ERM is a framework, not a theory, and the distinction matters for anyone planning to build research on it. It makes no falsifiable prediction about behaviour. It prescribes an organizational arrangement and asserts that firms adopting it will be better off. Treating a prescription as a theory is the single most common error in the literature that cites it.
The claim behind the prescription is coherent and worth taking seriously. Risks managed inside separate functions are managed without knowledge of each other. Two departments hedge the same exposure twice. A natural offset between currency risk in procurement and currency revenue in sales goes unused because no one sees both. Aggregate exposure to a single driver is never computed because no one owns the aggregate. Silo management is not merely uncoordinated; it is systematically wrong about the size of the firm's total risk.
What ERM adds in practice is a small number of concrete artefacts: a common risk taxonomy and measurement basis, a statement of how much risk the board is willing to accept, an executive who owns the aggregate view, and a reporting line that carries risk information to the board independent of the businesses that generate it. Whether those artefacts change anything is an empirical question, and the empirical answer is genuinely unsettled.
إدارةُ المخاطر المؤسسية إطارٌ لا نظرية، والفرقُ مهمٌّ لمن ينوي بناء بحثٍ عليها. فهي لا تقدّم تنبّؤًا قابلًا للتكذيب في السلوك. بل تصف ترتيبًا تنظيميًّا وتزعم أن المنشآت التي تتبنّاه تكون أحسن حالًا. ومعاملةُ الوصفة معاملةَ النظرية أشيعُ خطأٍ مفرد في الأدبيات التي تستشهد بها.
والدعوى وراء الوصفة متماسكة وجديرةٌ بأخذها مأخذ الجدّ. فالمخاطرُ المدارة داخل وظائف منفصلة تُدار بلا علمٍ بعضها ببعض. فتتحوّط إدارتان من التعرّض نفسه مرّتين. ويضيع تقاصٌّ طبيعي بين مخاطرة العملة في الشراء وإيراد العملة في البيع لأن أحدًا لا يرى الطرفين. ولا يُحسَب التعرّض الكلّي لمحرّكٍ واحد قطّ لأن أحدًا لا يملك الكلّي. فإدارةُ الصوامع ليست غير منسّقة فحسب، بل مخطئةٌ منهجيًّا في حجم مخاطرة المنشأة الإجمالية.
وما تضيفه إدارةُ المخاطر المؤسسية عمليًّا عددٌ قليل من الآثار المحسوسة: تصنيفٌ مشترك للمخاطر وأساسٌ مشترك لقياسها، وبيانٌ بمقدار المخاطرة التي يقبلها المجلس، وتنفيذيٌّ يملك النظرة الكلّية، وخطُّ إبلاغٍ يحمل معلومة المخاطر إلى المجلس مستقلًّا عن الأعمال التي تولّدها. وهل تغيّر هذه الآثار شيئًا سؤالٌ تجريبي، والجوابُ التجريبي غير محسومٍ حقًّا.
The insurance purchasing function, before the 1990s. Corporate risk management began as the administration of insurance contracts and loss prevention, reporting to treasury or to operations. Its concern was hazard risk, its instrument was a policy, and its scope was whatever an insurer would write. ERM is best understood as the attempt to escape that scope.
The mid 1990s losses. Orange County in 1994 and Barings in 1995 were failures of aggregation rather than of any single control: exposures existed that nobody at the top had seen assembled. The chief risk officer role appears in this period, first in energy and financial firms, precisely as an owner for the aggregate that had been missing.
COSO, 2004. The Enterprise Risk Management Integrated Framework, built by extending the internal control framework the same body had issued in 1992. Eight components, four objective categories, presented as a cube. It gave the field a common vocabulary and, less usefully, gave auditors a checklist.
ISO 31000, 2009 and 2018. A generic standard with principles, a framework and a process, deliberately written to apply to any organization and deliberately not certifiable. The 2018 revision simplified it and put the governing body's accountability at the centre. It is less prescriptive than COSO and correspondingly less auditable.
Power, 2009. The most serious critique, published while the crisis was still unfolding. Firms with fully documented risk frameworks had just failed. Power argued that ERM had become an auditable process detached from the risks it named, that risk appetite statements were unfalsifiable, and that the framework had turned risk management into the management of the appearance of risk management.
COSO, 2017. The framework was rewritten as five components and twenty principles, the cube was dropped, and the emphasis moved to strategy selection and performance. The revision is partly a response to the criticism that the 2004 version encouraged compliance behaviour, though whether the rewrite changes practice is exactly the kind of question the literature has not answered.
وظيفةُ شراء التأمين قبل التسعينيات. بدأت إدارة المخاطر في الشركات إدارةً لعقود التأمين ومنعًا للخسائر، تابعةً للخزينة أو للتشغيل. همُّها مخاطر الأخطار، وأداتُها وثيقة، ومداها ما يقبل المؤمِّن كتابته. وأحسنُ فهمٍ لإدارة المخاطر المؤسسية أنها محاولةٌ للخروج من ذلك المدى.
خسائر منتصف التسعينيات. كانت أورانج كاونتي في ١٩٩٤ وبارينغز في ١٩٩٥ إخفاقين في التجميع لا في ضابطٍ مفرد: فقد وُجدت تعرّضاتٌ لم يرها أحدٌ في القمّة مجموعة. وفي هذه الحقبة يظهر منصبُ رئيس إدارة المخاطر، في شركات الطاقة والمال أولًا، مالكًا للكلّي الذي كان غائبًا.
كوزو، ٢٠٠٤. إطارُ إدارة المخاطر المؤسسية المتكامل، مبنيًّا بتوسيع إطار الرقابة الداخلية الذي أصدرته الجهةُ نفسها في ١٩٩٢. ثمانيةُ مكوّنات، وأربع فئات أهداف، معروضةً في مكعّب. أعطى الحقلَ مفرداتٍ مشتركة، وأعطى المراجعين، وهذا أقلُّ نفعًا، قائمةَ تدقيق.
الأيزو ٣١٠٠٠، ٢٠٠٩ و٢٠١٨. معيارٌ عامّ فيه مبادئ وإطار وعملية، كُتب قصدًا ليصلح لأيّ منظمة، وقصدًا ليكون غير قابلٍ للاعتماد. وبسّطته مراجعةُ ٢٠١٨ وجعلت مساءلة مجلس الإدارة في المركز. وهو أقلّ إلزامًا من كوزو وأقلّ قابليةً للمراجعة تبعًا لذلك.
باور، ٢٠٠٩. أخطرُ النقد، نُشر والأزمة ما تزال تتكشّف. فمنشآتٌ لديها أطر مخاطر موثَّقة توثيقًا كاملًا كانت قد أخفقت لتوّها. ورأى باور أن إدارة المخاطر المؤسسية صارت عمليةً قابلة للمراجعة منفصلةً عن المخاطر التي تسمّيها، وأن بيانات الرغبة في تحمّل المخاطر غير قابلة للتكذيب، وأن الإطار حوّل إدارة المخاطر إلى إدارةٍ لمظهر إدارة المخاطر.
كوزو، ٢٠١٧. أُعيدت كتابةُ الإطار في خمسة مكوّنات وعشرين مبدأً، وأُسقط المكعّب، وانتقل التشديد إلى اختيار الاستراتيجية والأداء. والمراجعةُ جوابٌ جزئي عن النقد القائل إن نسخة ٢٠٠٤ شجّعت سلوك الامتثال، وإن كان هل غيّرت إعادةُ الكتابة الممارسةَ هو بالضبط نوعَ السؤال الذي لم تجب عنه الأدبيات.
The portfolio claim is the substance. Under silo management each function optimises its own exposure, and total risk is the sum of the parts by default. Under a portfolio view the correlations between exposures enter the calculation, so the firm can hold more of an uncorrelated risk and less of one that compounds an existing concentration. This is the same logic that governs an investment portfolio, applied to hazard, financial, operational and strategic exposures at once.
The three quantities that get confused. Most risk appetite documents fail because they collapse three different things into one sentence.
| Quantity | What it is | Who sets it | Expressed as |
|---|---|---|---|
| Risk capacity | The maximum loss the firm can absorb before it breaches a solvency, liquidity or covenant constraint | Determined by the balance sheet, not chosen | An amount of capital or liquidity |
| Risk appetite | The amount and type of risk the board chooses to accept in pursuit of the strategy, necessarily well inside capacity | The board | A small set of aggregate limits with a stated basis |
| Risk tolerance | The acceptable variation around a specific objective or metric | Management, within appetite | A range around a target, per objective |
The three lines model organises who does what. The first line owns and manages risk inside the business that creates it. The second line, the risk and compliance functions, sets the methods, monitors and challenges. The third line, internal audit, provides independent assurance directly to the governing body. The 2020 revision of the model dropped the word defence and reframed the lines as roles, partly because the original phrasing encouraged each line to treat risk as somebody else's responsibility.
دعوى المحفظة هي الجوهر. ففي إدارة الصوامع تُحسِّن كلُّ وظيفةٍ تعرّضها هي، وتكون المخاطرةُ الكلّية مجموعَ الأجزاء افتراضًا. وفي النظرة المحفظية تدخل الارتباطاتُ بين التعرّضات في الحساب، فتستطيع المنشأة أن تحمل أكثر من مخاطرةٍ غير مرتبطة وأقلّ من مخاطرةٍ تضاعف تركّزًا قائمًا. وهذا منطقُ محفظة الاستثمار نفسه، مطبَّقًا على تعرّضات الأخطار والمال والتشغيل والاستراتيجية في آنٍ واحد.
والكمّيات الثلاث التي يقع فيها الخلط. تُخفق أكثرُ وثائق الرغبة في تحمّل المخاطر لأنها تطوي ثلاثة أشياء مختلفة في جملةٍ واحدة.
| الكمّية | ما هي | مَن يحدّدها | كيف تُعبَّر |
|---|---|---|---|
| الطاقة الاستيعابية للمخاطر | أقصى خسارةٍ تستطيع المنشأة امتصاصها قبل أن تخرق قيدَ ملاءةٍ أو سيولةٍ أو تعهّد | يحدّدها المركز المالي ولا تُختار | مبلغُ رأس مالٍ أو سيولة |
| الرغبة في تحمّل المخاطر | قدرُ المخاطرة ونوعُها اللذان يختار المجلس قبولهما سعيًا للاستراتيجية، وهي بالضرورة دون الطاقة بمسافة | المجلس | مجموعةٌ صغيرة من الحدود الكلّية بأساسٍ معلَن |
| حدّ التحمّل | التباينُ المقبول حول هدفٍ أو مقياسٍ بعينه | الإدارة، ضمن الرغبة المعتمَدة | مدًى حول مستهدَف، لكلّ هدف |
ونموذج الخطوط الثلاثة ينظّم مَن يفعل ماذا. فالخطّ الأول يملك المخاطرة ويديرها داخل العمل الذي يولّدها. والخطّ الثاني، وهو وظائف المخاطر والالتزام، يضع الطرائق ويراقب ويحاجّ. والخطّ الثالث، وهو المراجعة الداخلية، يقدّم تأكيدًا مستقلًّا إلى مجلس الإدارة مباشرة. وقد أسقطت مراجعةُ النموذج في ٢٠٢٠ كلمة الدفاع وأعادت صوغ الخطوط أدوارًا، لأن الصياغة الأولى شجّعت كلّ خطٍّ على عدّ المخاطرة مسؤوليةَ غيره.
The dominant empirical question is whether ERM adoption is associated with firm value, and the answer is mixed. The most cited affirmative result reports a value premium for insurers identified as ERM users, using an instrumented specification to address selection. Other studies on other samples find no association, a relation that disappears with controls, or an association only within particular industries or particular periods. Reviews of this literature consistently attribute the disagreement to measurement of adoption rather than to genuine heterogeneity in effect.
Why the measurement problem is fatal rather than annoying. Adoption is almost always proxied by one of three things: the appointment of a chief risk officer, a keyword search of annual reports and press releases, or a third party rating available for a subset of firms. A title measures a title. A keyword count measures reporting language, which a firm can change in an afternoon. A rating measures a rater's judgement about firms that chose to be rated. All three measure announcement, and none measures whether risks are actually aggregated and acted upon.
Endogeneity is severe and rarely resolved. Firms that adopt ERM are larger, more complex, more institutionally held and better governed in general. Any of those characteristics could drive both adoption and value. Reverse causality is equally plausible: a firm performing well can afford a risk function. Instruments proposed in this literature are weak, and matching on observables does not address selection on the unobservable that matters, which is management quality.
Angles the local setting makes distinctive.
السؤال التجريبي الغالب هو هل يرتبط تبنّي إدارة المخاطر المؤسسية بقيمة المنشأة، والجواب مختلَط. فأكثرُ النتائج الموجبة استشهادًا تبلّغ علاوةَ قيمةٍ لشركات التأمين المصنَّفة مستعملةً للإطار، بمواصفةٍ ذات متغيّرٍ أداتيّ لمعالجة الانتقاء. ودراساتٌ أخرى على عيّناتٍ أخرى لا تجد ارتباطًا، أو تجد علاقةً تزول مع الضوابط، أو ارتباطًا في صناعاتٍ بعينها أو فتراتٍ بعينها. ومراجعاتُ هذه الأدبيات تردّ الخلاف باطّرادٍ إلى قياس التبنّي لا إلى تباينٍ حقيقي في الأثر.
ولماذا كانت مشكلةُ القياس قاتلةً لا مزعجة فحسب. فالتبنّي يُقاس غالبًا بواحدٍ من ثلاثة: تعيينُ رئيسٍ لإدارة المخاطر، أو بحثٌ بالكلمات المفتاحية في التقارير السنوية والبيانات الصحفية، أو تصنيفٌ من طرفٍ ثالث متاح لطائفةٍ من المنشآت. فالمنصبُ يقيس منصبًا. وعدُّ الكلمات يقيس لغةَ الإبلاغ، وهي ممّا تستطيع المنشأة تغييره في عصرٍ واحد. والتصنيفُ يقيس حكمَ مصنِّفٍ على منشآت اختارت أن تُصنَّف. وثلاثتُها تقيس الإعلان، ولا واحد منها يقيس هل جُمعت المخاطر فعلًا وعُمل بها.
والداخلية شديدة وقلّما تُحلّ. فالمنشآت المتبنّية أكبرُ حجمًا وأعقدُ بنيةً وأكثرُ ملكيةً مؤسسية وأحسنُ حوكمةً عمومًا. وأيٌّ من هذه الخصائص قد يقود التبنّي والقيمة معًا. والسببيةُ العكسية معقولةٌ بالقدر نفسه: فالمنشأة الجيّدة الأداء تقدر على وظيفة مخاطر. والأدواتُ المقترحة في هذه الأدبيات ضعيفة، والمطابقةُ على الملاحَظات لا تعالج الانتقاء على غير الملاحَظ ذي الشأن، وهو جودةُ الإدارة.
زوايا يجعلها السياق المحلّي متميّزة.
It is a framework and it behaves like one. There is no state of the world in which COSO or ISO 31000 is shown to be false. A firm that fails can always be described as having implemented the framework poorly, which makes the framework itself unfalsifiable and shifts every empirical claim onto the quality of implementation, which is unmeasured.
Adoption is measured by announcement, not by practice. The existence of a chief risk officer, a keyword count or a rating are the standard proxies, and each of them can be satisfied without a single risk being aggregated differently. Two firms coded identically as adopters can run entirely different risk functions, and two firms coded differently can run the same one. A binary variable built this way cannot carry a value hypothesis.
Endogeneity is not a caveat here, it is the main event. Size, complexity, institutional ownership, board quality and prior performance all predict adoption and all predict value. Weak instruments and observable matching do not solve selection on management quality. Most published value effects are consistent with adoption being a symptom of a well-run firm rather than a cause of one.
One size does not fit all, and the binary variable hides this. Field research has documented that risk functions occupy distinct roles across firms, from compliance record keeping to independent challenge of business plans, and that these roles are not stages on a single maturity path. Pooling them into one adoption dummy averages across practices that have opposite effects.
The aggregation the framework promises is not actually performed. Operational, strategic and reputational risks have no common metric with market and credit risk, so enterprise-level aggregation in practice reduces to scoring exercises on a heat map. The portfolio claim, which is the entire intellectual justification for the framework, is the part least implemented.
Documentation can substitute for judgement. Power's charge, made when institutions with exemplary frameworks were failing, was that ERM produces auditable evidence of process rather than better decisions, and that the demand for evidence actively crowds out the uncomfortable conversations that risk governance is supposed to force.
هو إطارٌ ويسلك سلوك الأطر. فليس ثمّة حالُ عالمٍ يظهر فيها كوزو أو الأيزو ٣١٠٠٠ باطلًا. فالمنشأة التي تخفق يمكن دائمًا وصفُها بأنها طبّقت الإطار تطبيقًا رديئًا، وهذا يجعل الإطار نفسه غير قابل للتكذيب ويحيل كلَّ دعوى تجريبية إلى جودة التطبيق، وهي غير مقيسة.
والتبنّي يُقاس بالإعلان لا بالممارسة. فوجودُ رئيسٍ لإدارة المخاطر، أو عدُّ كلمات، أو تصنيف، هي البدائل المعيارية، وكلٌّ منها يتحقّق من غير أن تُجمَع مخاطرةٌ واحدة على نحوٍ مختلف. ومنشأتان تُرمَّزان متبنّيتين بالسويّة قد تشغّلان وظيفتَي مخاطر مختلفتين تمامًا، ومنشأتان تُرمَّزان مختلفتين قد تشغّلان الوظيفة نفسها. ومتغيّرٌ ثنائي مبنيٌّ هكذا لا يحمل فرضيةَ قيمة.
والداخلية هنا ليست تحفّظًا بل هي الحدث الرئيس. فالحجمُ والتعقيد والملكية المؤسسية وجودةُ المجلس والأداءُ السابق كلُّها تتنبّأ بالتبنّي وكلُّها تتنبّأ بالقيمة. والأدواتُ الضعيفة والمطابقةُ على الملاحَظات لا تحلّان الانتقاء على جودة الإدارة. وأكثرُ آثار القيمة المنشورة متّسقٌ مع كون التبنّي عرضًا لمنشأةٍ حسنة الإدارة لا سببًا لها.
والمقاس الواحد لا يناسب الجميع، والمتغيّر الثنائي يخفي هذا. فقد وثّقت البحوث الميدانية أن وظائف المخاطر تشغل أدوارًا متمايزة بين المنشآت، من حفظ سجلّات الالتزام إلى المحاجّة المستقلّة لخطط الأعمال، وأن هذه الأدوار ليست مراحلَ على مسار نضجٍ واحد. وجمعُها في متغيّر تبنٍّ واحد يأخذ متوسّطًا لممارساتٍ آثارُها متعاكسة.
والتجميع الذي يعد به الإطار لا يُنفَّذ فعلًا. فمخاطرُ التشغيل والاستراتيجية والسمعة لا مقياس مشترك لها مع مخاطر السوق والائتمان، فينحلّ التجميعُ على مستوى المؤسسة عمليًّا إلى تمارين تقديرٍ على خريطةٍ حرارية. فدعوى المحفظة، وهي كلُّ المبرّر الفكري للإطار، هي أقلُّ أجزائه تنفيذًا.
والتوثيق قد ينوب عن الحُكم. فتهمةُ باور، وقد قالها حين كانت مؤسساتٌ ذات أطر نموذجية تخفق، أن هذا الإطار ينتج دليلًا قابلًا للمراجعة على وجود عملية لا قراراتٍ أفضل، وأن الطلب على الدليل يزاحم فعليًّا المحادثاتِ المزعجة التي يُفترَض بحوكمة المخاطر أن تفرضها.