A new risk lead came to me after an audit finding with a 47-page pack and a heat map. The board had two weeks, and she could tell me which committee had reviewed the papers. She could not tell me what the board was actually being asked to decide. That is why ERM fails.
I asked her to show me the sentence that said what the board should actually do. There was none. The pack had plenty on governance and appetite; it had nothing that said, plainly, whether the board should keep the hedge or remove it. In my experience, that missing sentence is the whole problem.
I see this in banks and manufacturers. The paperwork improves and the decision stays foggy. I have watched organisations spend months cleaning up the language around exposure while the capital decision that mattered sat untouched. That is the same problem running through how risk decisions go wrong, and it is why I keep asking what the register is actually for when a board wants more than tidier language.
ERM fails when it produces reports and review cycles without naming the live decision or the assumption carrying it.
The oversight machinery is doing a different job
NC State and AICPA did us a favour by counting how little of this machinery reaches a board call. Risk complexity was rising, yet only 32% of respondents said oversight was mature or strong, only 11% said it created strategic advantage, and only 30% said risk exposure was integrated into capital allocation. That is what an oversight industry looks like when it keeps growing after it has stopped helping leaders reach sufficient certainty. The figures also explain why so many boards feel busy and still arrive at the hard meeting underprepared.
The drift was not accidental. Enron collapsed, Arthur Andersen collapsed with it, and the large audit firms were suddenly short of a useful consultancy stream. They approached the Treadway Commission; COSO's ERM framework arrived in September 2004, and it was so long and so elaborate that many organisations could barely make sense of it without specialist consultant services! I remember the reaction from people actually trying to make decisions inside organisations. They did not need a larger edifice. They needed help naming the call and the assumption carrying it, then setting the trigger that would reopen it. The audit profession promoted the framework anyway. That is one reason so much ERM still looks like list management.
The same inflation happened with risk appetite. After Barings Bank and Nick Leeson, the idea of setting clear trading limits had an obvious use. Fine. Then the idea swelled into appetite paperwork and its assurance industry. I have watched organisations produce these annual confections with immense care, then put them aside when a live decision arrived on Thursday afternoon. This year's flavour is software that spits out longer lists of risks so managers do not even have to think about them. That is not progress; it is abdication with better formatting.
I sat on a committee that spent the better part of a morning polishing appetite wording after a regulator asked for more clarity. Near the end I asked what decision the board would make differently once the paper was approved. Silence. Then someone said the document would show we took risk seriously. That answer told the truth. The paper was serving the file, not the decision.
New risk managers feel this immediately. They inherit appetite language and assurance paperwork, yet the board still wants a recommendation by Thursday. Roger Estall and I made the same point in Deciding: if the answer is the framework, what exactly was the decision problem? Most of the time nobody can say, because the framework was commissioned as an answer before the question was defined.
A board pack can organise meetings and ownership lines. It cannot name the live decision for the board, test the few assumptions that matter, or write the reopen trigger. That is the mechanism of failure, and it is more common than most directors care to admit.
Take the ERM framework your board approved and find the sentence that names the decision, the assumption carrying it, and the trigger that would reopen it. Start the Walk →
ERM fails the same way under pressure
Silicon Valley Bank is the clean example. The Federal Reserve's review says management removed interest-rate hedges to protect short-term profit, and 31 supervisory findings were still open when the bank failed. The bank had reports and committees, with supervisors in the background. What it did not have was a decision record saying: we are removing the hedge because we believe deposits will remain stable enough to carry the exposure, and this is the trigger that sends the matter back to the board. In my experience, once you write the missing sentence, the failure becomes obvious.
Credit Suisse shows the same defect at slower speed. FINMA's report recorded 382 points requiring action between 2018 and 2022, including 113 rated high or critical, yet confidence still broke the institution. I have seen organisations admire a remediation inventory simply because it is long. They mistake volume for grip. A backlog of 382 items is not a decision basis; it is evidence that nobody has reduced the matter to the few judgments leaders must own about funding confidence and the timing of the business-model call.
Macondo is harsher. The U.S. Chemical Safety Board found BP and Transocean both had policies that exceeded the regulatory minimum, yet those policies were not applied at the well; 11 workers died and at least 17 were injured. The governance existed, but it never changed the operating decision at the well. That is the real test. A policy in a city office does not choose casing design or tell a crew to stop when the signals are wrong. People on the scene still need a usable basis for the call.

People sometimes tell me those cases are too extreme. I disagree. I have watched ordinary companies repeat the same mechanism at smaller scale: a thick board file and a settled appetite statement, with a management paper that never quite says yes or no. Under pressure, leaders do not need another taxonomy. They need the few assumptions carrying the decision, written plainly enough that someone will own them. Scale changes the damage, not the mechanism.
What to do when ERM fails
I start with one page, not a bigger register. The first line states the decision in plain language: keep the hedge or remove it, keep the site open or close it. Then we work through the Universal Decision-Making Method. Frame the decision stops the room hiding inside categories, and Develop options forces a real choice. Recognise assumptions exposes what the preferred option is secretly leaning on. Sufficient certainty asks whether we know enough to act, and Design monitoring assigns the trigger that reopens the decision after action.
I write the note as if it will be read aloud. If the sentence sounds evasive, the decision is still evasive. If the assumption cannot be named in one line, nobody understands it yet. I want a board to be able to say, in ordinary language, what it believes and what would prove it wrong. That is the discipline the machinery usually avoids, because once the judgment is visible it can be challenged.
In my experience, one assumption usually carries most of the load. It may be deposit stickiness; it may be demand recovery. Once that assumption is named, most of the committee paper becomes optional, which is disappointing only if you bill by the page, because the board needs to know what must be true for the decision to work. Everything else is commentary until it affects that assumption or the trigger tied to it.
I watched an organisation spend months debating risk categories while a decision to restructure its distribution network sat idle. When we forced the matter onto one page, the hinge was obvious: management was assuming the displaced volume would be absorbed by remaining channels within six months. The board did not need a register to react to that. It needed evidence on channel capacity and customer tolerance, plus a date when the assumption would be judged false. The rest of the framework could wait.
If someone insists that the standard must drive the whole exercise, I send them to ISO 31000 decision making. Standards can support a board call; they do not supply the judgment. They are background material. The decision note is the working instrument.
What I put in front of leaders is smaller
The repaired pack is short and unforgiving. It records the decision with its load-bearing assumption, then states the trigger that would reopen the call, with enough explanation to make the judgment visible. Once that is on the page, directors can disagree honestly; before that, they are usually arguing about presentation. I have seen a discussion that had wandered for an hour settle in ten minutes once someone wrote, plainly, what the board was assuming and when that assumption would be tested.
This is where the machinery exposes its real cost. When the decision is vague, nobody owns the assumption; when nobody owns the assumption, the organisation starts calling delay prudence. Capital sits in the wrong place and weak positions stay open too long; ugly choices return later with fewer options. I have seen boards mistake the annual appetite paper for discipline, when in fact it gave them a way to avoid naming the call they were unwilling to own.
I do not want leaders leaving the room with a heavier pack. I want them leaving with a clear decision and a date or event that sends it back to the table. If the framework cannot do that, it is not helping leaders decide. It is helping the organisation look busy while the real exposure stays unowned. I have been around this field long enough to know the difference.
You could rebuild the ERM framework and still leave no one able to name the decision it is supposed to support.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.