30.2 Enterprise Risk Management (ERM) & OMB Circular A-123 Implementation
Key Takeaways
- OMB Circular A-123 formally integrates ERM with strategic planning under GPRAMA and internal control under the GAO Green Book, requiring agencies to build and maintain an annual agency Risk Profile.
- The ERM process lifecycle encompasses establishing context, risk identification, qualitative/quantitative risk assessment, formulating risk responses (accept, avoid, reduce/mitigate, share/transfer), and continuous monitoring.
- Enterprise Risk Management (ERM) transforms agency governance from traditional, reactive compliance silos into a proactive, organization-wide strategic risk management architecture.
15.3 Enterprise Risk Management (ERM) & OMB Circular A-123 Implementation
The Public Sector Paradigm Shift: From Siloed Compliance to Enterprise Risk Management
Historically, risk management in government was highly fragmented, defensive, and backward-looking. Individual departments operated in functional silos—commonly referred to as "organizational stovepipes":
- The Chief Financial Officer (CFO) focused narrowly on internal controls over financial reporting;
- The Chief Information Officer (CIO) managed cybersecurity vulnerabilities in isolation;
- The Chief Procurement Officer (CPO) monitored vendor compliance and contract protests;
- Program managers focused exclusively on daily service delivery.
This fragmented posture left agencies blind to emerging, cross-cutting enterprise risks that spanned multiple divisions. When multi-agency crises occurred—such as catastrophic IT modernization failures, large-scale supply chain disruptions, or massive payment fraud—traditional internal control checklists proved inadequate.
To overcome these systemic vulnerabilities, modern public administration has embraced Enterprise Risk Management (ERM). ERM is a comprehensive, entity-wide strategic approach that enables government leaders to identify, evaluate, prioritize, and manage the full portfolio of risks and opportunities threatening their statutory mission.
+-----------------------------------------------------------------------------------+
| TRADITIONAL RISK MANAGEMENT VS. ENTERPRISE RISK MANAGEMENT |
+-----------------------------------------------------------------------------------+
| DIMENSION | TRADITIONAL SILOED APPROACH | ENTERPRISE RISK MANAGEMENT (ERM)|
|---------------------|------------------------------|---------------------------------|
| Scope | Departmental / Functional | Entity-wide / Cross-cutting |
| Perspective | Defensive / Compliance-first | Strategic / Mission-oriented |
| Focus | Past audit findings & errors | Future uncertainties & horizons |
| Risk Ownership | Isolated mid-level managers | Executive Leadership / CRO |
| Integration | Disconnected from strategy | Integrated with GPRAMA & budget |
+-----------------------------------------------------------------------------------+
The COSO ERM Framework: Strategy and Performance
In 2004, and significantly updated in 2017, COSO published its landmark framework: Enterprise Risk Management - Integrating with Strategy and Performance. This framework shifted the global conversation by demonstrating that risk is not merely an operational hazard to be avoided, but an intrinsic element of strategy formulation and performance execution. The 2017 framework is structured around five core components and twenty principles:
- Governance and Culture: Setting the organizational tone, risk oversight structures, and desired ethical behaviors.
- Strategy and Objective-Setting: Evaluating enterprise risk appetite in direct alignment with strategic objectives.
- Performance: Identifying, assessing, prioritizing, and responding to risks that impact performance targets.
- Review and Revision: Continually assessing organizational performance changes and recalibrating risk responses.
- Information, Communication, and Reporting: Leveraging risk data systems and reporting transparently to internal and external stakeholders.
Federal ERM Mandate: OMB Circular A-123
In July 2016, the Office of Management and Budget enacted a historic overhaul of OMB Circular A-123, retitling it: Management's Responsibility for Enterprise Risk Management and Internal Control. This directive established a mandatory federal ERM policy, requiring executive agencies to implement an enterprise-wide risk management capability directly integrated with:
- Strategic Planning under the GPRA Modernization Act of 2010 (GPRAMA): Risk management must align directly with an agency's Strategic Goals, Strategic Objectives, and Agency Priority Goals (APGs).
- Internal Control under the GAO Green Book (FMFIA): ERM establishes the strategic risk context that informs the design and operation of operational internal controls.
- Budget Formulation & Capital Investment: Resource allocation during budget formulation must reflect risk mitigation priorities.
+-----------------------------------------------------------------------------------+
| CIRCULAR A-123 INTEGRATED STRATEGIC RISK ARCHITECTURE |
+-----------------------------------------------------------------------------------+
| |
| GPRA MODERNIZATION ACT (GPRAMA) |
| Strategic Goals & Performance Plans |
| | |
| v |
| ENTERPRISE RISK MANAGEMENT |
| Portfolio Analysis & Risk Profile |
| | |
| v |
| GAO GREEN BOOK |
| Internal Control Activities & Monitoring |
| |
+-----------------------------------------------------------------------------------+
Executive ERM Governance Architecture
To implement ERM effectively, federal agencies establish formal governance structures:
- Chief Risk Officer (CRO): A designated senior executive responsible for establishing, leading, and coordinating the agency-wide ERM program.
- Senior Management Council (SMC) / Executive Risk Steering Committee: Chaired by the Deputy Secretary, Chief Operating Officer (COO), or CRO, and comprising assistant secretaries and bureau heads. This body reviews the enterprise risk profile, adjudicates cross-cutting vulnerabilities, and calibrates risk appetite.
The Comprehensive ERM Process Lifecycle
Under OMB Circular A-123 and COSO ERM, the management of risk moves through a continuous, disciplined five-phase lifecycle:
+-----------------------------------------------------------------------------------+
| THE FIVE-PHASE ERM LIFECYCLE |
+-----------------------------------------------------------------------------------+
| 1. ESTABLISH CONTEXT |
| • Articulate statutory mission, operating environment, and stakeholder needs. |
+-----------------------------------------------------------------------------------+
| 2. RISK IDENTIFICATION |
| • Systematically discover risks across strategic, operational, & compliance. |
+-----------------------------------------------------------------------------------+
| 3. RISK ASSESSMENT |
| • Evaluate Inherent Risk; score Likelihood (1-5) and Impact (1-5). |
+-----------------------------------------------------------------------------------+
| 4. RISK RESPONSE FORMULATION |
| • Select strategy: Accept, Avoid, Reduce/Mitigate, or Share/Transfer. |
+-----------------------------------------------------------------------------------+
| 5. MONITORING AND REVIEW |
| • Track Key Risk Indicators (KRIs), update Risk Profile, and report to SMC. |
+-----------------------------------------------------------------------------------+
Phase 1: Establish the Context
Management defines the internal and external environment in which the agency operates. This includes statutory authorizations, executive branch priorities, socioeconomic trends, geopolitical factors, organizational culture, and resource limitations.
Phase 2: Risk Identification
Agencies identify events, trends, or vulnerabilities that could adversely affect—or provide opportunities for—the achievement of strategic objectives. Techniques include environmental scans, executive interviews, risk workshops, employee surveys, historical incident analysis, and Inspector General audit reviews.
Phase 3: Risk Assessment
Risks are assessed qualitatively and quantitatively to establish their relative priority:
- Inherent Risk: The exposure level in the absence of any management action, policy, or control activity.
- Likelihood Scoring: The probability that the risk event will materialize over a specified timeframe (typically scored on a 1-to-5 scale from "Rare" to "Almost Certain").
- Impact Scoring: The severity of consequences if the event occurs, evaluated across programmatic, financial, compliance, health/safety, and reputational axes (typically scored on a 1-to-5 scale from "Inconsequential" to "Catastrophic").
- Risk Score: Calculated as $\text{Likelihood} \times \text{Impact}$, yielding an inherent risk ranking from 1 to 25.
- Residual Risk: The remaining risk exposure after existing internal controls and risk responses have been accounted for.
Phase 4: Risk Response Strategies
Management selects an appropriate response for each evaluated risk, ensuring alignment with organizational risk appetite:
- Accept: Take no active measures; retain the risk within existing tolerance levels (appropriate when risk severity is low or mitigation costs exceed any possible benefit).
- Avoid: Terminate, redesign, or exit the program, activity, or contract that generates the unacceptable risk.
- Reduce / Mitigate: Design and deploy internal controls, process reengineering, enhanced training, or automated monitoring to lower the likelihood of occurrence or the magnitude of impact.
- Share / Transfer: Reallocate or transfer a portion of the risk to third parties through commercial insurance, indemnification provisions, service agreements, or interagency partnerships.
Phase 5: Ongoing Monitoring & Review
Risks are not static. Agencies establish Key Risk Indicators (KRIs)—metric-based early warning indicators that alert leadership when an operational parameter is approaching an unacceptable threshold.
Developing the Agency Risk Profile
Under OMB Circular A-123, each executive agency is required to build and maintain an annual Agency Risk Profile. The Risk Profile is an executive-level portfolio analysis that documents the agency's primary risks and informs both executive decision-making and annual budget requests.
According to OMB Circular A-123, which of the following best describes the purpose and structure of an agency Risk Profile?