Balancing Risk with Strategic Innovation: Keys to a Modern Enterprise Risk Management Program

Many credit unions still treat enterprise risk management (ERM) as a necessary evil. But some are transforming their ERM program into a strategic decision-making framework that allows them to pursue innovation while operating within clearly defined risk tolerances.

When credit union leaders hear “risk management,” they often picture controls, audits, and barriers to innovation.

At Wescom Financial, that approach is turned on its head.

“Risk management isn’t just about saying no,” says Carina Hollis, Senior Vice President, General Counsel at Wescom Financial. “It’s about allowing you to take measured risks.”
Those credit unions best positioned for the future don’t focus on eliminating risk entirely. Instead, they are adept at understanding, measuring, and intentionally accepting the right kinds of risk, which empowers them to pursue growth at scale.

Why the Old View of ERM No Longer Works

Enterprise risk management (ERM) is a discipline at the intersection of several functions, including regulatory compliance, internal audit, legal, cybersecurity, and fraud prevention. Historically, ERM has been reactive and over-reliant on backwards-looking tools like audits and annual assessments.

Today, the risk landscape has evolved to the point where such a rearview approach is no longer sufficient. The rise of AI has supercharged fraud, putting sophisticated, scalable tools like voice and video spoofing in the hands of small-time criminals. Meanwhile, members increasingly demand immediate, anytime/anywhere access, making it harder to prevent bad actors from gaining access to sensitive information and accounts. And credit unions manage hundreds of third-party relationships, adding layers to the operational and cyber risk already inherent to internal systems.

This is why three-quarters of financial institutions identify cybersecurity as their top enterprise risk, while fraud and third-party risk continue to climb.

Rising competition from fintechs, online lenders, and big banks places enormous pressure on credit unions to constantly innovate in order to hold onto member relationships and remain solvent.

o combat these complex headwinds, the ERM discipline must evolve toward becoming a collaborative partner with the strategic function.

“Risk considerations are embedded within strategic decision-making,” Hollis says. “We don’t treat them as a separate exercise.”

Effective Risk Management Begins with Understanding Your Risk Appetite

When designing an ERM practice, most organizations begin by writing policies.

Wescom Financial took a different approach, starting with a senior-level conversation about the credit union’s risk comfort level. According to Lisa Thompson, Vice President of Enterprise Risk at Wescom Financial, answering this question at the outset is an imperative for successful enterprise risk management.

“If you don’t know what your risk appetite is, you don’t know what to manage to,” Thompson says.

“One of the things we agreed upon when we started developing and formalizing our enterprise risk program seven years ago is that risk management isn’t just about saying no, it’s about allowing you to take measured risks,” Hollis says.

Hollis and Thompson interviewed their peers on the senior leadership team, asking them about their ideal balance between risk management and strategic direction. The overwhelming consensus was to maintain a moderate risk appetite for the credit union as a whole.

However, Wescom Financial doesn’t take a one-size-fits-all approach. For certain domains like cybersecurity, where negative outcomes can have outsized impacts, Wescom Financial maintains a low or low-to-moderate risk appetite.

Hollis says that it’s perfectly fine to decide to operate within a low-risk posture, if that’s deemed the right approach for your credit union. But it’s important to understand how that stance may impact your members, in comparison with the experience they receive from big banks and other competitors.

For Wescom, having a moderate risk appetite doesn’t translate to recklessness. Moderate means intentionality, and it requires constant vigilance.

Build a Repeatable Framework

Once the first, critical step of defining risk appetite is complete, it’s time to build an ERM framework. An ideal structure contains several important elements, including:

  • Board involvement
  • Senior executive ownership
  • Risk domains
  • Key performance indicators (KPIs)
  • Key risk indicators (KRIs)
  • Enterprise Risk Committee
  • Consistent methodology

“The consistency of the framework is so important,” Thompson says, “because we assess each new endeavor against each of those risk domains.”

Wescom Financial puts this framework into action when it develops a new product or service to better serve its members or implements a new internal process to support its strategic goals. For example, when Wescom developed a credit card product in collaboration with a new affinity partner, the Credit Union went through a deliberative pre-launch risk assessment process that included market and demographic data research. The goal was to ensure the new product fit within the organization’s overall risk appetite and aligned with Wescom’s strategic direction. Although an affinity card is a credit product, the new product risk assessment addresses many risk areas beyond credit, including compliance, reputation, liquidity, cybersecurity, and strategic alignment, to name just a few. Thompson’s team then identifies the types of controls to put in place to mitigate each potential pitfall and ensure the overall risk level is acceptable. Each concern, along with the proposed controls, is presented to senior management for approval.

“We view risk through an integrated framework that aligns the strategic objectives of the organization with our risk appetite,” Hollis says. “This ensures there’s always a higher level, enterprise-wide view of risk. It’s not simply about identifying risks, but also assessing them, prioritizing them, and ensuring that leadership will have clear and ongoing visibility of not only the current exposure, but also emerging trends.”

Whereas the traditional approach to risk management includes periodic (often annual) assessments, today’s dynamic, fast-moving environment calls for a more agile and flexible approach. That’s where the concept of executive reports comes in.

Leadership regularly tracks several KPIs and KRIs, including emerging risks, risk control effectiveness, and opportunities, to ensure they operate with the overall risk appetite.

“It lays it all out really nicely for senior executives,” Hollis says. “Here are the risks…here are the controls…here’s what happens if we don’t implement them.”

At Wescom Financial, the culture of risk mindfulness doesn’t end at the senior-most levels. It’s ingrained throughout the organization and has become part of the daily vocabulary. As Thompson says, “The risk vernacular is second nature.”

The Credit Union has created a culture focused on transparency, accountability, and escalation if and when needed. This culture starts at the Board level and is actively communicated and reinforced throughout the organization.

“Employees at all levels understand their role in managing organizational risk,” Hollis says.

An Integrated, Strategic Framework for Success

A modern enterprise risk management program must answer one question: “How can we confidently pursue our strategic objectives?”

To achieve this ideal, focus on developing an ERM program that assesses each risk domain according to a consistent, repeatable process. Develop policies and processes that ensure everything is viewed through the lens of your institution’s overarching risk appetite. Then ingrain a culture of risk mindfulness and transparency throughout the organization, from the Board and senior management through to member-facing staff.

As Hollis says, “We view risk through an integrated framework that aligns strategic objectives with our risk appetite.”