Institutions are under pressure on every front: enrollment, student mental health, cybersecurity, shifting regulation, and natural disasters. Because these risks are cross-functional and far-reaching, many institutions are turning to Enterprise Risk Management (ERM) for a structured, strategic response.
However, numerous institutions have launched ERM programs aimed at identifying as many risks as possible. Risk workshops and surveys generate long lists of issues—ranging from campus safety threats to lab safety to information security to the occasional campus squirrel incident. Each may represent a valid operational concern, but collectively they create sprawling inventories that are difficult to prioritize or meaningfully discuss at the leadership level. The result is the ERM inventory trap: an unwieldy catalog of operational concerns with little connection to institutional decision-making. Effective ERM programs take the opposite approach. They start with governance, define enterprise risk, focus on a small set of strategic exposures, and create a structured process to monitor them over time.
Start with Governance, Not the Inventory
Many institutions begin ERM by asking departments to identify risks without defining how those risks will be owned, reported, or reviewed. Without that structure, even well-intentioned efforts quickly become disconnected from leadership and decision-making.

Sector research reflects this challenge. The 2025 DRU National Higher Education Enterprise Risk Management Survey1 found that the most commonly cited barrier to ERM success was lack of leadership interest or support—identified by 42% of respondents as their biggest challenge. Without clear ownership, ERM can lose momentum or be seen as a compliance exercise rather than a management tool. As one respondent noted, ERM is often “viewed as a compliance t