CHAPTER 3

Risk-Aware Culture

Introduction

COSO defines “enterprise risk management” as1:

The culture, capabilities, and practices, integrated with strategy-setting and performance that organizations rely on to manage risks in creating, preserving and realizing value.

An organization is a social entity. People are important to organizations. Organizational theory provides a macro examination of people in the organizations because it analyzes the organizations as a unit. The point of studying organizations is to enable us to find ways to improve performance and effectiveness.2 Improving an organization’s effectiveness is not a simple matter. The diversity of people within an organization is often matched by the needs of these people to want different ...

Get How New Risk Management Helps Leaders Master Uncertainty now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.