probability × impact · choose the response · assign the owner
Enterprise risk management for HR
The risk register is not the work. The work is choosing what to do with each risk — and naming the person who owns the response. CHRO owns the talent rows on the enterprise risk register.
The HR risk heat map
where each risk lives, what to do with it
low impact
high impact
high probability
REDUCE
Common, bearable. Add controls.
- · grievance backlog
- · manager-quality variance
- · compliance training gaps
AVOID
Eliminate the activity.
- · unmonitored AI hiring tool
- · unsupported pay practice
- · high-litigation business model
low probability
ACCEPT
Mitigation costs more than expected loss.
- · minor handbook policy gaps
- · low-frequency nuisance claims
- · small-scale benefits errors
TRANSFER
Insurance, contractual indemnity.
- · wrongful-term exposure → EPLI
- · cyber breach on HR data
- · fiduciary liability on plans
The framework the board uses
COSO ERM (2017 update)is the framework most boards reference. Five components: governance & culture sets the tone, strategy & objective-setting defines risk appetite, performance identifies and prioritizes risks, review & revision monitors the process, and information/communication keeps the picture current. ISO 31000:2018 is the alternative — same logic, different vocabulary.
The exam reliably distinguishes inherent risk (before controls) from residual risk (after controls), and risk appetite (broad willingness to accept) from risk tolerance (variation allowed around specific objectives).
on the enterprise risk register, CHRO owns:
- — talent continuity & key-person dependency
- — succession gaps for top 100 roles
- — culture risk (toxic culture, harassment, conduct)
- — pension underfunding
- — litigation exposure (wrongful term, discrimination, wage & hour)
- — HR data cyber exposure (in partnership with CISO)
Exam Traps
COSO ERM is broader than COSO Internal Control
COSO IC focuses on financial reporting. COSO ERM (2017) integrates strategy and performance. Different documents, related families.
Risk appetite ≠ risk tolerance
Appetite is the broad amount willing to accept. Tolerance is the variation around specific objectives. Boards set both.
Inherent risk vs residual risk
Inherent is risk before controls. Residual is risk remaining after controls. Senior HR audits residual.
HR is named risk owner for talent risks
CHRO often owns talent risk on the enterprise risk register. Workforce continuity, succession, key person dependency.
Risk register is not the work
Listing risks does not manage them. The work is choosing the response (avoid, reduce, transfer, accept) and assigning ownership.
CHRO owns workforce risks
On enterprise risk registers, CHRO is the named owner of talent continuity, succession, and culture risks.
Identify risks across the enterprise. Strategic, financial, operational, compliance, reputational, talent.
Probability × impact. Heat map plots them. Inherent vs residual.
Choose response per risk. Avoid the storm. Reduce exposure. Transfer to insurance. Accept and budget.
Assign owner per risk. CHRO owns talent risks. CFO owns financial. Compliance officer owns regulatory.
Monitor risks quarterly. Update the register. Report to board risk committee.
Ready to test your SPHR knowledge?
1,500+ practice questions written by certified professionals.
Start Practicing SPHR