Institutions are under pressure on every front: enrollment, student mental health, cybersecurity, shifting regulation, and natural disasters. Because these risks are cross-functional and far-reaching, many institutions are turning to Enterprise Risk Management (ERM) for a structured, strategic response.
However, numerous institutions have launched ERM programs aimed at identifying as many risks as possible. Risk workshops and surveys generate long lists of issues—ranging from campus safety threats to lab safety to information security to the occasional campus squirrel incident. Each may represent a valid operational concern, but collectively they create sprawling inventories that are difficult to prioritize or meaningfully discuss at the leadership level. The result is the ERM inventory trap: an unwieldy catalog of operational concerns with little connection to institutional decision-making. Effective ERM programs take the opposite approach. They start with governance, define enterprise risk, focus on a small set of strategic exposures, and create a structured process to monitor them over time.
Start with Governance, Not the Inventory
Many institutions begin ERM by asking departments to identify risks without defining how those risks will be owned, reported, or reviewed. Without that structure, even well-intentioned efforts quickly become disconnected from leadership and decision-making.

Sector research reflects this challenge. The 2025 DRU National Higher Education Enterprise Risk Management Survey1 found that the most commonly cited barrier to ERM success was lack of leadership interest or support—identified by 42% of respondents as their biggest challenge. Without clear ownership, ERM can lose momentum or be seen as a compliance exercise rather than a management tool. As one respondent noted, ERM is often “viewed as a compliance tool rather than a strategic approach to business.”
This governance-first approach aligns with frameworks such as COSO ERM2 and ISO 310003, both of which emphasize leadership oversight, accountability, and integration into decision-making.
Build Leadership Buy-In
If governance is essential to ERM success, the practical question becomes: how can institutions actually build leadership engagement?
First, invest in the pre-work. Rather than launching with a broad survey, meet individually with senior leaders to discuss risks and priorities. These conversations build awareness and signal that ERM supports decision-making by not creating an administrative burden.

Second, involve leadership in the design of the program itself. When leaders help shape the framework—risk categories, reporting, governance—they are more likely to stay engaged.
Finally, keep reporting focused and strategic, especially for boards. Boards need a clear view of enterprise exposure, not long inventories of operational issues. A concise portfolio keeps discussions focused. This is where less is more.
When leaders see that ERM clarifies strategic exposure rather than generating more documentation, engagement tends to follow.
Boards need a clear view of enterprise exposure, not long inventories of operational issues.
Define What Actually Counts
Another common challenge is the absence of a shared definition of “enterprise risk.” Without clear parameters, identification exercises produce a wide range of issues—many of which reflect operational risks such as safety incidents or compliance requirements rather than enterprise exposures.
This distinction matters. Universities manage thousands of operational risks every day—safety incidents, facility issues, compliance requirements, and more. These risks are real and important. But not every operational risk is an enterprise risk.
Enterprise risks are different in scale and scope. They are uncertainties that could materially affect strategy, financial sustainability, reputation, or core operations.
Research also suggests that different stakeholders naturally view risk through different lenses. Boards and senior leaders tend to focus on strategic risks, while operational staff identify more localized concerns. Effective ERM bridges these perspectives by elevating the discussion while still capturing underlying drivers.
A simple set of questions can help determine whether an issue rises to the level of an enterprise risk:
Could this materially affect the institution’s ability to achieve its strategic objectives?
Does this risk involve multiple departments or functions?
Would it require leadership-level coordination or resource decisions?
If yes, it likely belongs in ERM. If not, it is better managed through operational processes. Once this distinction is clear, the next question is scope.

Focus on a Small Portfolio
Even with a clear definition, many ERM programs still struggle with scope. The solution is discipline. Effective ERM focuses on a small portfolio—typically 8 to 12 risks—that could materially affect the institution’s strategy, operations, finances, or reputation.
Importantly, limiting the number of enterprise risks does not mean oversimplifying them. Each enterprise risk includes underlying drivers or sub-risks such as operational vulnerabilities, regulatory developments, and emerging trends that shape the overall exposure. Institutions may also maintain an “emerging risks” list to track issues that are evolving but not yet at the enterprise level. ERM isn’t ignoring complexity—it’s organizing it.
ERM is not a catalog of everything that could go wrong. It is a lens on what matters most.
Standardization Makes ERM Manageable
Once risks are defined, consistency in how they are monitored and reported becomes critical. Without standardization, comparisons are difficult and trends are hard to track.
Many programs use a common reporting template capturing key elements: risk description, mitigation strategies, and gaps. Some also use simple scoring models—such as probability × impact—to create a shared language for evaluating exposure and communicating with leadership and boards.
Governance Keeps the Process Alive
Even well-designed ERM frameworks can falter without sustained governance and leadership engagement. Many programs lose momentum because they become periodic documentation exercises.
Effective ERM requires a regular cadence of review. Enterprise risks should be revisited periodically to assess whether exposure levels are changing, whether mitigation strategies remain effective, and whether new or emerging risks should be considered.
Most importantly, governance keeps ERM connected to decision-making. When enterprise risks are discussed regularly within leadership forums, they provide valuable context for strategic planning, resource allocation, and operational priorities.
A Practical Framework for Higher Education ERM
For universities seeking to build more effective ERM programs, the solution is often not identifying more risks but designing a more focused and sustainable process.
In practice, effective ERM programs tend to follow a few core principles:
Establish governance first
Define what constitutes an enterprise risk
Limit the ERM portfolio to a small number of strategic risks
Use standardized reporting to monitor exposure over time
ERM is not a catalog of everything that could go wrong. It is a lens on what matters most. Universities manage thousands of operational risks every day. ERM serves a different purpose: providing leadership with clear visibility into the small number of uncertainties that could materially affect strategy, resilience, and long-term success.
https://resilient.uoregon.edu/dru/2025survey
https://www.coso.org/erm-framework
https://www.iso.org/standard/65694.html
https://www.deloitte.com/us/en/insights/industry/articles-on-higher-education/top-risksin-higher-education.html