ABSTRACT Approaches to risk governance are not homogeneous across organizations. Some organizations invest heavily in building formal and strategically focused enterprise-wide risk governance processes whereas others exhibit reduced formality and focus, allowing risk governance to be less structured. We argue that risk governance may best be described as a service dependent upon a network (or ecosystem) of participants who include users of risk information and providers who design and implement risk governance processes. Using a survey sample of 2,380 observations from 2011 to 2016, we find that external calls for enhanced risk governance are positively associated with risk governance processes having greater formality and strategic focus. We find this relationship is partially mediated by internal demands for enhanced risk governance. Further, we find that the positive association between internal demands and enhanced risk governance is reduced by resource constraints and that a risk-seeking attitude is negatively associated with enhanced risk governance. Data Availability: Contact the authors. JEL Classifications: G30; M10; M14; M40.
Recent corporate governance failures have heightened stakeholder expectations that the board of directors engage in robust oversight of the firm’s risk management processes. This expectation is in line with widely embraced enterprise risk management frameworks, which assert that strong board risk management is a key component of an entity’s risk management process. We use a hand-coded measure of board engagement in risk management from the recent literature to measure the robustness of that oversight for a sample of large, publicly traded U.S. firms and examine the relationship between robust board risk management (board risk management) and firm-wide strategies for mitigating financial reporting risk. While controlling for board composition-related characteristics, we found a positive association between robust board risk management processes and two avenues for mitigating financial reporting risk (i.e., more effective internal control over financial reporting and the selection of industry specialist auditors). Our results indicate that firms with more robust board risk management are associated with fewer actual instances of materially misstated financial statements and less earnings management.
The speed of change, including the emergence of new technologies, geopolitical disruptions, and escalating environmental and social challenges create uncertainties that can trigger complex risks derailing an organization’s business model and strategic plan. None of these risks behave in isolation, highlighting the need for executives to monitor and manage a rapidly evolving portfolio of interconnected risks.
We report on the results obtained from ten annual surveys of global business executives on their perceptions of the most significant risks facing their organizations in the ensuing calendar year. These surveys of C-suite executives, directors and other risk professionals elicit their concerns about risks that may affect their organization’s success over the near-term horizon (i.e., the next calendar year). After a decade, we believe these results provide an opportunity to examine how the global risk landscape has evolved. In addition, two additional survey questions allow us to examine how these executives view the overall risk context and how enterprise risk management (ERM) is deployed and augmented in the face of an escalating risk environment. On average, we find that executives view the risk landscape they face as persistently risky over the ten-year period, even during the relatively robust economic environments for much of that time frame. Two industries report much more volatility in their risk environments, with respondents from the Healthcare sector and in Technology, Media and Telecommunications acknowledging the largest volatility. We also observe an increase in entities’ decisions to devote more time and resources to risk management over the ten-year period, suggesting that ERM has become an essential mechanism for organizational success. Our goal is to highlight the realities of constantly changing risk conditions and how context (e.g., industry and time) is an important distinguishing factor that affects an organization’s given risk profile, which is relevant to both executives and academics. Collectively, our findings emphasize the importance of understanding the ever-changing context of an organization’s environment, that risk identification must be an ongoing process, and that there is no “one-size-fits-all” approach to risk governance. We believe all this signals the importance of future research to help organizations respond with robust risk governance.
Risk oversight by the board of directors is a key component of a firm's enterprise risk management framework, and recently, boards have paid more attention to their firm's tax-planning activities. In this study, we use a hand-collected sample of proxy statement disclosures about the board's role in risk oversight and provide evidence that risk oversight is negatively associated with both tax uncertainty and overall tax burdens. We find that risk oversight is most strongly associated with positions that yield permanent tax benefits and also with less risky tax-planning activities. Overall, the evidence suggests that board risk oversight is associated with more effective tax-planning practices.
The U.S. Securities and Exchange Commission (SEC) requires companies it regulates to include disclosures about the board's role in risk oversight in the annual proxy statement to shareholders. The SEC does not mandate specific content or actions that boards should perform as part of their risk oversight responsibilities, leaving the nature of activities and extent of those disclosures to the discretion of the reporting entity. This study examines whether these disclosures contain substantive information reflective of the effectiveness of the organization's risk oversight. We find that organizations disclosing more specific information (but not simply more information) about board risk oversight practices are associated with firms independently assessed as having the strongest management and governance processes. These findings suggest that these firms use the discretion provided by the SEC's disclosure rule to provide substantive and potentially value-relevant information for stakeholders about the entity's risk management processes and board risk oversight activities. (c) 2020 Elsevier Inc. All rights reserved.
Corporate governance failures in the early 2000s and the financial crisis that emerged in 2008 have contributed to heightened expectations for the board of directors to strengthen its oversight of the firm’s risk management processes. Thought leaders (COSO 2013, 2017, ISO 2018; NYSE 2004; SEC 2010) stress the importance of board risk oversight processes; however, we know little about what boards actually do to fulfill their risk oversight responsibilities. Most of the existing research has focused on the association between certain board of director input characteristics (e.g. member composition, independence, expertise, tenure, etc.) and a variety of financial reporting related outcomes. Studies have called for additional examination of what boards actually do to fulfill their oversight roles (e.g. Cohen, Krishnamoorthy and Wright 2017; Beasley, Carcello, Hermanson, and Neal 2009). Our study responds to this need by utilizing proxy disclosures about the board’s role in risk oversight, instituted by the SEC in 2010, to examine whether boards more engaged in risk oversight processes are associated with a lower risk of material misstatement (RMM) in the financial statements, while controlling for board input characteristics documented by prior studies. We find that boards more engaged in risk oversight are positively associated with two avenues for mitigating RMM: effective internal control over financial reporting and higher auditor quality. In addition, we find that boards with more extensive risk oversight processes are associated with fewer actual instances of materially misstated financial statements.
SYNOPSIS Since the early 2000s, expectations have increased for organizations to strengthen corporate governance with enterprise risk management (ERM) processes, with the accounting profession playing a major role in these efforts. The ultimate goal of an effective ERM process is to help boards and senior executives to manage risks in the context of strategy so that the organization is more likely to achieve its key objectives. We conduct semi-structured interviews of 15 ERM champions to provide insights about whether the ERM process is integrated with the strategic-planning and execution processes of the firm. We find that while the decision to launch ERM often is based on a desire for ERM to provide strategic value, the integration of ERM with strategy typically is limited. We then examine the ERM implementation process to identify possible ERM implementation practices limiting ERM's integration with strategy. We find that organizations' (1) culture and approach to preparing for ERM's launch, (2) ERM leadership structure, and (3) management of key risks appear to limit the intersection of ERM and strategy. Our summary of key findings highlights important considerations for boards of directors, executive management, and auditors as they assess the effectiveness of their risk oversight efforts in overseeing the strategic direction of the enterprise.
In recent years, expectations for increased risk governance have been placed explicitly on boards of directors. In response, boards are being held responsible for not only understanding and approving management's risk management processes, but they are also being held responsible for assessing the risks identified by those processes as part of overseeing management's pursuit of value. These increasing responsibilities have led a number of organizations to adopt enterprise risk management (ERM) as a holistic approach to risk management that extends beyond traditional silo-based risk management techniques. As boards, often through their audit committee, consider management's implementation of ERM as part of the board's risk oversight, a number of questions emerge that can be informed by academic research related to ERM. This article summarizes findings from ERM research to provide insights related to the board's risk governance responsibilities. We also identify a number of research questions that warrant further analysis by governance scholars. It is our hope that this article will spawn varying types of research about ERM and corporate governance.
Over the past decade, expectations for more effective oversight of risks by boards of directors have significantly increased. These expectations emanate from stock exchanges, regulators, credit rating agencies and other key stakeholders. Proponents of enhanced risk oversight argue that an increased understanding of enterprise-wide risks provides strategic benefit by helping the board and management identify and manage risks that may impact the achievement of strategic objectives while at the same time helping the board monitor the extent of risk-taking on the part of management in their desire to meet these objectives. In response to these growing expectations, some boards have asked management to embrace a more holistic, top-down approach to risk oversight widely known as enterprise risk management (ERM) while others have not. Little is known about the way in which boards and management organize their processes and the impact of those processes on the level of ERM adoption. More importantly, little is known about the extent to which ERM is perceived to provide strategic benefit to those organizations that have invested in developing a robust ERM process. Based on data gathered from over 750 survey responses from executives of organizations spanning a number of industries and sizes, we find that organizations with greater ERM maturity are significantly more likely to have taken steps to formally engage the board and senior management in specific risk oversight tasks, and certain board and management risk practices are associated with perceptions that ERM provides strategic advantage.
[ILLUSTRATION OMITTED] Accountants typically have significant training and experience in managing risks related to internal controls, financial reporting, and other compliance matters--traditional skills they can leverage to become strategic risk advisers for their organizations. Pamela Short Jenkins, CPA, vice president of audit services at US Foods in Rosemont, Ill., said she plays a crucial role in assessing strategic risks as her company seeks growth opportunities in the marketplace. US Foods distributes more than 350,000 products to restaurants, hospitals, and governmental and educational institutions. knowledge and skills of our financial team, including our internal audit function, play a significant role in helping facilitate consideration and communication of risks on the horizon that may affect our core business model and strategy, Jenkins said. As facilitator of our company's enterprise risk oversight process, I am heavily engaged in the identification and discussion of our organization's most significant strategic risks, which our team summarizes for monitoring by senior management and the board of directors. Risks that threaten an organization's strategic plan and execution, such as competitor moves, emerging disruptive innovations, changes in customer demographics, and new regulations, can significantly affect an organization's long-term value as is shown by the declines of former corporate giants such as Blockbuster, Circuit City, and Kodak. But the fact that accountants have traditionally focused more on loss prevention than on risks impacting an enterprise's strategic direction and success poses challenges as CPAs take on new roles in risk oversight. Mastering these challenges, however, offers them a chance to become strategic risk advisers for their organizations. THE CHALLENGES FOR ACCOUNTANTS Accountants assemble financial statement data to identify, record, and report key financial information for periods that have already passed. Focusing on what has already emerged tends to put accountants in a position of reacting to risks rather than proactively navigating risks before they occur. Other responsibilities reinforce accountants' attention to compliance, such as operational audits performed by internal audit and requirements of Section 404 of the Sarbanes-Oxley Act of 2002, P.L. 107-204. Section 404 involves evaluating the effectiveness of internal controls and whether any deficiencies might trigger the potential of a material misstatement in the financial statements. While important, these compliance responsibilities do not foster thinking about risks emerging from macroeconomic events, emerging geopolitical shifts, emerging technologies, competitor moves, and other important strategic concerns. To change the perception that they are mostly risk-averse, accountants should focus on appropriately balancing risk-taking with expected returns. THE OPPORTUNITY FOR ACCOUNTANTS TO BECOME STRATEGIC ADVISERS Accountants have a unique understanding of an organization's financial position (assets, liabilities, and capital) and what drives revenue and expenses. That allows them to add value in the context of strategic risk management. This is illustrated in Exhibit 1 for a for-profit organization. The red rectangle on the far right focuses on the organization's long-term strategic objective of growing shareholder value. The orange rectangles in the center illustrate examples of existing drivers of shareholder value that will continue to be important to the business. These drivers are the organization's crown jewels. The light blue rectangles illustrate new strategic initiatives contained in the organization's strategic plan that will be implemented in the future to drive additional shareholder value. Having a rich understanding of what drives the business and what is on the horizon related to new strategic initiatives is an important first step toward becoming an effective participant in broader, more-strategic enterprisewide risk management processes. …