Risk management · Vocabulary · Method

GRC, ERM, IRM, ORM: making sense of the acronyms

ERM, IRM, ORM, TPRM, SRM, Connected Risk: risk management produces acronyms at a steady pace. Some designate distinct realities, while others rebrand existing concepts. Knowing how to tell them apart prevents you from initiating a methodological overhaul where a simple vocabulary change is all that is at stake.

Category: Risk management Reading time: 8 minutes

Acronyms rarely emerge by chance. They most often stem from three sources: consultancy firms seeking to differentiate an offering; software vendors structuring a market around a category; and analysts naming segments to compare them. Each has valid reasons for coining a term — but the organisation receiving them must decide: is this a genuinely new concept, or merely a rebranding?

ERM

The baseline: enterprise-wide risk management

IRM · Connected Risk

Variations that bring nuances, not breaks

ORM · TPRM · SRM

Thematic variations of the same discipline

01

Why this proliferation

The question is not theoretical. Adopting new vocabulary often leads to rewriting a policy, reconfiguring a tool, or retraining teams. These are efforts that are justified if the substance changes; costly and demotivating if not.

02

ERM: the benchmark

Enterprise risk management (Enterprise Risk Management, ERM) refers to a structured and cross-functional approach: identifying, assessing and managing the risks likely to affect the achievement of the organisation's objectives, by integrating this perspective into decision-making, from strategy to operations.

Two characteristics define it. It is linked to the objectives — a risk only exists in relation to what the organisation is trying to achieve. And it is cross-curricular — it aims for an overview, not the addition of local concerns. It is the benchmark concept, and it has not been rendered obsolete by its announced successors.

03

MRI and Connected Risk: nuances rather than breaks

Integrated risk managementIntegrated Risk Management, IRM) presents itself as a holistic approach, covering all functions and levels, as opposed to siloed management. Upon reading, the difference from properly implemented ERM is subtle: ERM already laid claim to this cross-functional nature. IRM is distinguished above all by its insistence on tooling and technological integration.

The Connected Risk bring a more specific and genuinely useful idea: risks are not isolated, they influence one another, with systemic and cascading effects. An IT failure triggers an operational risk, which becomes regulatory, then reputational.

An often forgotten dimension: the risks are not just interconnected — their treatments compete with each other. Resources allocated to managing a risk are not available elsewhere. Balancing this competing demand is an exercise in governance, which is rarely formalised.

Does this idea deserve a separate repository? That is debatable. It does, however, deserve to be integrated into any serious mapping.

When the method is clear, the tool can then play its part: connecting what often remains scattered. Risk mappings, controls, obligations, incidents and action plans can be monitored in a common environment without imposing a new vocabulary on the organisation for each risk domain.

04

ORM, TPRM, SRM: thematic variations

A second family of acronyms refers not to competing methods, but to fields of application:

  • ORM (Operational Risk Management) — risks relating to processes, people, systems and external events.
  • TPRM (Third Party Risk Management) — risks relating to service providers and the supply chain.
  • SRM (Strategic Risk Management) — the risks weighing on strategic choices and the business model.
  • Added to these are credit risk, cyber risk, project risk, and others still.

These fields legitimately benefit from dedicated attention, and sometimes from specific frameworks and tools — the regulations themselves require this breakdown on certain subjects. The danger arises when this specialisation becomes a silo: each field assesses its scope according to its own scale, and no one consolidates.

05

The test that really counts

Rather than settling a vocabulary debate, it is better to evaluate the scheme by its results. Three questions suffice:

  • Is there an acceptable probability of achieving our goals, given the risks involved?
  • Are our decisions informed — do decision-makers have useful information about risks at the time they decide?
  • Are we taking the right level of the right risks, in line with the board's guidance?

A device that answers these three questions correctly is effective, regardless of the acronym on the cover of the policy. A device that does not answer them will not be saved by a change of name.

06

What terminology for a regulated Luxembourg entity?

The answer here is simpler than elsewhere: the reference vocabulary is that of the applicable regulatory framework, not that of market offers. The Commission de Surveillance du Secteur Financier (CSSF) and European texts refer to risk management, the risk management function, the internal control framework, and internal governance. It is these concepts that a supervisor will examine, and in these terms that the consistency of the framework must be demonstrated.

Nothing prevents using a tool positioned on the MRI segment, nor taking inspiration from the logic of the Connected Risk. However, internal policy, mapping and regulatory reporting benefit from sticking to the official terminology — and explaining, where appropriate, how it corresponds to the vocabulary of the chosen tool.

Point of vigilance: when a redesign project is presented as the transition from one model to another, ask how the decisions made, the risks monitored and the information passed on to the board will actually change. If the answer is vague, it is probably just a change in vocabulary.
07

The ARCAD approach

ARCAD reasons on the basis of the organisation's objectives, risks and obligations, and then adopts the vocabulary that serves clarity — that of the framework applicable as a priority. The value of a mechanism does not lie in the reference framework invoked, but in its ability to inform decisions and withstand scrutiny by a supervisor.

Clarify your risk management framework.

ARCAD helps to distinguish between matters of method and matters of vocabulary, and to align the mechanism with the applicable framework.

Schedule an exchange →

References & further reading

  • OCEG works (Open Compliance and Ethics Group) on GRC capabilities.
  • Enterprise risk management frameworks (COSO ERM, ISO 31000).
  • Internal governance framework and risk management requirements applicable to entities regulated by the CSSF.

Note: Good practice to be adapted to the profile, size and regulatory framework specific to each organisation.