On the Determinants of Enterprise Risk Management Implementation

Kurt Desender (Universitat Autonoma de Barcelona, Spain)
Corporate governance failures and new legislation have emphasized the importance of enterprise risk management (ERM) in preventing fraudulent reporting. Despite the increased attention to ERM, little research has been done to explain why some organizations embrace ERM while others do not. The objective of this paper is to explore how the board composition is related to the degree of enterprise risk management implementation. Our main results reveal that the position of the CEO in the board has an important influence on the level of ERM. Furthermore, we find that board independence by itself is not sufficient to induce higher levels of ERM. Board independence is only significantly related to ERM when there is a separation of CEO and chairman. Firms with an independent board and a separation of CEO and chairman show the highest level of ERM. One possible explanation for our results is that CEOs do not favour ERM implementation and are able to withstand pressure from the board when they are occupying the seat of chairman.
Existing agency theory proposes a series of mechanisms that seek to reconcile the interests of shareholders and managers, including the utilization of internal control mechanisms such as monitoring by non-executive directors (Fama & Jensen, 1983), monitoring by large shareholders (Shleifer & Vishny, 1986), the incentive effects of executive share ownership (Jensen & Meckling, 1976) and the implementation of internal controls (Matsumura & Tucker, 1992). An additional instrument of shareholder monitoring is the statutory audit whereby independent auditors report annually to shareholders on the appropriateness of the financial statements prepared by management (Watts & Zimmerman, 1983). The clear implication for corporate governance from an agency theory perspective is that adequate monitoring or control mechanisms need to be established to protect shareholders from management’s conflict of interest (Fama & Jensen, 1983). Since the corporate scandals and the creation of new corporate governance codes, ERM has been considered as a valuable element of the corporate governance structure.

Risk management has evolved from a narrow, insurance based view to a holistic; all risk encompassing view, commonly termed Enterprise Risk Management. In September 2004, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) issued Enterprise Risk Management—Integrated Framework, to provide a model framework for ERM. That framework defines ERM as “a process, effected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.” Nocco and Stultz (2006) argue that ERM is beneficial to most firms because it allows them to manage risks in a manner that avoids costly left tale outcomes.

