Enterprise Risk Management & Risk Assessments

Make the most of every opportunity.

get in touch

Our Enterprise Risk Management (ERM) service addresses more than just internal controls. Our ERM team will help you achieve business objectives more efficiently, maximize financial performance, optimize resources, and promote company-wide strategy alignment.

solution overviews

Governance and Culture

  • Exercise board risk oversight
  • Establish operating structures
  • Define desired culture
  • Demonstrate commitment to core values
  • Attract, develop, and retain capable individuals

Strategy and Objective-Setting

  • Analyze business context
  • Define risk appetite
  • Evaluate alternative strategies
  • Formulate business objectives

Performance

  • Identify risk
  • Assess severity of risk
  • Prioritize risks
  • Implement risk responses
  • Develop portfolio view

Assess and Revision

  • Assess substantial change
  • Analyze risk performance
  • Pursue improvement in enterprise risk management

Information, Communication and Reporting

  • Leverage information and technology
  • Communicate risk information
  • Report on risk, culture and performance

A key component of the Elliott Davis risk assessment approach is the individual attention paid to each key stakeholder, from management to field-level employees. In order to obtain the best information, we conduct one-on-one interviews with a wide range of stakeholders to encourage full transparency from all team members.

Key steps in the risk assessment process include:

  • Identifying and classifying inherent risks and the evaluating the sufficiency of the District’s enterprise risk management mechanisms
  • Performing high-level analysis of the current state of internal controls, including any potential design, documentation, and/or implementation gaps
  • Determining the residual risk ratings based on what remains after considering the inherent risks (i.e., type of risk and likelihood of occurrence) and the potential impact to the Company if these risks materialize, after considering the mitigating internal controls (i.e., control effectiveness)
  • Based on the residual risk ratings and recommended audit frequency, the internal audit plan is developed for the subsequent three-to five-year period, prioritizing the highest risk areas

related solutions

No solutions found.

find your solution

Industries

Solutions by Industry

Every industry has its own nuances. We take that into consideration and approach business solutions with the specific lens required of your field. Our teams are comprised of talent with relevant experience and we’re prepared to meet every challenge.

contact our team.