3 Best Practices for Factoring Risk into Your Strategic Planning Process

No one enjoys strategic planning exercises. They conjure images of a stuffy room filled with executives in dark suits, stacks of paper strewn across the table, and whiteboards covered in scribble. Even in the most collaborative organizations, each executive represents his own department as he vies for the few dollars set aside for yearly projects.

In the midst of the chaos, fact-based analysis is the best approach to setting a clear, realistic course for the organization.

The executives may want to implement sixty projects, but if the organization can only afford forty, then forty it is. They may not to want to upgrade the servers this year, but if the website falters on a weekly basis, then something must be done. These facts aren’t always fun, but they take much of the guesswork out of what needs to be accomplished in the upcoming cycle.

With its analytical approach, is it any wonder that ERM can provide tremendous value during the strategic planning process?

In fact, more than any other time, this is when ERM is needed the most.

Best Practices for factoring risks into your strategic planning process

Projects are implemented to bring about change, and change can always introduce risk. By involving ERM in the strategic planning process, the organization can better understand the potential impact of those projects before they are ever approved.

You can reduce risk in your organization and get the most out of your strategic planning process by following these three best practices.

1. Include all projects in the planning process. 

Even small projects can introduce big risks to the organization. Avoid fast-tracking the seemingly-simple projects; instead, include all of them in the same planning process to ensure visibility and traceability down the road. (Part 2 of this blog series will discuss how ERM can partner with project management to add value to project tracking.)

2. Utilize ERM to identify enterprise risks. 

When asked about risk, Sponsors often point to a problem they believe the project will solve. While this may be a valid problem, it may not be a risk to the organization. On the other hand, Sponsors rarely think of the risks the project could introduce or magnify. If he works in a silo, the Sponsor may not even realize the impact the change will have on other business areas.

For example, the project’s goal may be to create a new product for the coming year. While the product may be a great addition to the company’s lineup, it may stretch existing resources and increase the organization’s liability exposure. That doesn’t mean it’s not worth pursuing, just that certain risks may need to be addressed before, during, or after implementation (e.g. increase training for personnel and/or purchase more liability coverage).

The ERM team is better suited to observe and analyze these risks than any other group within the organization, as they can provide an unbiased perspective. Include them in this early stage to ensure your executives have all the facts when they start the planning process. This will also ensure the ERM team is aware of any risks that should be addressed as projects are implemented.

3. Utilize ERM to understand the cumulative risk effect. 

Some projects may impact the same risk area, such as the organization’s reputation or finances. While individually they may pose a low likelihood of occurrence and a low level of impact, small issues with each of the projects can accumulate, creating a large problem for the organization.

For example, a business that is heavily regulated by the state or federal government has a low risk tolerance for consumer complaints. During planning, executives decide to implement several new processes to help streamline the customer experience. Each project would introduce little risk, with only a few complaints expected. However, if all of the projects are pursued in the same year, the number of complaints could grow exponentially, opening the door to regulatory fines and increased oversight.

ERM should be included in the strategic planning process to help identify this cumulative risk effect of the projects being selected. In response, ERM may advise against implementing multiple projects that could impact the same area, especially if it is crucial to the organization (as reputation often is). If avoidance is not an option, ERM can help executives plan to transfer or mitigate the risk. This proactive approach to risk management can make the difference between a successful organization and one that is constantly in clean-up mode.

(Click here to learn more about risk response strategies to consider after identifying risks during the strategic planning process.)

strategic planning

A Good Beginning

Only by including ERM in the strategic planning process can organizations ensure they are getting the most out of their projects while avoiding unwanted consequences. However, the planning process is only the beginning stage for projects.

Has your organization considered risk during strategic planning? 

If so, were any projects altered, delayed or abandoned altogether after factoring risks into the decision? 

Let us know in the comments section below, or join the conversation on LinkedIn. And check back soon for part 2 of this blog where we’ll look at ways ERM can continue to identify and reduce enterprise risks throughout the project lifecycle.

We trust this blog has been helpful. Thank you for stopping by!

About the author

Ashley Jones recently joined ERM Insights by Carol. She graduated from Florida State University in 2003 with a B.A. in Risk Management and Insurance and obtained the Project Management Professional (PMP) designation in May 2012. Ashley has fourteen years of experience in the fields of insurance and risk management, most notably as a Senior Risk Analyst within the ERM department of a $7+ billion property and casualty insurance company. When she’s not working on project or risk management, Ashley is busy writing and blogging on a wide variety of topics.

Sign Up For Our Newsletter

Sign Up For Our Newsletter


Meet Carol

Helping companies achieve their vision and strategy, and succeeding in today's turbulent world, is something I'm honored to be a part of. Whether you're an occasional blog visitor or a long-term client, thank you for letting us be a part of your journey.

Most Recent Posts

The 12 Days of ERM Christmas

Without a doubt, one of my family’s favorite holidays is Christmas. Part of the fun, especially for our son, is seeing what “Santa” brought, but most importantly, we treasure the spirit of peace and goodwill the season brings. And after what seemed to be a never-ending warm spell, the weather is expected to be good…

Read More

Don’t Let Goals and Initiatives Be Blindsided by External Events

As the end of the year draws near, I think we’d all agree that while it wasn’t without its challenges, this year also wasn’t quite as turbulent as the previous two. While a lot of people are juggling company parties, shopping for friends and family, and special activities for the kids, most companies are putting…

Read More

Going the Distance: Ensuring Successful Execution of Strategic and Annual Initiatives

Strategic planning is a challenge – of all people, I understand… After all the meetings, risk and data analysis, and brainstorming of the preceding months, it’s tempting to think this is the end of the road and you can relax. Contrary to this common perception though, this is exactly not the time to relax, but…

Read More

Avoid Rookie Mistakes and Protect your Internal Reputation

Be honest – have you ever done something that you soon realized was a real rookie mistake? Me raising my hand… Considering the nature of ERM’s role to ask questions and challenge assumptions (often during conversations with executives), it can be argued that, in at least some cases, the expectations bar for risk professionals is…

Read More

ERM at Thanksgiving – An Illustration of Risk Management in Action

On occasion, I like to take some of the concepts we risk professionals think about in our jobs and apply them to different personal situations…take some of the same concepts we use when working with executives to develop corporate strategy and manage risks or uncertainty around that strategy. It’s Thanksgiving week in the U.S. –…

Read More

Why Quantitative Risk Assessment is Not Just the Best But the Only Option – A Conversation

Periodically, I have the pleasure of speaking one-on-one with Hans Læssøe on a variety of topics around ERM, strategic risk, and other issues and trends. As you know from my previous conversations (here, here) and posts featuring his work, Hans was formerly a practitioner at the iconic LEGO Company, but even more notably, is a…

Read More

The Three Lines Model – 3 Reasons Why I Don’t Like It

Everyone likes a clear-cut template that offers an easy way to create or manage something…I mean what’s not to like about a step-by-step process for accomplishing what you want? Sometimes this can work without any issues, such as the case with the Project Management Book of Knowledge (PMBOK), ISO 9001 standard, or a new cooking…

Read More

5 Avenues for Expanding your ERM Knowledge

One thing I was taught to appreciate from a young age was the value of education and knowledge. It didn’t necessarily matter what the subject was, just that I always maintain a learning or growth mindset regardless of my current status in life. This mindset has served me well over the years, and it’s a…

Read More

Storytelling and Risk Management – Developing Skills that Technology Cannot Replace

It’s amazing how technology has developed and changed our working world over time. Imagine trying to run my risk and strategy consulting firm without tools like Zoom, Box, Slack, and other ERM-specific technology tools. There is no way we would be able to serve our clients the way that we do. Just consider how the…

Read More

3 Phases to Creating and Launching an ERM Program Focused on Organizational Success

If you’ve been handed the task of creating an ERM program for your organization, let me first offer my congratulations quickly followed by my empathy for the task ahead of you. I don’t say that to scare you but to provide a small dose of reality. Building, launching, and refining an ERM program that is…

Read More