Saif Ali AlghamdiTransformation & Growth Advisor
تواصل
LibraryمكتبتيRisk & Diagnosticsمخاطر وتشخيص
FRAMEWORKS · OPERATIONAL FRAMEWORKالأطر · إطار تشغيلي

Enterprise Risk Managementإدارة مخاطر المؤسسة

SectionالقسمRisk & Diagnosticsمخاطر وتشخيص
Reading timeزمن القراءة7 min٧ دقيقة
ByإعدادSaif Alghamdiسيف الغامدي
One

Overview

Field: Enterprise risk management (ERM)
Scope: Managing risk across the whole organization as one portfolio
Owner role: Chief risk officer, sponsored by the board
Review cadence: Continuous, with an enterprise risk review each quarter
By: Saif Alghamdi

Enterprise risk management is the practice of understanding and managing risk across an entire organization as a single connected portfolio, rather than letting each department handle its own risks in isolation. Its purpose is to give leadership one coherent view of the uncertainties that could threaten the organization's objectives, so that risk is weighed deliberately in every major decision.

The difference from ordinary risk management is the word enterprise. In a siloed approach, finance manages financial risk, operations manages operational risk, and IT manages technology risk, each competently but separately, so no one sees how they combine, and a risk that is small in each silo can be large in aggregate. ERM lifts the view to the whole organization, so that risks are compared on one scale, their interactions are visible, and scarce risk-management effort flows to what matters most across the enterprise, not just within each function.

This framework describes ERM as a governed, continuous capability, drawing on the integrated structure of the COSO ERM framework and the principles and process of ISO 31000. It is written to be reusable across sectors and aligns to both without reproducing their text.

Note: ERM is not about avoiding risk, it is about taking the right risks knowingly. An organization that takes no risk earns no return, so the goal is to understand risk well enough to accept it deliberately where it is worth it.
الأول

نظرة عامة

المجال: إدارة مخاطر المؤسسة (ERM)
النطاق: إدارة المخاطر عبر المنشأة كلها كمحفظةٍ واحدة
دور المالك: رئيس المخاطر، برعاية المجلس
دورية المراجعة: مستمرة، مع مراجعة مخاطر مؤسسيةٍ كل ربع
إعداد: سيف الغامدي

إدارة مخاطر المؤسسة ممارسة فهم المخاطر وإدارتها عبر المنشأة كلها كمحفظةٍ واحدة متصلة، بدل ترك كل إدارةٍ تعالج مخاطرها بمعزل. وغرضها منح القيادة رؤيةً متماسكة واحدة لعدم اليقين الذي قد يهدّد أهداف المنشأة، فيُوزَن الخطر عن قصد في كل قرارٍ كبير.

الفرق عن إدارة المخاطر العادية كلمة «المؤسسة». ففي نهجٍ صومعي، تدير المالية الخطر المالي، والعمليات الخطر التشغيلي، والتقنية خطر التقنية، كلٌّ بكفاءةٍ لكن منفصلًا، فلا أحد يرى كيف تتجمّع، وخطرٌ صغير في كل صومعة قد يكون كبيرًا في المجموع. وERM ترفع الرؤية للمنشأة كلها، فتُقارَن المخاطر على مقياسٍ واحد، وتُرى تفاعلاتها، ويتدفّق جهد إدارة المخاطر النادر إلى الأهمّ عبر المؤسسة لا داخل كل وظيفةٍ فقط.

يصف هذا الإطار ERM كقدرةٍ محوكَمة مستمرة، مستندًا إلى البنية المتكاملة لإطار COSO ومبادئ وعملية ISO 31000. وهو قابل لإعادة الاستخدام عبر القطاعات ويتوافق مع كليهما دون نسخ نصّهما.

ملاحظة: ERM ليست تجنّب الخطر، بل أخذ المخاطر الصحيحة عن علم. فمنشأةٌ لا تأخذ خطرًا لا تكسب عائدًا، فالهدف فهم الخطر بما يكفي لقبوله عن قصدٍ حيث يستحق.
Two

The Components of ERM

A recognized way to structure ERM organizes it into interrelated components that together make risk management a continuous, integrated capability rather than a periodic report. Each component addresses a different part of embedding risk into how the organization runs.

The components run from the cultural foundation through to reporting. Governance and culture set the tone and the accountability for risk. Strategy and objective-setting weave risk into the choices the organization makes about its direction. Performance identifies, assesses, and responds to the risks to achieving objectives. Review and revision keep the whole thing current as conditions change. And information, communication, and reporting carry risk knowledge to where decisions are made. Read together, they describe risk management that lives inside strategy and operations, not beside them.

  • Governance and culture: the tone at the top and the shared attitudes that make risk everyone's concern.
  • Strategy and objective-setting: considering risk as strategy is formed, not after it is set.
  • Performance: identifying, assessing, prioritizing, and responding to the risks to objectives.
  • Review and revision: checking whether risk management is still working and improving it.
  • Information and reporting: communicating risk to decision-makers in usable form.

The placement of strategy so early is the defining insight of modern ERM. Older approaches treated risk as something to assess after the strategy was chosen, but that is too late, because the biggest risk an organization faces is often the strategy itself. Considering risk while strategy is being formed, asking not only can we execute this but what could make this the wrong strategy, is where ERM adds the most value and where its absence has sunk the most companies.

Note: The greatest risks are usually strategic, not operational. A perfectly executed strategy aimed at a declining market fails, so ERM has to reach into strategy, not just guard the operations beneath it.
الثاني

مكوّنات ERM

من الطرق المعترف بها لبناء ERM تنظيمها في مكوّناتٍ مترابطة تجعل إدارة المخاطر معًا قدرةً مستمرة متكاملة لا تقريرًا دوريًا. وكل مكوّنٍ يعالج جزءًا مختلفًا من دمج الخطر في كيف تعمل المنشأة.

تمتد المكوّنات من الأساس الثقافي إلى التقارير. الحوكمة والثقافة تضعان النبرة والمساءلة عن الخطر. والاستراتيجية ووضع الأهداف تنسجان الخطر في خيارات المنشأة حول اتجاهها. والأداء يحدّد مخاطر تحقيق الأهداف ويقيّمها ويستجيب لها. والمراجعة والتنقيح يُبقيان الكل محدَّثًا مع تغيّر الظروف. والمعلومات والتواصل والتقارير تحمل معرفة الخطر حيث تُتَّخذ القرارات. ومقروءةً معًا، تصف إدارة مخاطر تعيش داخل الاستراتيجية والعمليات لا بجانبهما.

  • الحوكمة والثقافة: النبرة من القمة والمواقف المشتركة التي تجعل الخطر شأن الجميع.
  • الاستراتيجية ووضع الأهداف: مراعاة الخطر أثناء تشكيل الاستراتيجية لا بعد وضعها.
  • الأداء: تحديد مخاطر الأهداف وتقييمها وترتيبها والاستجابة لها.
  • المراجعة والتنقيح: فحص هل ما زالت إدارة المخاطر تعمل وتحسينها.
  • المعلومات والتقارير: إيصال الخطر لصنّاع القرار بصورةٍ قابلة للاستخدام.

وضعُ الاستراتيجية مبكرًا هكذا هو البصيرة المميِّزة لـ ERM الحديثة. فالنُهج الأقدم عاملت الخطر كشيءٍ يُقيَّم بعد اختيار الاستراتيجية، لكن ذلك متأخّر، لأن أكبر خطرٍ تواجهه منشأةٌ غالبًا الاستراتيجية نفسها. ومراعاة الخطر أثناء تشكيل الاستراتيجية، بالسؤال لا «هل نستطيع تنفيذ هذا» فقط بل «ما الذي قد يجعل هذه الاستراتيجية خاطئة»، حيث تضيف ERM أعظم قيمة وحيث أغرق غيابها أكثر الشركات.

ملاحظة: أعظم المخاطر عادةً استراتيجية لا تشغيلية. فاستراتيجيةٌ مُنفَّذة بإتقانٍ موجَّهة لسوقٍ آفلة تفشل، فعلى ERM أن تصل إلى الاستراتيجية لا أن تحرس العمليات تحتها فقط.
Three

Risk Appetite

At the enterprise level, the single most important decision is how much risk the organization is willing to take in pursuit of its objectives. This risk appetite is the reference point against which every significant risk is judged.

Risk appetite translates the board's attitude to risk into a usable guide. It states, in terms the organization can act on, how much uncertainty it will accept overall and in specific areas, so that managers throughout the organization make decisions consistent with what leadership actually wants. Without a stated appetite, risk decisions are made inconsistently, some managers too cautious and others too bold, and the organization's actual risk-taking becomes an accidental sum of individual temperaments rather than a deliberate choice.

Appetite is most useful when it distinguishes between types of risk. An organization might have a healthy appetite for market and innovation risk, where taking risk is how it earns its return, while having almost no appetite for compliance or safety risk, where a failure is unacceptable regardless of the potential upside. Stating these differences explicitly stops the organization from accidentally trading a risk it should never take for a reward in an area where it should be bold.

Risk appetite guides every decision: is this risk within what the board has said we will accept, here?
Note: Risk appetite is a board-level statement, but its value is at the front line. It only works if it is expressed concretely enough that a manager making a real decision can tell whether their choice is inside it or outside it.
الثالث

شهية المخاطر

على مستوى المؤسسة، أهمّ قرارٍ مفرد كم من الخطر مستعدّة المنشأة لأخذه سعيًا لأهدافها. وشهية المخاطر هذه هي المرجع الذي يُحكَم عليه كل خطرٍ مهمّ.

شهية المخاطر تترجم موقف المجلس من الخطر إلى دليلٍ قابل للاستخدام. تذكر، بعباراتٍ تستطيع المنشأة التصرّف بها، كم من عدم اليقين تقبل إجمالًا وفي مجالاتٍ بعينها، فيتّخذ المديرون عبر المنشأة قراراتٍ متّسقة مع ما تريده القيادة فعلًا. وبلا شهيةٍ مُعلَنة، تُتَّخذ قرارات الخطر بلا اتساق، بعض المديرين مفرطون في الحذر وآخرون في الجرأة، ويصير أخذ المنشأة للخطر مجموعًا عرضيًا لأمزجةٍ فردية لا خيارًا متعمَّدًا.

الشهية أنفع ما تكون حين تميّز بين أنواع الخطر. فقد يكون لمنشأةٍ شهيةٌ صحّية لخطر السوق والابتكار، حيث أخذ الخطر هو كيف تكسب عائدها، بينما لا تكاد تملك شهيةً لخطر الامتثال أو السلامة، حيث الفشل غير مقبولٍ مهما كان العائد المحتمل. وإعلان هذه الفروق صراحةً يمنع المنشأة من مقايضة خطرٍ ينبغي ألّا تأخذه أبدًا بعائدٍ في مجالٍ ينبغي أن تكون فيه جريئة.

شهية المخاطر توجّه كل قرار: هل هذا الخطر ضمن ما قال المجلس إننا سنقبله، هنا؟
ملاحظة: شهية المخاطر بيانٌ على مستوى المجلس، لكن قيمتها في الخطّ الأمامي. ولا تعمل إلا إن عُبِّر عنها بعينيّةٍ تكفي ليعرف مديرٌ يتّخذ قرارًا حقيقيًا هل خياره داخلها أم خارجها.
Four

Identify, Assess, Respond

Within the enterprise view, each risk is handled through the same disciplined process: find it, size it, decide what to do, and watch it. The process is familiar from risk management generally, but at the enterprise level it is applied consistently so that risks from every corner can be compared.

The steps build on each other. Identification finds the risks to the organization's objectives, across strategy, operations, finance, compliance, and beyond. Assessment sizes each by its likelihood and impact so they can be ranked on one scale. Response chooses how to treat each significant risk, to reduce, avoid, share, or accept it, exactly as in any risk framework. And monitoring keeps the picture current, because the enterprise risk profile shifts constantly. What ERM adds is consistency: because every function uses the same scale and process, a strategic risk and an operational one land in the same ranked list, and leadership can see the true top risks of the whole organization.

  • Identify: surface the risks to objectives from every part of the organization, not just the obvious ones.
  • Assess: size each risk by likelihood and impact on one consistent enterprise scale.
  • Respond: reduce, avoid, share, or accept each significant risk, with a named owner.
  • Monitor: track the changing enterprise risk profile and re-run the cycle continuously.

The portfolio view reveals what silos hide: interactions between risks. Two risks that are each individually acceptable can combine into one that is not, and a single event can trigger several risks at once, a pattern that only becomes visible when risks are looked at together. Seeing these connections, and the concentrations where many objectives depend on one thing going right, is the distinctive value that justifies the enterprise in enterprise risk management.

Note: Aggregate before you conclude. The enterprise view exists to catch the risk that is invisible in any single silo but material to the organization as a whole.
الرابع

التحديد والتقييم والاستجابة

ضمن رؤية المؤسسة، يُعالَج كل خطرٍ بالعملية المنضبطة نفسها: جِده، وقِسه، وقرّر ما تفعل، وراقبه. والعملية مألوفةٌ من إدارة المخاطر عمومًا، لكنها على مستوى المؤسسة تُطبَّق باتساقٍ لتُقارَن مخاطر كل ركن.

الخطوات تبني على بعضها. التحديد يجد مخاطر أهداف المنشأة، عبر الاستراتيجية والعمليات والمالية والامتثال وأبعد. والتقييم يقيس كلًّا باحتماله وأثره ليُرتَّب على مقياسٍ واحد. والاستجابة تختار كيف يُعالَج كل خطرٍ مهمّ، بالتقليل أو التجنّب أو المشاركة أو القبول، كأي إطار مخاطر. والمراقبة تُبقي الصورة محدَّثة، لأن ملف مخاطر المؤسسة ينزاح باستمرار. وما تضيفه ERM هو الاتساق: فلأن كل وظيفةٍ تستخدم المقياس والعملية نفسيهما، يقع خطرٌ استراتيجي وآخر تشغيلي في القائمة المرتَّبة نفسها، وترى القيادة أعلى مخاطر المنشأة كلها حقًّا.

  • التحديد: أظهِر مخاطر الأهداف من كل جزءٍ من المنشأة، لا الظاهرة فقط.
  • التقييم: قِس كل خطرٍ باحتماله وأثره على مقياسٍ مؤسسي متّسق واحد.
  • الاستجابة: قلّل أو تجنّب أو شارك أو اقبل كل خطرٍ مهمّ، بمالكٍ مُسمّى.
  • المراقبة: تتبّع ملف مخاطر المؤسسة المتغيّر وأعِد الدورة باستمرار.

رؤية المحفظة تكشف ما تُخفيه الصوامع: تفاعلات المخاطر. فخطران كلٌّ مقبول منفردًا قد يجتمعان في واحدٍ غير مقبول، وحدثٌ واحد قد يُطلِق عدّة مخاطر دفعةً، نمطٌ لا يظهر إلا حين يُنظَر للمخاطر معًا. ورؤية هذه الصلات، والتركّزات حيث تعتمد أهدافٌ كثيرة على صحّة شيءٍ واحد، هي القيمة المميِّزة التي تبرّر «المؤسسة» في إدارة مخاطر المؤسسة.

ملاحظة: اجمع قبل أن تستنتج. فرؤية المؤسسة موجودةٌ لالتقاط الخطر الخفيّ في أي صومعةٍ مفردة لكنه جوهري للمنشأة ككل.
Five

Integration & Reporting

ERM only delivers value if it is woven into how the organization actually makes decisions, not run as a parallel reporting exercise. Integration is what separates ERM that shapes the business from ERM that merely describes it.

Integrated ERM shows up when risk is a standing input to real decisions: a major investment carries a risk assessment, a strategic choice is tested against the risk appetite, and the board sees the enterprise risk profile alongside performance, not in a separate meeting no one connects to strategy. When ERM is instead a quarterly report produced by a risk team and filed, it consumes effort and changes nothing, which is the most common way ERM fails, not by getting the risks wrong but by having no path from knowing them to acting on them.

Top
Enterprise risks above appetite
KRI
Indicators trending toward the line
%
Risk responses completed on time

Reporting that drives action

Reporting is the bridge from risk knowledge to decision, and it works only when it is aimed at the audience that can act. The board needs the handful of enterprise risks that could threaten strategy, with a trend; an executive needs the risks and responses in their area. Key risk indicators, early-warning signals that a risk is rising, make reporting forward-looking rather than a record of what already went wrong. The test of ERM reporting is simple: has a risk report ever changed a decision. If not, the reporting is description, not management.

Bottom line: enterprise risk management creates value by seeing risk across the whole organization as one portfolio, judging it against a stated appetite, embedding it in strategy and decisions, and reporting it so it actually changes what the organization does.
الخامس

الدمج والتقارير

ERM لا تسلّم قيمةً إلا إن نُسِجت في كيف تتّخذ المنشأة قراراتها فعلًا، لا أن تُدار كتمرين تقارير موازٍ. والدمج هو ما يفصل ERM التي تُشكّل العمل عن التي تصفه فحسب.

ERM المدمجة تظهر حين يكون الخطر مُدخَلًا دائمًا لقراراتٍ حقيقية: استثمارٌ كبير يحمل تقييم خطر، وخيارٌ استراتيجي يُختبَر مقابل شهية المخاطر، ويرى المجلس ملف مخاطر المؤسسة بمحاذاة الأداء، لا في اجتماعٍ منفصل لا يربطه أحد بالاستراتيجية. وحين تكون ERM بدل ذلك تقريرًا ربعيًا يُنتِجه فريق مخاطرٍ ويُحفَظ، تستهلك جهدًا ولا تغيّر شيئًا، وهو أشيع طرق فشلها، لا بإخطاء المخاطر بل بغياب مسارٍ من معرفتها إلى الفعل بها.

الأعلى
مخاطر مؤسسية فوق الشهية
KRI
مؤشرات تتّجه نحو الخط
%
استجابات خطرٍ أُنجزت في وقتها

تقاريرٌ تقود الفعل

التقارير جسرٌ من معرفة الخطر إلى القرار، ولا تعمل إلا حين تُوجَّه للجمهور القادر على الفعل. فالمجلس يحتاج حفنة مخاطر المؤسسة التي قد تهدّد الاستراتيجية، باتجاه؛ والتنفيذي يحتاج المخاطر والاستجابات في مجاله. ومؤشرات المخاطر الرئيسة، إشارات إنذارٍ مبكر بأن خطرًا يرتفع، تجعل التقارير استشرافيةً لا سجلًّا لما ساء أصلًا. واختبار تقارير ERM بسيط: هل غيّر تقرير خطرٍ قرارًا يومًا. فإن لا، فالتقارير وصفٌ لا إدارة.

الخلاصة: إدارة مخاطر المؤسسة تخلق القيمة برؤية الخطر عبر المنشأة كلها كمحفظةٍ واحدة، والحكم عليه مقابل شهيةٍ مُعلَنة، ودمجه في الاستراتيجية والقرارات، والتبليغ عنه بحيث يغيّر فعلًا ما تفعله المنشأة.
Six

Key Takeaways & References

Enterprise risk management manages uncertainty across the whole organization as one portfolio, so risk is taken deliberately in service of objectives.

  • Lift risk from silos to the enterprise so risks are compared, their interactions seen, and effort aimed at what matters most.
  • Embed risk in strategy from the start, because the biggest risks are usually strategic.
  • Set a clear risk appetite, distinguished by risk type, as the reference for every decision.
  • Apply one consistent identify-assess-respond-monitor process, and aggregate to reveal hidden interactions.
  • Integrate ERM into real decisions and report it forward with indicators, so it changes what the organization does.

References

السادس

الخلاصات والمراجع

إدارة مخاطر المؤسسة تدير عدم اليقين عبر المنشأة كلها كمحفظةٍ واحدة، فيُؤخَذ الخطر عن قصدٍ خدمةً للأهداف.

  • ارفع الخطر من الصوامع للمؤسسة لتُقارَن المخاطر وتُرى تفاعلاتها ويُوجَّه الجهد للأهمّ.
  • ادمج الخطر في الاستراتيجية من البداية، لأن أكبر المخاطر عادةً استراتيجية.
  • حدّد شهية مخاطرٍ واضحة، مميَّزة بنوع الخطر، كمرجعٍ لكل قرار.
  • طبّق عملية تحديدٍ وتقييمٍ واستجابةٍ ومراقبةٍ واحدة متّسقة، واجمع لكشف التفاعلات الخفية.
  • ادمج ERM في القرارات الحقيقية وبلّغ عنها استشرافيًا بمؤشرات، فتغيّر ما تفعله المنشأة.

المراجع