Enterprise Risk Management (ERM) is the executive discipline of identifying, assessing, prioritizing, governing, and responding to uncertainty across the entire organization. Unlike traditional risk management, which often treats financial, operational, legal, cyber, supply-chain, strategic, and compliance risks as separate functional problems, ERM examines how these risks interact and how they can affect the organization’s ability to achieve its objectives.
Enterprise Risk Management is an advanced Junior MBA course designed to train students to think like senior executives, Chief Risk Officers, CFOs, COOs, business-unit leaders, and board members responsible for protecting and creating enterprise value under uncertainty. It moves beyond introductory risk registers and basic probability concepts to focus on risk appetite, strategic risk, scenario analysis, concentration risk, interdependencies, emerging risks, resilience, controls, governance, crisis escalation, capital allocation, and board oversight.
The course emphasizes that risk management is not about eliminating uncertainty. Every meaningful strategic decision involves risk. Growth, innovation, acquisitions, geographic expansion, technology adoption, new products, leverage, outsourcing, and transformation can all create enterprise value precisely because organizations are willing to accept uncertainty.
The challenge is to understand which risks the organization is deliberately taking, which risks it is unintentionally accumulating, how much loss or disruption it can absorb, what warning signs management should monitor, and what actions should be taken before a threat becomes a crisis.
Students will learn to evaluate both downside risk and opportunity risk. They will also examine common ERM failures, including risk silos, excessive reliance on heat maps, weak escalation, false precision, poor risk ownership, ignored correlations, inadequate scenario planning, control fatigue, and board reporting that describes risks without supporting decisions.
The practical objective is to build managers capable of answering: What could prevent us from achieving the strategy? Which risks matter most? Who owns them? How do they interact? What level of exposure are we willing to accept? What evidence would tell us the risk is increasing? What should we do if it does? And is our organization resilient enough to recover if our assumptions are wrong?
Course Objectives
By the end of this course, students will be able to:
• Analyze enterprise risk as an integrated strategic management discipline.
• Distinguish strategic, financial, operational, compliance, cyber, legal, reputational, supply-chain, and other major risk categories.
• Design practical ERM structures aligned with enterprise strategy.
• Develop and interpret risk appetite and risk tolerance frameworks.
• Identify enterprise risk concentrations and interdependencies.
• Evaluate risks using probability, impact, velocity, persistence, and recoverability.
• Build decision-useful risk registers without relying mechanically on scoring systems.
• Distinguish inherent risk from residual risk.
• Evaluate controls and mitigation strategies for effectiveness.
• Develop key risk indicators and escalation thresholds.
• Apply scenario analysis and stress testing to enterprise decisions.
• Evaluate strategic risk associated with growth, acquisitions, innovation, and transformation.
• Analyze emerging risks where historical data are limited.
• Integrate ERM with capital allocation, budgeting, strategy, and performance management.
• Evaluate third-party and supply-chain risk.
• Develop cyber, technology, and data-risk governance from an executive perspective.
• Understand liquidity, credit, market, and financial risk at a managerial level.
• Develop crisis escalation and resilience systems.
• Design board-level risk reporting.
• Build a risk-aware culture that supports intelligent risk-taking rather than excessive risk avoidance.
• Apply executive judgment to situations where risk cannot be quantified precisely.