| name | design-enterprise-risk-management-committee |
| description | Use when a board wants to establish a dedicated board-level committee (or full-board process) for overseeing the company's enterprise-wide risk profile — distinct from the audit committee's financial-reporting-specific mandate — integrating risk appetite, major risk categories, and management's risk response into a single board-level oversight function, rather than leaving enterprise risk oversight scattered across committees with no unifying view. |
| source | COSO, "Enterprise Risk Management — Integrating with Strategy and Performance" (2017); NACD board risk oversight guidance |
| tags | ["law","corporate","enterprise-risk-management","board-risk-oversight","coso-erm","corporate-governance"] |
| related | ["design-audit-committee-charter","apply-iso-31000-risk-framework","design-risk-appetite-framework"] |
Design Enterprise Risk Management Committee
Establish a dedicated board-level committee (or defined full-board process) for overseeing the company's enterprise-wide risk profile — distinct from the audit committee's financial-reporting-specific mandate — integrating risk appetite, major risk categories, and management's risk response into a single board-level oversight function.
Why This Is Best Practice
Adopted by: The COSO Enterprise Risk Management framework (2017) explicitly identifies board risk oversight as a distinct governance function requiring dedicated structure, and the National Association of Corporate Directors documents an increasing number of large public companies establishing a dedicated risk committee distinct from the audit committee, particularly in financial services and other risk-intensive industries where risk oversight has outgrown what the audit committee's financial-reporting mandate can reasonably absorb.
Impact: Companies relying solely on the audit committee for enterprise risk oversight are documented to experience gaps in non-financial risk categories (operational, strategic, cybersecurity, reputational risk) that don't map naturally onto the audit committee's core financial-reporting expertise and already-full agenda, while companies with a dedicated risk oversight structure demonstrate more comprehensive, integrated risk visibility across these broader categories.
Why best: The audit committee's mandate and expertise are specifically oriented toward financial reporting and internal controls — asking it to also serve as the primary venue for enterprise-wide risk oversight (strategic risk, operational risk, cyber risk, reputational risk) stretches its bandwidth and expertise beyond its core function, while a dedicated committee (or clearly defined full-board process) provides the specific structure and bandwidth this broader oversight function actually requires.
Sources: Committee of Sponsoring Organizations of the Treadway Commission (COSO), "Enterprise Risk Management — Integrating with Strategy and Performance" (2017); National Association of Corporate Directors (NACD), board risk oversight guidance
Steps
Step 1: Decide between a dedicated risk committee and a full-board process
Decide whether the company's risk profile and scale warrant a dedicated risk committee, or whether a clearly defined full-board risk oversight process (with specific agenda time and reporting structure) is more proportionate — larger, more complex, or more risk-intensive organizations (particularly financial institutions) more commonly warrant a dedicated committee.
Step 2: Define the committee's scope distinct from the audit committee
Define the committee's scope to cover enterprise-wide risk categories — strategic, operational, cyber, reputational, and other major risk categories — explicitly distinct from (and coordinated with, not duplicating) the audit committee's financial-reporting and internal-controls-specific mandate.
Step 3: Establish the committee's connection to the organization's risk appetite
Establish the committee's responsibility for reviewing and recommending the organization's overall risk appetite — how much risk the organization is willing to accept in pursuit of its objectives — as the reference standard against which specific risks and management's risk responses are evaluated.
Step 4: Establish management reporting lines into the committee
Establish clear reporting lines from a Chief Risk Officer or equivalent risk management function into the committee on a defined cadence, ensuring the committee receives substantive, structured risk information rather than only ad hoc or crisis-driven updates.
Step 5: Coordinate explicitly with other committees to avoid gaps or duplication
Explicitly coordinate the risk committee's scope with the audit committee, ESG/sustainability committee, and any other risk-adjacent committees to ensure risk categories are clearly allocated without gaps (a risk category no committee owns) or duplication (multiple committees separately, redundantly covering the same risk).
Rules
- Decide deliberately between a dedicated committee and a defined full-board process, based on the organization's actual risk profile and scale — not by default assumption either way.
- Define the committee's scope explicitly distinct from the audit committee's financial-reporting mandate, covering the broader enterprise risk categories.
- Connect the committee's oversight explicitly to the organization's defined risk appetite, not an undifferentiated general risk discussion.
- Coordinate explicitly with other risk-adjacent committees to avoid both oversight gaps and duplicated coverage.
Examples
Dedicated committee providing focused oversight the audit committee couldn't sustain: A financial services company establishes a dedicated risk committee specifically because its audit committee's financial-reporting workload had left insufficient bandwidth for genuine strategic and operational risk oversight. The new committee's dedicated focus surfaces and addresses a cybersecurity risk gap that had received only cursory attention under the prior audit-committee-only structure.
Explicit coordination avoiding a scope gap: A board explicitly allocates climate-related risk to its risk committee and financial-reporting risk to its audit committee, documenting the boundary in both committees' charters. When a climate-related regulatory risk emerges with financial reporting implications, the two committees coordinate directly rather than each assuming the other has ownership — a coordination the explicit allocation specifically enabled.
Common Mistakes
- Relying solely on the audit committee for all enterprise risk oversight — this stretches the audit committee's financial-reporting-oriented mandate and bandwidth beyond what it can reasonably absorb for broader risk categories.
- Establishing a dedicated risk committee without clearly distinguishing its scope from the audit committee's — overlapping, undifferentiated scope produces confusion and potential duplication rather than genuine additional coverage.
- Failing to connect risk oversight explicitly to a defined risk appetite — without this reference standard, risk discussions lack a consistent basis for evaluating whether a specific risk or response is actually acceptable.
- Neglecting to coordinate explicitly with other risk-adjacent committees — this risks either gaps (no committee owning a specific risk category) or duplication (multiple committees separately covering the same ground).
When NOT to Use
- For a smaller or less risk-intensive organization where a dedicated risk committee is disproportionate to actual risk complexity — a defined full-board risk oversight process may be more appropriate at this scale.
- As a substitute for the audit committee's specific financial-reporting and internal-controls oversight — enterprise risk committee oversight complements, but doesn't replace, the audit committee's distinct mandate (see
design-audit-committee-charter).
- As a substitute for the organization's own operational risk management process — board-level committee oversight provides governance accountability; it doesn't replace the management-level work of actually identifying and managing specific risks (see
apply-iso-31000-risk-framework).
Legal disclaimer: This skill encodes professional best practices for educational purposes. It is not legal advice. Board risk oversight structure requirements vary by industry (particularly for regulated financial institutions) and jurisdiction — consult licensed corporate governance counsel for requirements specific to your organization.