PrepSolution
SPHRHigh-YieldLeadership and Strategy 33%

probability × impact · choose the response · assign the owner

Enterprise risk management for HR

The risk register is not the work. The work is choosing what to do with each risk — and naming the person who owns the response. CHRO owns the talent rows on the enterprise risk register.

The HR risk heat map

where each risk lives, what to do with it

low impact

high impact

high probability

REDUCE

Common, bearable. Add controls.

  • · grievance backlog
  • · manager-quality variance
  • · compliance training gaps

AVOID

Eliminate the activity.

  • · unmonitored AI hiring tool
  • · unsupported pay practice
  • · high-litigation business model

low probability

ACCEPT

Mitigation costs more than expected loss.

  • · minor handbook policy gaps
  • · low-frequency nuisance claims
  • · small-scale benefits errors

TRANSFER

Insurance, contractual indemnity.

  • · wrongful-term exposure → EPLI
  • · cyber breach on HR data
  • · fiduciary liability on plans

The framework the board uses

COSO ERM (2017 update)is the framework most boards reference. Five components: governance & culture sets the tone, strategy & objective-setting defines risk appetite, performance identifies and prioritizes risks, review & revision monitors the process, and information/communication keeps the picture current. ISO 31000:2018 is the alternative — same logic, different vocabulary.

The exam reliably distinguishes inherent risk (before controls) from residual risk (after controls), and risk appetite (broad willingness to accept) from risk tolerance (variation allowed around specific objectives).

on the enterprise risk register, CHRO owns:

  • — talent continuity & key-person dependency
  • — succession gaps for top 100 roles
  • — culture risk (toxic culture, harassment, conduct)
  • — pension underfunding
  • — litigation exposure (wrongful term, discrimination, wage & hour)
  • — HR data cyber exposure (in partnership with CISO)

Exam Traps

COSO ERM is broader than COSO Internal Control

COSO IC focuses on financial reporting. COSO ERM (2017) integrates strategy and performance. Different documents, related families.

Risk appetite ≠ risk tolerance

Appetite is the broad amount willing to accept. Tolerance is the variation around specific objectives. Boards set both.

Inherent risk vs residual risk

Inherent is risk before controls. Residual is risk remaining after controls. Senior HR audits residual.

HR is named risk owner for talent risks

CHRO often owns talent risk on the enterprise risk register. Workforce continuity, succession, key person dependency.

Risk register is not the work

Listing risks does not manage them. The work is choosing the response (avoid, reduce, transfer, accept) and assigning ownership.

CHRO owns workforce risks

On enterprise risk registers, CHRO is the named owner of talent continuity, succession, and culture risks.

1
Read the chart

Identify risks across the enterprise. Strategic, financial, operational, compliance, reputational, talent.

2
Assess the storm

Probability × impact. Heat map plots them. Inherent vs residual.

3
Set the course

Choose response per risk. Avoid the storm. Reduce exposure. Transfer to insurance. Accept and budget.

4
Crew the watch

Assign owner per risk. CHRO owns talent risks. CFO owns financial. Compliance officer owns regulatory.

5
Sail and adjust

Monitor risks quarterly. Update the register. Report to board risk committee.

Picture the ship navigating the storm. Risk register is the chart. Response is the course. Owner is the watch. Board is the harbor master.
reading is not enough, you gotta practice

Ready to test your SPHR knowledge?

1,500+ practice questions written by certified professionals.

Start Practicing SPHR
Reviewed by Megan O., PrepSolution Content Editor, Senior HR
Sources verified against HRCI 2026 standards
Updated May 2026