French Caldwell

A member of the Gartner Blog Network

French Caldwell
Research VP
11 years at Gartner
15 years IT industry

French Caldwell is a vice president in Gartner Research, where he leads governance, risk and compliance research. Mr. Caldwell also writes and presents on knowledge management. His research includes analysis of the impact… Read Full Bio

Coverage Areas:

Five Characteristics of Good Enterprise Risk Management

by French Caldwell  |  August 3, 2010  |  Comments Off

Does your company do an annual risk assessment? What happens afterward — is there ongoing monitoring and management of risks throughout the year? Or is the assessment just an exercise to review last year’s risk assessment and update it for this year’s?

Very few enterprises truly evaluate their risks — rather they take a list of risks common to their industry and just have a tabletop discussion once a year or once a quarter. However regulators are pushing companies to get more serious in their risk management programs.

In talking with clients, I’ve come up with five characteristics of a good enterprise risk management program:

  1. Risks are derived from business goals and objectives
  2. A framework guides a common approach across the enterprise
  3. Risks, including IT risks, are communicated in terms of their impact on the business
  4. There is operational support for risk management and accountable ownership of risks
  5. There is a business process approach to risk management technology

Comments Off

Category: Uncategorized     Tags: