FRM Exam Part II · Integrated Risk Management
Enterprise Risk Management Framework for FRM Part II
Updated 11 October 2026 · Fact-checked
Enterprise risk management (ERM) is a firm-wide process that identifies, measures, aggregates and manages all material risks together, not in separate silos. The board sets strategy and risk appetite, management applies a common risk language, and results are reported upward so risk is judged against objectives and capital.
Understand Enterprise Risk Management Framework
Start with the problem. A bank faces credit, market, operational, liquidity and other risks. If each sits in its own department with its own metrics, no one sees the total. Risks also interact. A market fall can raise defaults, drain liquidity and expose control failures at the same time. Siloed management misses these links.
ERM answers this by treating risk as one connected whole. It has four core ingredients: board-level governance, a defined risk appetite, a common risk language (shared definitions, taxonomy and metrics) and integrated measurement and reporting, including aggregation across risk types and diversification effects.
Governance starts at the top. The board approves strategy and risk appetite and holds management accountable. Senior management, often through a chief risk officer (CRO) and risk committees, turns appetite into limits and policies. The three lines of defense then divide the work: business units own and take risk, independent risk and compliance oversee it, and internal audit gives independent assurance.
Risk appetite is the amount and type of risk the firm is willing to accept to pursue its objectives. It is cascaded into risk limits for business lines. A related idea, risk capacity, is the maximum risk the firm could bear, set by capital, liquidity and regulation. Appetite should sit below capacity.
The COSO ERM framework (Enterprise Risk Management: Integrating with Strategy and Performance, 2017) links risk to strategy and performance. Its five components are governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. The key point is that risk is considered when strategy is chosen, not only after.
Economic capital is the usual common currency. It lets the firm express credit, market and operational risk in one measure, aggregate it with diversification, and compare returns with risk across businesses.
Key formulas to remember
- Risk appetite versus capacity
- Risk appetite < Risk tolerance/limits ≤ Risk capacity
- Appetite is the target level of risk, limits are the operating boundaries, capacity is the absolute maximum the firm can absorb. Wording of tolerance and limits varies by source; the ordering is the point.
- Simple aggregation of risk capital
- Total = Σ standalone capital (no diversification benefit)
- This is the upper bound, which assumes perfect correlation across risk types.
- Diversification benefit
- Diversification benefit = Σ standalone capital − aggregated (diversified) capital
- Positive when risks are less than perfectly correlated. Estimates depend on correlation and aggregation assumptions, which carry model risk.
- Three lines of defense
- 1st: business units own risk | 2nd: risk management and compliance oversee | 3rd: internal audit assures
- Know which line performs which role.
- COSO ERM 2017 components
- Governance and culture; Strategy and objective-setting; Performance; Review and revision; Information, communication and reporting
- Five components; the 2017 version integrates risk with strategy and performance.
How to solve Enterprise Risk Management Framework questions
Most ERM questions are conceptual or case-based. Use one routine to find the right answer and avoid distractors.
- 1Identify what is being asked: definition, governance role, risk appetite, aggregation, or a COSO component.
- 2Decide who owns the issue. Board sets appetite and strategy, management implements, business lines own risk, second line oversees, internal audit assures.
- 3Check whether the scenario is siloed or integrated. Look for missing links across risks, inconsistent metrics or no firm-wide view.
- 4Match the problem to an ERM ingredient: governance, appetite, common language, or aggregation and reporting.
- 5For numeric items, compute standalone sums first, then apply the diversification or correlation given.
- 6Eliminate options that overstate ERM, such as eliminating risk, replacing specialist risk teams or guaranteeing profit.
- 7Pick the answer that links risk to strategy, capital and board oversight.
Quickest way: Role-and-purpose scan
When to use it: Use when the question is a short conceptual MCQ and time is tight.
- Underline the actor in the stem (board, CRO, business unit, audit).
- Recall that actor's one-line role from the three lines of defense.
- Choose the option that matches that role and mentions firm-wide or strategic scope.
- Reject options that imply risk is only measured, only avoided, or handled by one silo.
Common mistakes in Enterprise Risk Management Framework
Saying ERM eliminates risk.
The word management suggests control of outcomes.
Fix: ERM aims to take the right risks within appetite and to improve decisions. It does not remove risk.
Treating risk appetite and risk capacity as the same.
Both describe how much risk a firm can take.
Fix: Appetite is what the firm chooses to accept. Capacity is the maximum it could survive. Appetite should be lower.
Assigning independent oversight to the first line.
Business units manage risk daily, so they seem to oversee it.
Fix: The first line owns and takes risk. The second line oversees and challenges. Internal audit, the third line, gives independent assurance.
Assuming the diversification benefit is always large and reliable.
Aggregated models often show big savings.
Fix: The benefit depends on correlation assumptions, which can rise in stress. State it as an estimate with model risk.
Confusing COSO ERM with the COSO internal control framework.
Both come from COSO and share vocabulary.
Fix: ERM covers strategy, performance and all risks. The internal control framework focuses on controls over objectives such as reporting.
Thinking the CRO owns all risk decisions.
The CRO is visible as the head of risk.
Fix: The board sets appetite. Business lines own risk. The CRO runs the independent risk function and reports to the board.
Worked examples
Example 1
A bank's standalone economic capital is: credit USD 600 million, market USD 300 million, operational USD 100 million. The risk team estimates aggregated capital with diversification at USD 850 million. What is the diversification benefit, and what does it mean for the ERM view?
Show the solution
- Sum standalone capital: 600 + 300 + 100 = USD 1,000 million.
- Diversification benefit = 1,000 − 850 = USD 150 million.
- As a share of the simple sum: 150 ÷ 1,000 = 15%.
- Interpretation: only an integrated view captures this benefit. It rests on correlation assumptions that may fail in stress, so it should be reported with caution.
Answer: USD 150 million (15% of the simple sum). It is an estimate that depends on correlation assumptions.
Example 2
A bank's credit, market and liquidity teams each use different definitions of stress and report separately. A downturn then causes loan losses, trading losses and funding outflows together, and no one anticipated the combined effect. Which ERM weakness is this, and what is the fix?
Show the solution
- Note the symptoms: separate reporting, inconsistent definitions, no view of combined impact.
- This is siloed risk management. It lacks a common risk language and firm-wide aggregation.
- Fix at governance level: the board and CRO set a common risk taxonomy and shared scenarios.
- Run integrated stress tests across credit, market and liquidity risk.
- Report aggregated results to the board and link them to risk appetite and capital.
Answer: Siloed risk management with no common risk language or aggregation. Fix it with a shared taxonomy, integrated stress testing and board-level aggregated reporting against risk appetite.
Exam tips
- Expect case-style stems where the answer is a missing ERM ingredient: governance, appetite, common language or aggregation.
- Memorize who does what in the three lines of defense. Questions often swap roles in distractors.
- Distinguish risk appetite, tolerance and capacity, and know the ordering.
- Reject absolute wording such as eliminates, guarantees or always.
- For numeric items, the usual task is simple sum minus diversified total. Check units and currency.
Practice questions from Integrated Risk Management
- After a failure, a bank evaluates its three lines of defense. The first line (a lending desk) approved loans outside appetite and self-repor…
- A regional bank's board wants its enterprise risk management (ERM) framework to deliver a firm-wide view of risk rather than separate views …
- A bank's board sets a firmwide economic capital risk appetite of USD 500 million for operational risk. Standalone capital for three units is…
- A firm's ERM team aggregates stand-alone economic capital of 60 for market risk, 80 for credit risk and 40 for operational risk, in USD mill…
- A bank suffered a large loss from a complex structured product. The post-mortem found: the business unit's models were validated only by its…
Enterprise Risk Management Framework in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Enterprise Risk Management Framework: frequently asked questions
What is the difference between ERM and siloed risk management?
Siloed management handles each risk type separately with its own metrics and owners. ERM covers all material risks together under board oversight, with a common language and aggregation. This captures interactions and diversification that silos miss.
What are the components of the COSO ERM framework?
The 2017 COSO ERM framework has five components: governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. Its main message is that risk should be integrated with strategy and performance.
Who sets risk appetite in a bank?
The board approves risk appetite, usually on management's proposal and with CRO input. Management then converts it into limits and policies for business lines.
Why is a common risk language important?
Shared definitions, taxonomy and metrics let different risk types be compared and aggregated. Without them, reports cannot be combined and the board cannot see total risk.