FRM Exam Part I · Enterprise Risk Management and Future Trends
Enterprise Risk Management (ERM) Framework for FRM Part I
Updated 11 October 2026 · Fact-checked
Enterprise risk management (ERM) is a firm-wide approach that identifies, measures, aggregates and manages all material risks together, linked to strategy and risk appetite, instead of in separate silos. To answer exam questions, name the integration benefit, the framework component involved, and who owns it: board, CRO or business units.
Understand Enterprise Risk Management (ERM) Framework
Start with the problem. In a traditional silo approach, each risk is managed by a separate team. Credit, market, operational and liquidity risk each have their own limits, tools and reports. Nobody sees the total picture, and risks that interact can be missed.
Enterprise risk management (ERM) fixes this by managing risk across the whole organization in an integrated way. It looks at all risk types, across all business lines, and ties them to the firm's strategy and risk appetite. The aim is not to remove risk. It is to take the right risks, in the right amount, for the right return.
Integration matters for three reasons. First, risks are correlated, so the total may be more or less than the sum of the parts. Second, diversification benefits only show up when risks are aggregated. Third, a firm-wide view lets management compare risk and return across units and allocate capital sensibly.
Typical benefits are: better decisions on risk and return, more efficient use of capital, fewer surprises and losses, stronger governance and reporting, and greater confidence from regulators, rating agencies and investors. Typical challenges are: cost and effort, data that is hard to collect and aggregate, different risk measures across units, weak risk culture, and the difficulty of modelling rare events and correlations.
The main components of an ERM program, in the COSO-style view, cover governance and culture, strategy and objective-setting, performance (identifying, assessing, prioritizing and responding to risk), review and revision, and information, communication and reporting. The chief risk officer (CRO) leads the program. The CRO builds the framework, aggregates and reports risk to senior management and the board, and keeps independence from the business lines. Ownership of day-to-day risk stays with the business. The board sets risk appetite and oversight. Risk culture is the shared attitude to risk across the firm, and a framework fails without it.
Key formulas to remember
- ERM in one line
- ERM = integrated, firm-wide risk identification, measurement, aggregation, response and reporting, linked to strategy and risk appetite
- Use this to separate ERM from silo risk management. Words like integrated, firm-wide and strategy are the signals.
- COSO ERM components (2017 version)
- Governance and Culture | Strategy and Objective-Setting | Performance | Review and Revision | Information, Communication and Reporting
- Five components. The earlier 2004 version listed eight, including internal environment, objective setting, event identification, risk assessment, risk response, control activities, information and communication, and monitoring. Know that the framework has been updated.
- Risk response options
- Avoid | Reduce (mitigate) | Share or transfer | Accept (retain)
- Choice depends on whether the risk fits the firm's risk appetite and on the cost versus benefit of the response.
- Aggregation and diversification
- Firm-wide risk ≤ Σ stand-alone risks, when risks are not perfectly correlated and the measure is subadditive
- This is the logic behind aggregation. Value at Risk is not always subadditive, so state the condition.
How to solve Enterprise Risk Management (ERM) Framework questions
Most ERM questions are conceptual. Use the same short routine each time so you pick the answer that matches the integrated, firm-wide idea.
- 1Read the stem and decide what is being tested: definition of ERM, benefits, challenges, framework component, CRO role or risk culture.
- 2Look for the key contrast. Is the scenario siloed or integrated? Is it about one risk type or the whole firm?
- 3Match the scenario to a component: governance and culture, strategy, performance, review, or information and reporting.
- 4Check who owns the task. The board sets appetite and oversight. The CRO designs and runs the framework. Business units own and manage their risks.
- 5Eliminate options that claim ERM removes all risk, replaces specialist risk teams, or ignores strategy.
- 6Eliminate options that treat the CRO as a risk-taker or as reporting only to a business head.
- 7Pick the option that links risk to strategy, appetite and firm-wide aggregation, and re-read the stem to confirm.
Quickest way: Three-question filter for ERM MCQs
When to use it: Use this on any conceptual ERM question when time is short, which is most of them.
- Ask: is this firm-wide and integrated? If an option is siloed, it is usually wrong.
- Ask: does it link to strategy and risk appetite? ERM answers almost always do.
- Ask: who owns it? Board for appetite, CRO for the framework and independence, business for day-to-day risk.
- Choose the option passing all three. Beware absolute words such as always, eliminates and only.
Common mistakes in Enterprise Risk Management (ERM) Framework
Saying ERM eliminates risk.
The word management sounds like control or removal.
Fix: ERM aims to take the right risks within appetite. It optimizes risk and return and does not aim for zero risk.
Treating ERM as the sum of separate risk reports.
Students think collecting silo reports in one pack is integration.
Fix: True ERM aggregates risks, considers their interactions and correlations, and links the result to strategy and capital.
Making the CRO responsible for taking and owning business risk.
The CRO runs the framework, so students assume ownership of all risk.
Fix: Business units own their risks. The CRO designs the framework, challenges, aggregates and reports, and must stay independent.
Confusing the board's role with management's role.
Both are described as responsible for risk.
Fix: The board approves risk appetite and oversees the framework. Senior management implements it, with the CRO leading.
Mixing up COSO versions and component lists.
Notes cite the 2004 eight components and the 2017 five components interchangeably.
Fix: Learn the 2017 five components first, note that the 2004 version had eight, and read the stem for clues.
Ignoring risk culture as a component.
Culture seems soft compared with models and limits.
Fix: Culture is part of governance and is often the cause of failures. Expect questions where weak culture defeats a sound framework.
Worked examples
Example 1
A bank's credit, market and operational risk teams each report separately to different executives. No one measures total risk or the interaction between them. Which description best fits this setup, and what is the main improvement ERM offers?
A. ERM; it adds more reports
B. Silo risk management; it offers firm-wide aggregation and a view of risk interactions linked to strategy
C. Silo risk management; it removes the need for specialist teams
D. ERM; it eliminates market risk
Show the solution
- Identify the feature: separate teams, separate reporting, no total view. This is siloed.
- Recall what ERM adds: integration, aggregation, recognition of correlations and diversification, and linkage to strategy and appetite.
- Check A: the setup is not ERM, so A is wrong.
- Check C: ERM does not remove specialist teams, they remain. C is wrong.
- Check D: ERM does not eliminate any risk type, and the setup is not ERM. D is wrong.
- B matches both parts.
Answer: B
Example 2
A new CRO at an international bank is setting up the ERM program. Which action is most consistent with the CRO's role?
A. Approving the firm's risk appetite on behalf of the board
B. Taking ownership of all trading losses
C. Building the firm-wide risk framework, aggregating risk across business lines and reporting it to senior management and the board, while remaining independent of the business
D. Reporting only to the head of the largest trading desk
Show the solution
- Recall the split: the board approves risk appetite, so A is wrong.
- Business units own and manage their risks, so B is wrong.
- Independence is essential. Reporting only to a desk head undermines it, so D is wrong.
- The CRO designs and runs the framework, aggregates and reports risk firm-wide, and keeps independence. That is C.
Answer: C
Exam tips
- Questions are mostly conceptual. Learn the contrast between silo and integrated risk management and the benefits and challenges cold.
- Know who does what: the board sets appetite and oversight, the CRO runs the framework independently, business units own risk.
- Learn the five 2017 COSO ERM components in order and know that earlier versions listed more.
- Watch for absolute wording such as eliminates, always or only. These options are usually wrong.
- Link ERM to nearby topics: risk appetite, three lines of defense and governance failures. Cases often combine them.
Practice questions from Enterprise Risk Management and Future Trends
- A firm deploys an AI tool to automate parts of its risk reporting. Which control best addresses the risk that the tool degrades over time as…
- A bank's risk committee is reviewing how best to identify emerging risks such as those arising from climate change and rapid technological c…
- A firm's strategy team proposes entering a new market with high expected returns but highly uncertain outcomes. Under an ERM approach to the…
- A company's management is rewarded solely on revenue growth, and it expands rapidly into riskier lending segments without adjusting capital.…
- In the three lines of defense model commonly used in risk governance, which arrangement is most consistent with the model?
Enterprise Risk Management (ERM) Framework in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Enterprise Risk Management (ERM) Framework: frequently asked questions
What is the difference between ERM and traditional silo risk management?
Silo risk management handles each risk type separately, with its own limits and reports. ERM manages all material risks together across the firm, considers how they interact, and ties them to strategy and risk appetite. This gives a clearer total picture and better capital decisions.
What are the main benefits and challenges of ERM?
Benefits include better risk-return decisions, more efficient capital use, fewer surprises, stronger governance and greater stakeholder confidence. Challenges include cost, data aggregation, inconsistent risk measures across units, weak risk culture and difficulty modelling correlations and rare events.
What are the components of the COSO ERM framework?
The 2017 COSO framework has five components: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting. The earlier 2004 version listed eight components. Learn the five, and recognise the older list if it appears.
What is the role of the CRO in ERM?
The CRO leads the ERM program. This includes designing the framework, aggregating risk across the firm, reporting to senior management and the board, and challenging the business. The CRO must be independent of the business lines, which own their day-to-day risks.