Building Resilience Starts with Better Risk Thinking in ERM
CIOREVIEW >> Enterprise Risk Management >> NEWS

Andersen Corporation

Paul Stone, Director of Enterprise Risk Management

Building Resilience Starts with Better Risk Thinking in ERM

Paul Stone, Director of Enterprise Risk Management
Paul Stone, Director of Enterprise Risk Management, Andersen Corporation

Paul Stone

Governance Risk Advisor

Enterprise Risk Management (ERM) has evolved significantly over the past decade. What once functioned primarily as a compliance-driven discipline is now an essential leadership capability, one that shapes strategy, resilience and long-term value creation. My own approach to risk leadership has been shaped less by textbooks or frameworks and more by real-world complexity: navigating uncertainty while connecting with business teams or partners to help enable growth in the dynamic business environments.

The most defining influence on my approach has been recognizing that risk is intertwined with decision-making. Early in my career, risk management was often positioned as a risk control function—focused on identifying issues after decisions were already made. Over time, I’ve learned that risk leaders create far greater value when they are involved earlier, helping leaders understand the risks and potential outcomes of risk before decisions are made.

Equally important has been experience across different risk domains including strategic, operational, financial and emerging risks. These experiences reinforced that risks rarely exist in isolation. The most impactful issues are interconnected, crossing functional and organizational boundaries. This reality requires risk leaders to think systemically and communicate clearly, translating complexity into insights that leaders can act upon with confidence as they build out their mitigation plans and balance these with their risk appetite.

One of the most common misconceptions about ERM is that managing risk means slowing the business down. The goal is not risk avoidance, but risk alignment—ensuring that the risks we take are intentional, understood and consistent with the organization’s objectives and risk appetite. I want to know if a leader is taking enough risk or if they should be taking more risk which may get them to a better outcome.

Balancing mitigation and growth are moving to risk conversations around resiliency. Instead of asking, “How do we prevent this from happening?” I really want to know what options we have to get to an outcome that will give us a longer-term solution that points the organization toward growth. This shift can show a different side of a risk assessment with a different set of questions, constructive dialogue and positions risk as a partner in innovation and risk mitigation.

  There is not a right or wrong way to lead ERM, but the key is how the risk leader can facilitate the conversations toward a more resilient outcome.  

Several trends are reshaping the ERM landscape over the past number of years. First is the acceleration of change, driven by technology, geopolitical uncertainty and evolving regulatory expectations. Risks are emerging faster and often with less historical data, which challenges traditional assessment methods.

Second, organizations are placing increased emphasis on resilience. This includes supply chain continuity, cyber preparedness and workforce adaptability. I am trying to move from an emphasis on score carding risk and completing risk registers, etc (not that these will go away) to using the mitigation plans to build long term resiliency.

Finally, managing emerging risks which often come with limited data, limited experience and at times limited knowledge of the risk at hand. The organizations that can find the “artful” solutions with these limitations will be building resiliency and stability in their business and unlocking the key to successfully mitigating these risks

Embedding risk awareness is ultimately more about culture than structure. Policies and frameworks matter, but they are ineffective without engaged leaders and employees who understand their role in managing risk.

In my experience, this starts with speaking the language of the business. Risk professionals must move away from technical jargon and connect risk concepts to everyday decisions. The most powerful driver is consistent behavior from senior leaders who visibly integrate risk thinking into strategic and operational conversations.

For those aspiring to leadership roles in risk, my advice is simple: develop both technical depth and business fluency. Understanding frameworks and methodologies is important, but influence comes from credibility and relationships and flexibility. There is not a right or wrong way to lead ERM, but the key is how the risk leader can facilitate the conversations toward a more resilient outcome.

Equally important is curiosity. The risk landscape will continue to evolve and effective leaders must be comfortable with ambiguity. Ask better questions, challenge assumptions respectfully and focus on enabling informed decisions rather than providing perfect answers.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.