企业风险管理(ERM)流程中的步骤

Identify Risks
The first step in the ERM process is to identify the potential risks (and opportunities) that may affect the organization’s objectives. This step involves recognizing internal and external risks that may arise from various sources such as operations, financial, regulatory, legal, 声誉和战略风险. 识别新的风险是管理即将出现的风险的关键.

显示ERM过程中涉及的典型步骤的图形.

Assess Risks
After identifying the risks, the next step is to assess their likelihood and potential impact on the organization’s objectives. 这一步包括根据风险发生的概率来分析风险, potential impact, the speed (or velocity) that the risk might affect the organization and the adequacy of the organization’s current controls to mitigate those risks.

Prioritize Risks
Based on the risk assessment, the next step is to prioritize the risks based on their level of importance to the organization’s objectives. This step involves determining which risks require immediate attention and which risks can be managed over the long term.

制定风险缓解策略
After prioritizing the risks, the next step is to develop risk management strategies that align with the organization’s objectives. This step involves developing a risk management plan that outlines how the organization will mitigate, avoid, transfer or accept each risk.

实施风险缓解策略
The next step is to implement the risk mitigation strategies identified in the previous step. 这一步包括将必要的流程落实到位, 管理已识别风险的政策和程序.

Report, Monitor and Review
ERM流程的最后一步是报告, 监督和审查所实施的风险管理策略的有效性. 这一步包括持续监控风险, 评估风险管理策略的有效性, adjusting the strategies as necessary and reporting the results in a timely manner to be useful in strategic planning.