the goal.
- It is not transferring liability to insurers, which is one treatment, sharing, standing in for the whole definition.
- It is not satisfying regulators that controls are documented. That is a byproduct.
The ERM process
The BASK describes enterprise risk management as understanding context and identifying, analyzing and prioritizing risks.
- Buying insurance and setting deductibles is a treatment applied after risks are understood.
- Auditing financial statements is financial reporting.
- Drafting evacuation maps is emergency planning, which the BASK lists separately.
The quantitative measures
The BASK names single loss expectancy and annualized loss expectancy.
- Net present value and internal rate of return are capital budgeting.
- Standard deviation and coefficient of variation are general statistics.
- Cost per hire and time to fill are talent acquisition metrics.
The two COSO frameworks
- 2004 original: Enterprise Risk Management—Integrated Framework.
- Update: Enterprise Risk Management—Integrating with Strategy and Performance, which emphasizes risk in both strategy-setting and driving performance.
The trap is Internal Control—Integrated Framework, which is COSO's separate internal control work, not its ERM framework. And the updated ERM title is never the right answer to "what did COSO publish in 2004."
Carry this in: minimize, monitor and control, not eliminate.