A featured contribution from Leadership Perspectives, a curated forum for banking, financial services, and fintech leaders, nominated by our subscribers and vetted by the Financial Services Review Editorial Board.



The ERM Perception Problem
In most banks, enterprise risk management (ERM) does not arrive by invitation. It usually arrives after an exam finding, a consent order or an audit letter that lands on the CEO's desk with a deadline attached. That origin story matters because it shapes how the organization sees the function from day one. ERM can be perceived as a cost center wearing an audit or compliance badge instead of a discipline that helps leaders make better decisions.
I view the challenge in stark terms: risk functions are routinely prejudged as overhead, compliance, technology or an extension of audit. That reputation must be actively countered. Human nature is wired with a fight-or-flight response. Apply that to a bank rolling out a risk framework, and you get the full range of reactions ERM leaders see every week.
The fix is not a better slide deck. In a compliance-heavy environment, effective ERM leadership requires understanding, strategy, relationships and calm persistence. Risk Leaders must market the program as collaborative, strategic, cost-saving and value-added, rather than purely regulatory.
That means speaking in the language of your business. Risk assessments cannot feel like abstract exercises done to please the regulators. They must connect to loan growth, process stability, technology resilience, customer experience, remediation and board confidence. When leaders see that ERM reduces surprises and clarifies accountability, the conversation changes.
Treat Resistance as Grief, Not Defiance
One concept I use often is grief and change-curve psychology. Organizational change follows a process that resembles the stages people move through after a major loss, even though the trigger is different. People are not always being difficult. Sometimes they are processing uncertainty, lost control or the concern that a new framework will expose weaknesses they have managed quietly for years.
“To make ERM stick, risk managers must keep selling the value and then prove it through disciplined execution.”
For that reason, I think about adopters in rough groups: early adopters, the slightly cautious majority, the significantly cautious and a small core of naysayers. Risk leaders should focus on the cautious middle rather than chasing unanimous business adoption. Do not build rollout communications for the loudest skeptics. Build them for the persuadable majority, use early adopters as advocates, celebrate successes and define when the organization will move forward.
I also reference the military concept of VUCA: volatility, uncertainty, complexity and ambiguity, as a shared vocabulary for talking about change with a skeptical, numbers-driven audience. Business decisions made in reaction to change are, in fact, risk-based decisions: identifying what might happen, estimating impact and taking calculated steps while facts are still developing. In an audit-centric culture, that framing shows risk management is measuring uncertainty, organizing it and making it discussable.
Make the Blueprint Visible
Perhaps my most practical recommendation for compliance-heavy institutions is that ERM must demonstrate, not just assert, its structure. I recommend visible executive sponsorship, a layered risk taxonomy, committee governance and a predictable reporting cadence so business partners know how and when to engage. I often describe the three lines of defense this way: the third line audit tests the organization's work, the first line performs and demonstrates the work, and the second line risk management prepares the first line to pass that test. That framing repositions ERM from adversary to partner and coach.
Sell the Value, Then Prove It
The real test of an ERM program is not whether it satisfies a regulatory deadline. It is whether the organization continues to use it after the immediate pressure fades. If the only reason people participate is that an examiner, auditor or committee chair is asking, then ERM remains a compliance patch. It may close a finding, but it will not change how the bank operates.
To make ERM stick, risk managers must keep selling the value and then prove it through disciplined execution. That means showing up consistently, explaining the why, reducing friction and giving the business something useful in return for its time. A strong ERM program should help leaders see patterns sooner, choose priorities confidently, avoid preventable surprises and prepare for scrutiny before it arrives.
In a compliance-first culture, embracing ERM is not marketing spin. It is a translation. I am translating regulatory expectations into business routines, risk language into operating decisions and control discipline into strategic advantage. When that translation is done well, ERM stops feeling like another oversight layer and becomes part of how the bank protects its franchise, supports growth and earns trust. Banks that treat ERM as a partner in performance will get further. Banks that treat it as a one-time answer to a past problem will usually do the work twice.