Saif Ali AlghamdiTransformation & Growth Advisor
تواصل
Business Fields and Theoriesحقول الأعمال ونظرياتهاRisk Management & Insuranceإدارة المخاطر والتأمين
RISK MANAGEMENT & INSURANCE · PhDإدارة المخاطر والتأمين · دكتوراه

Enterprise Risk Management (ERM)إدارة المخاطر المؤسسية ERM

SectionالقسمRisk Management & Insuranceإدارة المخاطر والتأمين
Reading timeزمن القراءة9 min٩ دقيقة
ByإعدادSaif Alghamdiسيف الغامدي
One

Overview

Theory: Enterprise risk management, a framework rather than a theory
Primary field: Risk Management & Insurance
Core question: What changes when a firm manages its risks as one portfolio instead of function by function?
By: Saif Alghamdi

ERM is a framework, not a theory, and the distinction matters for anyone planning to build research on it. It makes no falsifiable prediction about behaviour. It prescribes an organizational arrangement and asserts that firms adopting it will be better off. Treating a prescription as a theory is the single most common error in the literature that cites it.

The claim behind the prescription is coherent and worth taking seriously. Risks managed inside separate functions are managed without knowledge of each other. Two departments hedge the same exposure twice. A natural offset between currency risk in procurement and currency revenue in sales goes unused because no one sees both. Aggregate exposure to a single driver is never computed because no one owns the aggregate. Silo management is not merely uncoordinated; it is systematically wrong about the size of the firm's total risk.

What ERM adds in practice is a small number of concrete artefacts: a common risk taxonomy and measurement basis, a statement of how much risk the board is willing to accept, an executive who owns the aggregate view, and a reporting line that carries risk information to the board independent of the businesses that generate it. Whether those artefacts change anything is an empirical question, and the empirical answer is genuinely unsettled.

الأول

نظرة عامة

النظرية: إدارة المخاطر المؤسسية، وهي إطارٌ لا نظرية
الحقل الأساسي: إدارة المخاطر والتأمين
السؤال الجوهري: ما الذي يتغيّر حين تدير المنشأة مخاطرها محفظةً واحدة بدل إدارتها وظيفةً وظيفة؟
إعداد: سيف الغامدي

إدارةُ المخاطر المؤسسية إطارٌ لا نظرية، والفرقُ مهمٌّ لمن ينوي بناء بحثٍ عليها. فهي لا تقدّم تنبّؤًا قابلًا للتكذيب في السلوك. بل تصف ترتيبًا تنظيميًّا وتزعم أن المنشآت التي تتبنّاه تكون أحسن حالًا. ومعاملةُ الوصفة معاملةَ النظرية أشيعُ خطأٍ مفرد في الأدبيات التي تستشهد بها.

والدعوى وراء الوصفة متماسكة وجديرةٌ بأخذها مأخذ الجدّ. فالمخاطرُ المدارة داخل وظائف منفصلة تُدار بلا علمٍ بعضها ببعض. فتتحوّط إدارتان من التعرّض نفسه مرّتين. ويضيع تقاصٌّ طبيعي بين مخاطرة العملة في الشراء وإيراد العملة في البيع لأن أحدًا لا يرى الطرفين. ولا يُحسَب التعرّض الكلّي لمحرّكٍ واحد قطّ لأن أحدًا لا يملك الكلّي. فإدارةُ الصوامع ليست غير منسّقة فحسب، بل مخطئةٌ منهجيًّا في حجم مخاطرة المنشأة الإجمالية.

وما تضيفه إدارةُ المخاطر المؤسسية عمليًّا عددٌ قليل من الآثار المحسوسة: تصنيفٌ مشترك للمخاطر وأساسٌ مشترك لقياسها، وبيانٌ بمقدار المخاطرة التي يقبلها المجلس، وتنفيذيٌّ يملك النظرة الكلّية، وخطُّ إبلاغٍ يحمل معلومة المخاطر إلى المجلس مستقلًّا عن الأعمال التي تولّدها. وهل تغيّر هذه الآثار شيئًا سؤالٌ تجريبي، والجوابُ التجريبي غير محسومٍ حقًّا.

Two

Where It Came From

The insurance purchasing function, before the 1990s. Corporate risk management began as the administration of insurance contracts and loss prevention, reporting to treasury or to operations. Its concern was hazard risk, its instrument was a policy, and its scope was whatever an insurer would write. ERM is best understood as the attempt to escape that scope.

The mid 1990s losses. Orange County in 1994 and Barings in 1995 were failures of aggregation rather than of any single control: exposures existed that nobody at the top had seen assembled. The chief risk officer role appears in this period, first in energy and financial firms, precisely as an owner for the aggregate that had been missing.

COSO, 2004. The Enterprise Risk Management Integrated Framework, built by extending the internal control framework the same body had issued in 1992. Eight components, four objective categories, presented as a cube. It gave the field a common vocabulary and, less usefully, gave auditors a checklist.

ISO 31000, 2009 and 2018. A generic standard with principles, a framework and a process, deliberately written to apply to any organization and deliberately not certifiable. The 2018 revision simplified it and put the governing body's accountability at the centre. It is less prescriptive than COSO and correspondingly less auditable.

Power, 2009. The most serious critique, published while the crisis was still unfolding. Firms with fully documented risk frameworks had just failed. Power argued that ERM had become an auditable process detached from the risks it named, that risk appetite statements were unfalsifiable, and that the framework had turned risk management into the management of the appearance of risk management.

COSO, 2017. The framework was rewritten as five components and twenty principles, the cube was dropped, and the emphasis moved to strategy selection and performance. The revision is partly a response to the criticism that the 2004 version encouraged compliance behaviour, though whether the rewrite changes practice is exactly the kind of question the literature has not answered.

الثاني

الأصل والنشأة

وظيفةُ شراء التأمين قبل التسعينيات. بدأت إدارة المخاطر في الشركات إدارةً لعقود التأمين ومنعًا للخسائر، تابعةً للخزينة أو للتشغيل. همُّها مخاطر الأخطار، وأداتُها وثيقة، ومداها ما يقبل المؤمِّن كتابته. وأحسنُ فهمٍ لإدارة المخاطر المؤسسية أنها محاولةٌ للخروج من ذلك المدى.

خسائر منتصف التسعينيات. كانت أورانج كاونتي في ١٩٩٤ وبارينغز في ١٩٩٥ إخفاقين في التجميع لا في ضابطٍ مفرد: فقد وُجدت تعرّضاتٌ لم يرها أحدٌ في القمّة مجموعة. وفي هذه الحقبة يظهر منصبُ رئيس إدارة المخاطر، في شركات الطاقة والمال أولًا، مالكًا للكلّي الذي كان غائبًا.

كوزو، ٢٠٠٤. إطارُ إدارة المخاطر المؤسسية المتكامل، مبنيًّا بتوسيع إطار الرقابة الداخلية الذي أصدرته الجهةُ نفسها في ١٩٩٢. ثمانيةُ مكوّنات، وأربع فئات أهداف، معروضةً في مكعّب. أعطى الحقلَ مفرداتٍ مشتركة، وأعطى المراجعين، وهذا أقلُّ نفعًا، قائمةَ تدقيق.

الأيزو ٣١٠٠٠، ٢٠٠٩ و٢٠١٨. معيارٌ عامّ فيه مبادئ وإطار وعملية، كُتب قصدًا ليصلح لأيّ منظمة، وقصدًا ليكون غير قابلٍ للاعتماد. وبسّطته مراجعةُ ٢٠١٨ وجعلت مساءلة مجلس الإدارة في المركز. وهو أقلّ إلزامًا من كوزو وأقلّ قابليةً للمراجعة تبعًا لذلك.

باور، ٢٠٠٩. أخطرُ النقد، نُشر والأزمة ما تزال تتكشّف. فمنشآتٌ لديها أطر مخاطر موثَّقة توثيقًا كاملًا كانت قد أخفقت لتوّها. ورأى باور أن إدارة المخاطر المؤسسية صارت عمليةً قابلة للمراجعة منفصلةً عن المخاطر التي تسمّيها، وأن بيانات الرغبة في تحمّل المخاطر غير قابلة للتكذيب، وأن الإطار حوّل إدارة المخاطر إلى إدارةٍ لمظهر إدارة المخاطر.

كوزو، ٢٠١٧. أُعيدت كتابةُ الإطار في خمسة مكوّنات وعشرين مبدأً، وأُسقط المكعّب، وانتقل التشديد إلى اختيار الاستراتيجية والأداء. والمراجعةُ جوابٌ جزئي عن النقد القائل إن نسخة ٢٠٠٤ شجّعت سلوك الامتثال، وإن كان هل غيّرت إعادةُ الكتابة الممارسةَ هو بالضبط نوعَ السؤال الذي لم تجب عنه الأدبيات.

Three

How It Works

The portfolio claim is the substance. Under silo management each function optimises its own exposure, and total risk is the sum of the parts by default. Under a portfolio view the correlations between exposures enter the calculation, so the firm can hold more of an uncorrelated risk and less of one that compounds an existing concentration. This is the same logic that governs an investment portfolio, applied to hazard, financial, operational and strategic exposures at once.

The three quantities that get confused. Most risk appetite documents fail because they collapse three different things into one sentence.

QuantityWhat it isWho sets itExpressed as
Risk capacityThe maximum loss the firm can absorb before it breaches a solvency, liquidity or covenant constraintDetermined by the balance sheet, not chosenAn amount of capital or liquidity
Risk appetiteThe amount and type of risk the board chooses to accept in pursuit of the strategy, necessarily well inside capacityThe boardA small set of aggregate limits with a stated basis
Risk toleranceThe acceptable variation around a specific objective or metricManagement, within appetiteA range around a target, per objective

The three lines model organises who does what. The first line owns and manages risk inside the business that creates it. The second line, the risk and compliance functions, sets the methods, monitors and challenges. The third line, internal audit, provides independent assurance directly to the governing body. The 2020 revision of the model dropped the word defence and reframed the lines as roles, partly because the original phrasing encouraged each line to treat risk as somebody else's responsibility.

The value of ERM depends entirely on correlations, and correlations are exactly what nobody can measure across risk types. If a firm's risks are independent, the portfolio view adds nothing that simple addition does not already provide. If they are correlated, the aggregation requires a joint distribution across hazard, credit, operational and strategic exposures, and no framework supplies one. COSO and ISO both stop at the point where the hard problem begins, which is why aggregation in practice is done by workshop scoring rather than by measurement.
الثالث

الآلية والبنية

دعوى المحفظة هي الجوهر. ففي إدارة الصوامع تُحسِّن كلُّ وظيفةٍ تعرّضها هي، وتكون المخاطرةُ الكلّية مجموعَ الأجزاء افتراضًا. وفي النظرة المحفظية تدخل الارتباطاتُ بين التعرّضات في الحساب، فتستطيع المنشأة أن تحمل أكثر من مخاطرةٍ غير مرتبطة وأقلّ من مخاطرةٍ تضاعف تركّزًا قائمًا. وهذا منطقُ محفظة الاستثمار نفسه، مطبَّقًا على تعرّضات الأخطار والمال والتشغيل والاستراتيجية في آنٍ واحد.

والكمّيات الثلاث التي يقع فيها الخلط. تُخفق أكثرُ وثائق الرغبة في تحمّل المخاطر لأنها تطوي ثلاثة أشياء مختلفة في جملةٍ واحدة.

الكمّيةما هيمَن يحدّدهاكيف تُعبَّر
الطاقة الاستيعابية للمخاطرأقصى خسارةٍ تستطيع المنشأة امتصاصها قبل أن تخرق قيدَ ملاءةٍ أو سيولةٍ أو تعهّديحدّدها المركز المالي ولا تُختارمبلغُ رأس مالٍ أو سيولة
الرغبة في تحمّل المخاطرقدرُ المخاطرة ونوعُها اللذان يختار المجلس قبولهما سعيًا للاستراتيجية، وهي بالضرورة دون الطاقة بمسافةالمجلسمجموعةٌ صغيرة من الحدود الكلّية بأساسٍ معلَن
حدّ التحمّلالتباينُ المقبول حول هدفٍ أو مقياسٍ بعينهالإدارة، ضمن الرغبة المعتمَدةمدًى حول مستهدَف، لكلّ هدف

ونموذج الخطوط الثلاثة ينظّم مَن يفعل ماذا. فالخطّ الأول يملك المخاطرة ويديرها داخل العمل الذي يولّدها. والخطّ الثاني، وهو وظائف المخاطر والالتزام، يضع الطرائق ويراقب ويحاجّ. والخطّ الثالث، وهو المراجعة الداخلية، يقدّم تأكيدًا مستقلًّا إلى مجلس الإدارة مباشرة. وقد أسقطت مراجعةُ النموذج في ٢٠٢٠ كلمة الدفاع وأعادت صوغ الخطوط أدوارًا، لأن الصياغة الأولى شجّعت كلّ خطٍّ على عدّ المخاطرة مسؤوليةَ غيره.

قيمةُ هذا الإطار موقوفةٌ كلّها على الارتباطات، والارتباطاتُ هي بالضبط ما لا يستطيع أحدٌ قياسه عبر أنواع المخاطر. فإن كانت مخاطر المنشأة مستقلّة لم تضف النظرةُ المحفظية شيئًا لا يوفّره الجمع البسيط. وإن كانت مرتبطة اقتضى التجميعُ توزيعًا مشتركًا عبر تعرّضات الأخطار والائتمان والتشغيل والاستراتيجية، ولا إطار يوفّر مثله. فكوزو والأيزو كلاهما يقف عند النقطة التي تبدأ عندها المشكلة الصعبة، ولهذا يجري التجميعُ عمليًّا بتقديرات ورش العمل لا بالقياس.
Four

Using It in Research

The dominant empirical question is whether ERM adoption is associated with firm value, and the answer is mixed. The most cited affirmative result reports a value premium for insurers identified as ERM users, using an instrumented specification to address selection. Other studies on other samples find no association, a relation that disappears with controls, or an association only within particular industries or particular periods. Reviews of this literature consistently attribute the disagreement to measurement of adoption rather than to genuine heterogeneity in effect.

Why the measurement problem is fatal rather than annoying. Adoption is almost always proxied by one of three things: the appointment of a chief risk officer, a keyword search of annual reports and press releases, or a third party rating available for a subset of firms. A title measures a title. A keyword count measures reporting language, which a firm can change in an afternoon. A rating measures a rater's judgement about firms that chose to be rated. All three measure announcement, and none measures whether risks are actually aggregated and acted upon.

Endogeneity is severe and rarely resolved. Firms that adopt ERM are larger, more complex, more institutionally held and better governed in general. Any of those characteristics could drive both adoption and value. Reverse causality is equally plausible: a firm performing well can afford a risk function. Instruments proposed in this literature are weak, and matching on observables does not address selection on the unobservable that matters, which is management quality.

Report at least two adoption proxies and show the sensitivity. A value effect that appears under a keyword measure and vanishes under a rating, or vice versa, is a finding about the proxy and should be reported as one. The stronger design abandons the binary adoption variable altogether and uses a dated, externally imposed change in risk governance, so that the treatment is a rule and not a firm's own choice.

Angles the local setting makes distinctive.

  • A regulator-mandated risk committee is the design this literature has been missing. Where a supervisor requires a board risk committee from a stated date, with the requirement phased by institution size or sector, adoption is exogenous and dated. That converts the endogenous adoption problem into a difference in differences, and it is the strongest available answer to the selection critique.
  • Risk appetite when the state is owner, regulator and customer. A board cannot set appetite independently when the controlling shareholder is also the supervisor and the principal counterparty. Comparing appetite statements and realised exposures across ownership types in one market tests whether the framework's central artefact means anything where its assumed autonomy is absent.
  • An implicit sovereign backstop widens appetite. If the ultimate absorber of losses is not the firm, the rational appetite is wider than capacity alone would justify. This is a moral hazard prediction with an observable implication: leverage and concentration should vary with the credibility of the backstop, holding governance constant.
  • Takaful operators carry two risk appetites in one entity. The participants' fund and the shareholders' fund bear different losses under different rules, so a single enterprise appetite statement is not obviously coherent. How operators reconcile them is an unexamined governance question with a direct bearing on the framework's aggregation logic.
  • Climate and water exposure as an enterprise risk. Desalination dependence, extreme heat affecting outdoor labour productivity, and physical exposure of coastal industrial assets are correlated across otherwise unrelated business units. Whether local risk registers aggregate them or file them separately by unit is a direct test of whether the portfolio view is real.
الرابع

التوظيف البحثي

السؤال التجريبي الغالب هو هل يرتبط تبنّي إدارة المخاطر المؤسسية بقيمة المنشأة، والجواب مختلَط. فأكثرُ النتائج الموجبة استشهادًا تبلّغ علاوةَ قيمةٍ لشركات التأمين المصنَّفة مستعملةً للإطار، بمواصفةٍ ذات متغيّرٍ أداتيّ لمعالجة الانتقاء. ودراساتٌ أخرى على عيّناتٍ أخرى لا تجد ارتباطًا، أو تجد علاقةً تزول مع الضوابط، أو ارتباطًا في صناعاتٍ بعينها أو فتراتٍ بعينها. ومراجعاتُ هذه الأدبيات تردّ الخلاف باطّرادٍ إلى قياس التبنّي لا إلى تباينٍ حقيقي في الأثر.

ولماذا كانت مشكلةُ القياس قاتلةً لا مزعجة فحسب. فالتبنّي يُقاس غالبًا بواحدٍ من ثلاثة: تعيينُ رئيسٍ لإدارة المخاطر، أو بحثٌ بالكلمات المفتاحية في التقارير السنوية والبيانات الصحفية، أو تصنيفٌ من طرفٍ ثالث متاح لطائفةٍ من المنشآت. فالمنصبُ يقيس منصبًا. وعدُّ الكلمات يقيس لغةَ الإبلاغ، وهي ممّا تستطيع المنشأة تغييره في عصرٍ واحد. والتصنيفُ يقيس حكمَ مصنِّفٍ على منشآت اختارت أن تُصنَّف. وثلاثتُها تقيس الإعلان، ولا واحد منها يقيس هل جُمعت المخاطر فعلًا وعُمل بها.

والداخلية شديدة وقلّما تُحلّ. فالمنشآت المتبنّية أكبرُ حجمًا وأعقدُ بنيةً وأكثرُ ملكيةً مؤسسية وأحسنُ حوكمةً عمومًا. وأيٌّ من هذه الخصائص قد يقود التبنّي والقيمة معًا. والسببيةُ العكسية معقولةٌ بالقدر نفسه: فالمنشأة الجيّدة الأداء تقدر على وظيفة مخاطر. والأدواتُ المقترحة في هذه الأدبيات ضعيفة، والمطابقةُ على الملاحَظات لا تعالج الانتقاء على غير الملاحَظ ذي الشأن، وهو جودةُ الإدارة.

أبلغ بديلين للتبنّي على الأقلّ وأظهِر الحساسية. فأثرُ قيمةٍ يظهر بمقياس الكلمات ويختفي بالتصنيف، أو العكس، نتيجةٌ عن البديل وينبغي إبلاغُها كذلك. والتصميمُ الأقوى يهجر متغيّر التبنّي الثنائي بالكلّية ويستعمل تغيّرًا مؤرَّخًا مفروضًا من خارج في حوكمة المخاطر، فتكون المعالجةُ قاعدةً لا اختيارًا من المنشأة نفسها.

زوايا يجعلها السياق المحلّي متميّزة.

  • لجنةُ المخاطر الملزَمة نظامًا هي التصميم الذي افتقدته هذه الأدبيات. فحيث يوجب المشرف لجنةَ مخاطر منبثقة عن المجلس من تاريخٍ معلَن، بتدرّجٍ بحسب حجم المؤسسة أو قطاعها، يكون التبنّي خارجيًّا ومؤرَّخًا. وهذا يحوّل مشكلة التبنّي الداخلي إلى فروقٍ في الفروق، وهو أقوى جوابٍ متاح عن نقد الانتقاء.
  • الرغبة في تحمّل المخاطر حين تكون الدولة مالكًا ومنظِّمًا وعميلًا. فلا يستطيع مجلسٌ تحديد رغبته استقلالًا حين يكون المساهم المسيطر هو المشرف والطرف المقابل الرئيس كذلك. ومقارنةُ بيانات الرغبة والتعرّضات المتحقّقة بين أنماط الملكية في سوقٍ واحدة تختبر هل يعني الأثرُ المركزي في الإطار شيئًا حيث ينعدم الاستقلال الذي يفترضه.
  • السندُ السياديّ الضمني يوسّع الرغبة. فإذا لم تكن المنشأة هي الممتصَّ الأخير للخسائر كانت الرغبةُ الرشيدة أوسع ممّا تبرّره الطاقة وحدها. وهذا تنبّؤُ خطرٍ أخلاقي له لازمٌ قابل للملاحظة: فينبغي أن يتغيّر الرفعُ المالي والتركّز بمصداقية السند، مع تثبيت الحوكمة.
  • مشغّلو التكافل يحملون رغبتين في كيانٍ واحد. فصندوق المشتركين وصندوق المساهمين يتحمّلان خسائر مختلفة بقواعدَ مختلفة، فليس بيانُ رغبةٍ مؤسسي واحد متماسكًا على وجه ظاهر. وكيف يوفّق المشغّلون بينهما سؤالُ حوكمةٍ لم يُدرَس، وله مساسٌ مباشر بمنطق التجميع في الإطار.
  • التعرّض للمناخ والمياه مخاطرةً مؤسسية. فالاعتماد على التحلية، والحرارةُ الشديدة وأثرُها في إنتاجية العمل في الخارج، والتعرّضُ المادّي للأصول الصناعية الساحلية، أمورٌ مترابطة عبر وحدات أعمالٍ لا صلة بينها في غير ذلك. وهل تجمعها سجلّاتُ المخاطر المحلّية أم تودعها منفصلةً بحسب الوحدة اختبارٌ مباشر لهل النظرة المحفظية حقيقية.
Five

Limits and Critique

It is a framework and it behaves like one. There is no state of the world in which COSO or ISO 31000 is shown to be false. A firm that fails can always be described as having implemented the framework poorly, which makes the framework itself unfalsifiable and shifts every empirical claim onto the quality of implementation, which is unmeasured.

Adoption is measured by announcement, not by practice. The existence of a chief risk officer, a keyword count or a rating are the standard proxies, and each of them can be satisfied without a single risk being aggregated differently. Two firms coded identically as adopters can run entirely different risk functions, and two firms coded differently can run the same one. A binary variable built this way cannot carry a value hypothesis.

Endogeneity is not a caveat here, it is the main event. Size, complexity, institutional ownership, board quality and prior performance all predict adoption and all predict value. Weak instruments and observable matching do not solve selection on management quality. Most published value effects are consistent with adoption being a symptom of a well-run firm rather than a cause of one.

One size does not fit all, and the binary variable hides this. Field research has documented that risk functions occupy distinct roles across firms, from compliance record keeping to independent challenge of business plans, and that these roles are not stages on a single maturity path. Pooling them into one adoption dummy averages across practices that have opposite effects.

The aggregation the framework promises is not actually performed. Operational, strategic and reputational risks have no common metric with market and credit risk, so enterprise-level aggregation in practice reduces to scoring exercises on a heat map. The portfolio claim, which is the entire intellectual justification for the framework, is the part least implemented.

Documentation can substitute for judgement. Power's charge, made when institutions with exemplary frameworks were failing, was that ERM produces auditable evidence of process rather than better decisions, and that the demand for evidence actively crowds out the uncomfortable conversations that risk governance is supposed to force.

Do not build a study on a binary ERM adoption variable. Build it on a dated external mandate, a governance change with a known effective date, or an observable behaviour such as a hedging decision, a limit breach or an actual reallocation of capital across risks. Say in the paper that ERM is a framework and not a theory, and state which specific mechanism, aggregation, appetite setting or independent challenge, the design is testing. In a market where risk committees are mandated by rule and phased by size, the exogenous variation this literature has lacked for two decades is available, and using it well would be a larger contribution than another value regression.
  • COSO, Enterprise Risk Management: Integrating with Strategy and Performance, Committee of Sponsoring Organizations of the Treadway Commission, 2017.
  • ISO 31000, Risk Management: Guidelines, International Organization for Standardization, 2018.
  • Hoyt and Liebenberg, The Value of Enterprise Risk Management, Journal of Risk and Insurance, 2011.
  • Power, The Risk Management of Nothing, Accounting, Organizations and Society, 2009.
  • Mikes and Kaplan, When One Size Doesn't Fit All: Evolving Directions in the Research and Practice of Enterprise Risk Management, Journal of Applied Corporate Finance, 2015.
الخامس

الحدود والنقد

هو إطارٌ ويسلك سلوك الأطر. فليس ثمّة حالُ عالمٍ يظهر فيها كوزو أو الأيزو ٣١٠٠٠ باطلًا. فالمنشأة التي تخفق يمكن دائمًا وصفُها بأنها طبّقت الإطار تطبيقًا رديئًا، وهذا يجعل الإطار نفسه غير قابل للتكذيب ويحيل كلَّ دعوى تجريبية إلى جودة التطبيق، وهي غير مقيسة.

والتبنّي يُقاس بالإعلان لا بالممارسة. فوجودُ رئيسٍ لإدارة المخاطر، أو عدُّ كلمات، أو تصنيف، هي البدائل المعيارية، وكلٌّ منها يتحقّق من غير أن تُجمَع مخاطرةٌ واحدة على نحوٍ مختلف. ومنشأتان تُرمَّزان متبنّيتين بالسويّة قد تشغّلان وظيفتَي مخاطر مختلفتين تمامًا، ومنشأتان تُرمَّزان مختلفتين قد تشغّلان الوظيفة نفسها. ومتغيّرٌ ثنائي مبنيٌّ هكذا لا يحمل فرضيةَ قيمة.

والداخلية هنا ليست تحفّظًا بل هي الحدث الرئيس. فالحجمُ والتعقيد والملكية المؤسسية وجودةُ المجلس والأداءُ السابق كلُّها تتنبّأ بالتبنّي وكلُّها تتنبّأ بالقيمة. والأدواتُ الضعيفة والمطابقةُ على الملاحَظات لا تحلّان الانتقاء على جودة الإدارة. وأكثرُ آثار القيمة المنشورة متّسقٌ مع كون التبنّي عرضًا لمنشأةٍ حسنة الإدارة لا سببًا لها.

والمقاس الواحد لا يناسب الجميع، والمتغيّر الثنائي يخفي هذا. فقد وثّقت البحوث الميدانية أن وظائف المخاطر تشغل أدوارًا متمايزة بين المنشآت، من حفظ سجلّات الالتزام إلى المحاجّة المستقلّة لخطط الأعمال، وأن هذه الأدوار ليست مراحلَ على مسار نضجٍ واحد. وجمعُها في متغيّر تبنٍّ واحد يأخذ متوسّطًا لممارساتٍ آثارُها متعاكسة.

والتجميع الذي يعد به الإطار لا يُنفَّذ فعلًا. فمخاطرُ التشغيل والاستراتيجية والسمعة لا مقياس مشترك لها مع مخاطر السوق والائتمان، فينحلّ التجميعُ على مستوى المؤسسة عمليًّا إلى تمارين تقديرٍ على خريطةٍ حرارية. فدعوى المحفظة، وهي كلُّ المبرّر الفكري للإطار، هي أقلُّ أجزائه تنفيذًا.

والتوثيق قد ينوب عن الحُكم. فتهمةُ باور، وقد قالها حين كانت مؤسساتٌ ذات أطر نموذجية تخفق، أن هذا الإطار ينتج دليلًا قابلًا للمراجعة على وجود عملية لا قراراتٍ أفضل، وأن الطلب على الدليل يزاحم فعليًّا المحادثاتِ المزعجة التي يُفترَض بحوكمة المخاطر أن تفرضها.

لا تبنِ دراسةً على متغيّر تبنٍّ ثنائي لإدارة المخاطر المؤسسية. ابنِها على إلزامٍ خارجي مؤرَّخ، أو تغيّرِ حوكمةٍ معلوم تاريخ النفاذ، أو سلوكٍ ملاحَظ كقرار تحوّط أو خرقِ حدٍّ أو إعادةِ تخصيصٍ فعلية لرأس المال بين المخاطر. وقُل في البحث إن هذا إطارٌ لا نظرية، وسمِّ الآليةَ التي يختبرها التصميم بعينها: التجميع، أو تحديد الرغبة، أو المحاجّة المستقلّة. وفي سوقٍ تُلزَم فيها لجانُ المخاطر بقاعدةٍ متدرّجة بالحجم، يتوافر التباينُ الخارجي الذي افتقدته هذه الأدبيات عقدين، وحسنُ استعماله إسهامٌ أكبر من انحدار قيمةٍ آخر.
  • COSO, Enterprise Risk Management: Integrating with Strategy and Performance, Committee of Sponsoring Organizations of the Treadway Commission, 2017.
  • ISO 31000, Risk Management: Guidelines, International Organization for Standardization, 2018.
  • Hoyt and Liebenberg, The Value of Enterprise Risk Management, Journal of Risk and Insurance, 2011.
  • Power, The Risk Management of Nothing, Accounting, Organizations and Society, 2009.
  • Mikes and Kaplan, When One Size Doesn't Fit All: Evolving Directions in the Research and Practice of Enterprise Risk Management, Journal of Applied Corporate Finance, 2015.