Use when a board wants to establish a dedicated board-level committee (or full-board process) for overseeing the company's enterprise-wide risk profile — distinct from the audit committee's financial-reporting-specific mandate — integrating risk appetite, major risk categories, and management's risk response into a single board-level oversight function, rather than leaving enterprise risk oversight scattered across committees with no unifying view.
Scanned 9/8/2026
Install to Claude Code
npx -y skills add jeffreytse/grimoire-core --skill design-enterprise-risk-management-committee --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Design Enterprise Risk Management Committee?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/jeffreytse-design-enterprise-risk-management-committee)More formats (shields.io, HTML) on the badges page.
---
name: design-enterprise-risk-management-committee
description: Use when a board wants to establish a dedicated board-level committee (or full-board process) for overseeing the company's enterprise-wide risk profile — distinct from the audit committee's financial-reporting-specific mandate — integrating risk appetite, major risk categories, and management's risk response into a single board-level oversight function, rather than leaving enterprise risk oversight scattered across committees with no unifying view.
source: COSO, "Enterprise Risk Management — Integrating with Strategy and Performance" (2017); NACD board risk oversight guidance
tags: [law, corporate, enterprise-risk-management, board-risk-oversight, coso-erm, corporate-governance]
related: [design-audit-committee-charter, apply-iso-31000-risk-framework, design-risk-appetite-framework]
---
# Design Enterprise Risk Management Committee
Establish a dedicated board-level committee (or defined full-board process) for overseeing the company's enterprise-wide risk profile — distinct from the audit committee's financial-reporting-specific mandate — integrating risk appetite, major risk categories, and management's risk response into a single board-level oversight function.
## Why This Is Best Practice
**Adopted by:** The COSO Enterprise Risk Management framework (2017) explicitly identifies board risk oversight as a distinct governance function requiring dedicated structure, and the National Association of Corporate Directors documents an increasing number of large public companies establishing a dedicated risk committee distinct from the audit committee, particularly in financial services and other risk-intensive industries where risk oversight has outgrown what the audit committee's financial-reporting mandate can reasonably absorb.
**Impact:** Companies relying solely on the audit committee for enterprise risk oversight are documented to experience gaps in non-financial risk categories (operational, strategic, cybersecurity, reputational risk) that don't map naturally onto the audit committee's core financial-reporting expertise and already-full agenda, while companies with a dedicated risk oversight structure demonstrate more comprehensive, integrated risk visibility across these broader categories.
**Why best:** The audit committee's mandate and expertise are specifically oriented toward financial reporting and internal controls — asking it to also serve as the primary venue for enterprise-wide risk oversight (strategic risk, operational risk, cyber risk, reputational risk) stretches its bandwidth and expertise beyond its core function, while a dedicated committee (or clearly defined full-board process) provides the specific structure and bandwidth this broader oversight function actually requires.
Sources: Committee of Sponsoring Organizations of the Treadway Commission (COSO), "Enterprise Risk Management — Integrating with Strategy and Performance" (2017); National Association of Corporate Directors (NACD), board risk oversight guidance
## Steps
### Step 1: Decide between a dedicated risk committee and a full-board process
Decide whether the company's risk profile and scale warrant a dedicated risk committee, or whether a clearly defined full-board risk oversight process (with specific agenda time and reporting structure) is more proportionate — larger, more complex, or more risk-intensive organizations (particularly financial institutions) more commonly warrant a dedicated committee.
### Step 2: Define the committee's scope distinct from the audit committee
Define the committee's scope to cover enterprise-wide risk categories — strategic, operational, cyber, reputational, and other major risk categories — explicitly distinct from (and coordinated with, not duplicating) the audit committee's financial-reporting and internal-controls-specific mandate.
### Step 3: Establish the committee's connection to the organization's risk appetite
Establish the committee's responsibility for reviewing and recommending the organization's overall risk appetite — how much risk the organization is willing to accept in pursuit of its objectives — as the reference standard against which specific risks and management's risk responses are evaluated.
### Step 4: Establish management reporting lines into the committee
Establish clear reporting lines from a Chief Risk Officer or equivalent risk management function into the committee on a defined cadence, ensuring the committee receives substantive, structured risk information rather than only ad hoc or crisis-driven updates.
### Step 5: Coordinate explicitly with other committees to avoid gaps or duplication
Explicitly coordinate the risk committee's scope with the audit committee, ESG/sustainability committee, and any other risk-adjacent committees to ensure risk categories are clearly allocated without gaps (a risk category no committee owns) or duplication (multiple committees separately, redundantly covering the same risk).
## Rules
- Decide deliberately between a dedicated committee and a defined full-board process, based on the organization's actual risk profile and scale — not by default assumption either way.
- Define the committee's scope explicitly distinct from the audit committee's financial-reporting mandate, covering the broader enterprise risk categories.
- Connect the committee's oversight explicitly to the organization's defined risk appetite, not an undifferentiated general risk discussion.
- Coordinate explicitly with other risk-adjacent committees to avoid both oversight gaps and duplicated coverage.
## Examples
**Dedicated committee providing focused oversight the audit committee couldn't sustain:** A financial services company establishes a dedicated risk committee specifically because its audit committee's financial-reporting workload had left insufficient bandwidth for genuine strategic and operational risk oversight. The new committee's dedicated focus surfaces and addresses a cybersecurity risk gap that had received only cursory attention under the prior audit-committee-only structure.
**Explicit coordination avoiding a scope gap:** A board explicitly allocates climate-related risk to its risk committee and financial-reporting risk to its audit committee, documenting the boundary in both committees' charters. When a climate-related regulatory risk emerges with financial reporting implications, the two committees coordinate directly rather than each assuming the other has ownership — a coordination the explicit allocation specifically enabled.
## Common Mistakes
- **Relying solely on the audit committee for all enterprise risk oversight** — this stretches the audit committee's financial-reporting-oriented mandate and bandwidth beyond what it can reasonably absorb for broader risk categories.
- **Establishing a dedicated risk committee without clearly distinguishing its scope from the audit committee's** — overlapping, undifferentiated scope produces confusion and potential duplication rather than genuine additional coverage.
- **Failing to connect risk oversight explicitly to a defined risk appetite** — without this reference standard, risk discussions lack a consistent basis for evaluating whether a specific risk or response is actually acceptable.
- **Neglecting to coordinate explicitly with other risk-adjacent committees** — this risks either gaps (no committee owning a specific risk category) or duplication (multiple committees separately covering the same ground).
## When NOT to Use
- For a smaller or less risk-intensive organization where a dedicated risk committee is disproportionate to actual risk complexity — a defined full-board risk oversight process may be more appropriate at this scale.
- As a substitute for the audit committee's specific financial-reporting and internal-controls oversight — enterprise risk committee oversight complements, but doesn't replace, the audit committee's distinct mandate (see `design-audit-committee-charter`).
- As a substitute for the organization's own operational risk management process — board-level committee oversight provides governance accountability; it doesn't replace the management-level work of actually identifying and managing specific risks (see `apply-iso-31000-risk-framework`).
> **Legal disclaimer:** This skill encodes professional best practices for educational purposes. It is not legal advice. Board risk oversight structure requirements vary by industry (particularly for regulated financial institutions) and jurisdiction — consult licensed corporate governance counsel for requirements specific to your organization.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!