Few questions in a board meeting are as common and as difficult to answer as “what is, in fact, our exposure to risks?”. Knowing how to calculate ERM is what turns that question into a defensible number, comparable across areas and Connected to the strategy.
This article presents the method in stages, the indicators that provide executive reading of the result, and the ERM framework that organizes the entire process.
The approach is didactic but not simplistic: calculating ERM requires deciding what to measure, with what criteria and for what decision.
What does calculating ERM mean?
Calculating ERM means quantifying, in a consistent manner, the organization’s exposure to risks that affect its strategic objectives. In practice, It combines the probability and impact of each risk, The result is adjusted for the effectiveness of controls and the exposure to risk defined by senior management and the board is compared.
Actio’s Enterprise Risk Management, known in Brazil as corporate risk management (ERM), is not a single indicator, but a discipline that it integrates risks into the strategy and to performance.
Why there is no single formula
The COSO framework organizes the discipline into five interrelated components and 20 principles, applicable to organizations of any size or sector. The model is based on principles: defines what good risk management should achieve, without imposing an equation.
The ISO 31000:2018 There is a similar logic. It proposes a comprehensive approach to identifying, analyzing, evaluating, treating, monitoring, and communicating risks, and the standard is not prescriptive. The choice of metrics therefore falls to the company itself.
Exposition, appetite and tolerance
Before calculating, align four concepts that are often confused:
- Intrinsic exposure: risk level before any control.
- Residual exposure: level of risk after the action of the existing controls.
- Risk appetite: the amount of risk the organization accepts in its pursuit of its objectives.
- Tolerance: acceptable deviation around appetite, usually expressed in numerical limits.
How to calculate ERM in practice
To calculate ERM, first map and classify the relevant risks; then estimate probability and financial impact; calculate the inherent and residual exposure, taking into account the effectiveness of controls; finally, compare the consolidated total to the risk appetite and prioritize responses. Repeat the cycle every quarter.
Each stage depends on the previous one. The rigor of the latter only exists if the first ones were well executed.
Step 1: Map and classify the risks
Not all risks are calculated in the same way. In an article published in Harvard Business Review, Robert Kaplan and Anette Mikes distinguish avoidable risks, strategy risks and external risks, each category having its own management logic.
Expected losses work well for avoidable risks, As operational failures. Strategy risks require analysis of the return sought, and external risks require scenario analysis. A good risk mapping avoid applying the same rule to different natures.
Stage 2: estimating probability and impact
When deciding how to calculate ERM for each risk, there are three levels of sophistication, which can coexist in the same portfolio:
| Approach | How it is calculated | When to use |
| Qualitative | Scales from 1 to 5; score = probability × impact | Initial screening of many risks |
| Semi-quantitative | Probability bands (%) and impact (R$) | Prioritization and reporting to the board |
| Quantitative | Expected loss and Monte Carlo simulation | Critical risks and capital decisions |
Early-stage companies usually start with the 4×4 risk matrix or with a risk matrix in Excel. Real gain comes from migrating critical risks to monetary values.
Step 3: Calculate the inherent and residual exposure
Understanding how to calculate ERM in practice becomes simpler with numbers. With annual probability and impact in reais, the formulas are straightforward:
- Intrinsic exhibition = probability × impact
- Residual exposure = inherent exposure × (1 − effectiveness of controls)
The following table provides an illustrative example, with hypothetical values, for a fictitious company:
| Risk | Prob. annual | Impact (R$ mi) | Intrinsic exposure (R$ mi) | Effectiveness of controls | Residual exposure (R$ mi) |
| Critical supplier failure | 20% | 15 | 3,0 | 40% | 1,8 |
| Cyber incident | 10% | 30 | 3,0 | 50% | 1,5 |
| Regulatory fine | 5% | 20 | 1,0 | 70% | 0,3 |
| Loss of key talent | 30% | 4 | 1,2 | 25% | 0,9 |
| Total | 8,2 | 4,5 |
The simple sum assumes that the risks are independent, which rarely happens. To capture correlations and tail events, critical risks require simulation and modeling, a field in which data science and AI they broaden the analytical capacity.
Step 4: compare with appetite and prioritize
Suppose the board has set the appetite at R$ 4 million in annual residual exposure. In the example, the total of R$ 4.5 million exceeds the limit by R$ 0.5 million, which triggers response plans.
Critical and incident suppliers concentrate about 73% of the residual exposure and should lead the prioritization. The response can avoid, mitigate, transfer or accept the risk. One Risk management policy well-drawn defines beforehand who decides in each exposure range.
Key indicators for calculating the ERM
Defining how to calculate ERM is not enough, because a single value of exposure provides little information. The advice needs indicators that show trend, appetite adherence and the quality of controls.
| Indicator | How to calculate | What it reveals |
| Total residual exposure | Σ (probability × impact × (1 − effectiveness)) | The liquid risk to which the company is exposed |
| Attraction to appetite | Residual exposure ÷ appetite limit | Excess or excess in front of the limit (above 100% = out of range) |
| Covering controls | Critical risks with tested control ÷ critical risks | Robustness of the response |
| KRIs on alert | KRIs outside the range ÷ total KRIs | Precedent sign of deterioration |
| Actual vs. projected losses | Lost funds ÷ expected loss | Calibration of the calculation model |
For Kaplan and Norton, indicators only fulfill their role when they translate strategy into measurable goals. The same applies to risk.: the Key risk indicators (KRIs) they should be integrated into the strategic panel, not a parallel report.
The comparison between actual and projected losses depends on good historical records. Therefore, treating Operational losses in a structured way, it is a direct input for calibrating probabilities and impacts.
ERM framework: where calculation fits in
How to calculate ERM without a reference framework? The result are orphaned numbers. The ERM framework defines governance, appetite, responsibilities, and review cadence, which give meaning to the metrics.
| Criterion | COSO ERM (2017) | ISO 31000 (2018) |
| Structure | Five components and 20 principles | Principles, structure and process |
| Focus | Integrating risk into strategy and performance | Common approach to any type of risk and organization |
| Where calculation comes in | Performance component: identify, evaluate, respond to, and report | Evaluation process: identification, analysis and evaluation |
| Nature | Market reference for corporate risk management | International standard of guidelines |
Anyone starting from scratch can follow the roadmap to structure a risk management program. To formalize adherence to the standard, it is worth knowing the path from the beginning to the end. ISO 31000 certification.
The same framework supports integration with the ESG agenda, a topic addressed in the content about ESG software.
Benefits of corporate risk management when ERM is quantified
Quantification transforms the ERM into a decision-making instrument. The main benefits of corporate risk management become apparent when the number reaches the executive committee:
- Priority by value: Control resources go to where residual exposure is highest.
- Financial dialogue with the board: Risks are now discussed in the same language as budgets and targets.
- Stronger capital decisions: investments and hiring incorporate the expected cost of risk.
- Anticipation Previous indicators signal deterioration before the loss.
The January 2025 Resilience Pulse Check from the World Economic Forum and McKinsey indicates that 55% of the organizations expect relevant or severe disruption caused by technology, according to the report. Global research by McKinsey about productivity at risk.
As early as June 2025, the McKinsey on Risk & Resilience It reinforces that CROs and risk professionals, along with senior leadership and boards, treat the understanding and mitigation of risks as a prerequisite for success.
Common errors that distort the calculation of ERM
Even with the method, some deviations compromise the result. Some of them are:
- Treat risk as compliance. Kaplan and Mikes warn that management based solely on rules does not reduce the probability or the impact of major disasters.
- Using scales without calibration. A “level 4” means different things in each area; anchor the bands in percentages and real numbers.
- Adding risks without considering correlation. Events that feed on each other underestimate the aggregate exposure.
- Ignoring rare, high-impact events. Low probability does not mean low relevance.
- Keep spreadsheets separate. Without a history, responsibility, and a plan of action, the number loses its decisive value.
How to calculate ERM continuously with technology
Repeating the cycle every quarter with disconnected spreadsheets consumes time and fragmentates the information. O Actio Risk Management It centralizes risks, matrices, control tests, mitigation plans, and operational losses in a single environment, aligned with the ISO 31000, COSO, and PMI references.
With Actio IA, the platform is even more advanced automatically detects risks and gaps of performance. By linking risks to strategic objectives and indicators, the manager no longer treats them as a separate report.
Logic dialogues with the importance of the integrated management system, In which strategy, risks and processes operate as a single cycle.
For managers of medium and large companies, the next step is to choose the framework, calibrate the scales and give technology to the process.
Meet the Actio Corporate Risk Management (ERM) and schedule a free demo with one of our specialists.
