Enterprise Risk Management: Moving Beyond Taxonomies

Tags:

As part of its 2026 Tea Talk series, the Institute of Enterprise Risk Practitioners (IERP)® hosted a session titled “ERM That Delivers: Moving Beyond Taxonomies”.

Key Insights

  • To extract real value from Enterprise Risk Management, organisations must abandon rigid risk categories and adopt an objective-centric approach that aligns risk insights directly with strategic decision-making.
  • Many organisations fall into the taxonomy trap of treating risk management as a theoretical reporting exercise, but true resilience requires shifting to a framework that anticipates threats and actively supports business goals.
  • Moving beyond static definitions allows leaders to transform risk management from an administrative burden into a practical engine for informed, proactive decision-making in a disruptive environment.

Enterprise risk management (ERM) promises strategic clarity, yet often delivers bureaucratic compliance. For many organisations, the culprit is the “taxonomy trap” of identifying threats based on rigid, predefined categories.

When programmes are built on these static definitions, they fail to generate actionable insights. Leadership teams receive comprehensive reports, but find little they can actually use to drive decisions, allocate resources, or navigate market volatility.

In a Tea Talk titled “ERM That Delivers: Moving Beyond Taxonomies”, hosted by the Institute of Enterprise Risk Practitioners (IERP)®, Ramesh Pillai, Chairman of the Board of Governors of the IERP®, explored why many organisations are trapped by taxonomy.

The Taxonomy Trap in Enterprise Risk Management

While brainstorming against strict definitions is an outdated practice, the illusion of progress persists.

Between 2010 and 2023, the percentage of organisations claiming to have complete ERM processes in place jumped from 9% to 34%.

Yet, the numbers do not tell the full story. Even though more organisations now have these frameworks to guide their decision-making, very few can translate the provided information into actionable choices.

A 2024 global report by AICPA and CIMA found that 32% of organisations considered their risk oversights “mature” and only 17% used risk insights to gain a competitive advantage.

Overcoming the taxonomy trap allows organisations to approach risk assessment from a broader, integrated perspective.

“ERM elevates such efforts by putting in place processes and frameworks that allow for effective risk management across the entire organisation holistically, rather than just within specific departments, functions, or activities,” Ramesh said.

He added that operational risk is a component of enterprise-wide risk management. Organisations cannot manage strategic or reputational fallout without taking a holistic approach to all their activities.

Yet, the struggle to implement and mature ERM programmes remains. Organisations continue to face hurdles: an overemphasis on reporting, insufficient influence on decision-making, strict adherence to static processes, and a lack of clarity.

Choosing the Right Enterprise Risk Management Framework

Selecting the right risk management framework is crucial for integrating ERM within an organisation.

“Frameworks developed by the International Organization for Standardization (ISO) and the Committee of Sponsoring Organizations of the Treadway Commission (COSO) provide guidance for ERM programmes,” Ramesh shared.

With the advance of information technology, organisations are spoilt for choice when it comes to selecting an ERM system. Ramesh cautioned, however, that most of them were taxonomy-based, not objective-centric.

This issue was compounded, he observed, when IT or internal audit departments drove the evaluation and purchase of these systems, as obtaining them was considered normal procurement rather than technical.

To succeed, organisations need an adaptable, objective-centric framework. For most, this means choosing between two main models: ISO 31000 and COSO 2017.

COSO 2017, authored by PwC for the Committee of Sponsoring Organisations (COSO), integrates risk management directly with strategy and performance. ISO 31000, developed by the International Organization for Standardisation (ISO), is an international standard outlining principles and guidelines for risk management.

“Whether you adopt ISO’s more tailored risk management approach or the COSO framework, both require a higher level of coordination, collaboration and communication between risk managers, executive management and the Board,” Ramesh said.

Where Most Enterprise Risk Management Programmes Fall Short

The right framework lays the foundation for traditional ERM. Yet, the true payoff happens as these programmes mature, leveraging gathered insights for short- and long-term strategic decision-making.

To accelerate this progress, external evaluations, like the IERP®’s Risk Maturity Model, offer fresh perspectives that boost overall effectiveness.

“Most programmes are not yet at a level of maturity where they deliver maximum value,” Ramesh noted. He attributed this unfulfilled potential to weak technology adoption, fragmented collaboration, and inconsistent approaches to risk assessments, appetite, and strategy.

To address these weaknesses, Ramesh highlighted one focal point: timely risk assessments. A single assessment once in three years, or even annually, is insufficient in disruptive times as it paints only a partial picture of the organisation’s risks.

The challenge for ERM managers is to educate leadership about the greater value frequent assessments provide, which includes identifying emerging risks, improving mitigation, and generating useful information for decision-making.

Improving Risk Assessment with the 2-By-2 Method

While most organisations focus on high risk over low, the challenge lies in the definitions: high exposure implies high returns, and low exposure implies low returns.

Ramesh pointed out that failure to achieve targeted returns or break into new markets could simply be the result of the organisation not taking sufficient risk. Establishing a clear risk appetite supports ERM by empowering leadership to confidently take the calculated risks required to drive returns.

“What may look like a low risk, when you only plot and only consider probability against impact on your prioritisation matrix, could actually be high risk,” he illustrated this using the 2-by-2 method.

“If, as risk managers, we cannot understand this and pivot our way of thinking, we very quickly become theoretical and irrelevant, and will not be able to garner support from the board and senior management.”

Being holistic means aligning all elements and stakeholders so that the organisation’s vision connects to its jobs and employees. Tools to achieve this include the IERP®’s Goals and Objectives Harmonisation process.

The result is the alignment of risk insights with strategic decision-making. In today’s polycrisis environment, this translates into risk assessments that go beyond likelihood and impact; these assessments consider management preparedness and velocity to help ensure organisational resilience

5 Steps to Master Objective-Centric Risk Management

ERM is unique to each organisation, yet it is only as strong as the information it collects and the insights it can provide.

The process of obtaining relevant information and insights is split between taxonomic and objective-centric methodologies. The latter is now the international best practice.

To ensure objective-centric, forward-looking, and anticipatory risk management, Ramesh outlined five critical steps:

  • Build awareness: Ensure all levels of the organisation have sufficient awareness of ERM
  • Align objectives: Establish proper alignment of the vision, mission, strategy, and objectives throughout the organisation
  • Drive implementation: Implement the objective-centric approach to managing and dealing with risks
  • Validate continuously: Ensure your programme and reports remain relevant by continuous validation
  • Conduct reviews: Improve the quality of decision-making by including independent reviews

Key Lessons For Risk Leaders

To extract genuine value from enterprise risk management, organisations must integrate risk insights directly into strategic decision-making. Overcoming pitfalls like infrequent assessments and static processes requires a proactive, objective-centric approach.

Escape the taxonomy trap

Move past static, definition-based brainstorming and implement timely, holistic assessments to better inform leadership.

Adopt a risk management framework

Utilise flexible guidelines like ISO 31000 to align your risk management strategy directly with specific business goals rather than operational rigidity.

Rethink risk prioritisation

Apply the 2-by-2 method to uncover hidden threats, discover new opportunities, and recognise that avoiding risk entirely can sometimes jeopardise targeted returns.

Embrace the objective-centric approach

Embed an objective-centric approach towards risk management through five continuous steps: raising awareness, aligning objectives, driving implementation, validating data, and conducting independent reviews.

All in all, moving beyond taxonomies is more than updating a framework; it is about redefining the ERM practices. When organisations align their risk insights with strategic objectives, they transform ERM from a theoretical reporting tool into a practical engine for resilient, informed decision-making.

Share the Post
Share the Post

Subscribe to our weekly newsletter
and stay connected!

Subscribe to our weekly newsletter and stay connected!

Receive the latest update on our risk management program, industry news, events and more!

Subscribe to our weekly newsletter