Accendo Reliability

Your Reliability Engineering Professional Development Site

  • Home
  • About
    • Contributors
    • About Us
    • Colophon
    • Survey
  • Reliability.fm
  • Articles
    • CRE Preparation Notes
    • NoMTBF
    • on Leadership & Career
      • Advanced Engineering Culture
      • ASQR&R
      • Engineering Leadership
      • Managing in the 2000s
      • Product Development and Process Improvement
    • on Maintenance Reliability
      • Aasan Asset Management
      • AI & Predictive Maintenance
      • Asset Management in the Mining Industry
      • CMMS and Maintenance Management
      • CMMS and Reliability
      • Conscious Asset
      • EAM & CMMS
      • Everyday RCM
      • History of Maintenance Management
      • Life Cycle Asset Management
      • Maintenance and Reliability
      • Maintenance Management
      • Plant Maintenance
      • Process Plant Reliability Engineering
      • RCM Blitz®
      • ReliabilityXperience
      • Rob’s Reliability Project
      • The Intelligent Transformer Blog
      • The People Side of Maintenance
      • The Reliability Mindset
    • on Product Reliability
      • Accelerated Reliability
      • Achieving the Benefits of Reliability
      • Apex Ridge
      • Field Reliability Data Analysis
      • Metals Engineering and Product Reliability
      • Musings on Reliability and Maintenance Topics
      • Product Validation
      • Reliability by Design
      • Reliability Competence
      • Reliability Engineering Insights
      • Reliability in Emerging Technology
      • Reliability Knowledge
    • on Risk & Safety
      • CERM® Risk Insights
      • Equipment Risk and Reliability in Downhole Applications
      • Operational Risk Process Safety
    • on Systems Thinking
      • Communicating with FINESSE
      • The RCA
    • on Tools & Techniques
      • Big Data & Analytics
      • Experimental Design for NPD
      • Innovative Thinking in Reliability and Durability
      • Inside and Beyond HALT
      • Inside FMEA
      • Institute of Quality & Reliability
      • Integral Concepts
      • Learning from Failures
      • Progress in Field Reliability?
      • R for Engineering
      • Reliability Engineering Using Python
      • Reliability Reflections
      • Statistical Methods for Failure-Time Data
      • Testing 1 2 3
      • The Manufacturing Academy
  • eBooks
  • Resources
    • Accendo Authors
    • FMEA Resources
    • Glossary
    • Feed Forward Publications
    • Openings
    • Books
    • Webinar Sources
    • Podcasts
  • Courses
    • Your Courses
    • Live Courses
      • Introduction to Reliability Engineering & Accelerated Testings Course Landing Page
      • Advanced Accelerated Testing Course Landing Page
    • Integral Concepts Courses
      • Reliability Analysis Methods Course Landing Page
      • Applied Reliability Analysis Course Landing Page
      • Statistics, Hypothesis Testing, & Regression Modeling Course Landing Page
      • Measurement System Assessment Course Landing Page
      • SPC & Process Capability Course Landing Page
      • Design of Experiments Course Landing Page
    • The Manufacturing Academy Courses
      • An Introduction to Reliability Engineering
      • Reliability Engineering Statistics
      • An Introduction to Quality Engineering
      • Quality Engineering Statistics
      • FMEA in Practice
      • Process Capability Analysis course
      • Root Cause Analysis and the 8D Corrective Action Process course
      • Return on Investment online course
    • Industrial Metallurgist Courses
    • FMEA courses Powered by The Luminous Group
    • Foundations of RCM online course
    • Reliability Engineering for Heavy Industry
    • How to be an Online Student
    • Quondam Courses
  • Calendar
    • Call for Papers Listing
    • Upcoming Webinars
    • Webinar Calendar
  • Login
    • Member Home
  • Barringer Process Reliability Introduction Course Landing Page
  • Upcoming Live Events
You are here: Home / Articles / Enterprise Risk Management and Environmental Risk

by Greg Hutchins Leave a Comment

Enterprise Risk Management and Environmental Risk

Enterprise Risk Management and Environmental Risk

Guest Post by James Kline (first posted on CERM ® RISK INSIGHTS – reposted here with permission)

In CERM Risk Insights #354 I discussed the risk management study of local governments in New Zealand. One of the cases in the study was Environment Canterbury Regional Council. The regional council’s focus and the increasing concerns about environmental risks by both the public and private sector represents a challenge to the common approach used by most of the New Zealand local governments, ISO 31000:2018 and the International Organization for Standardization (ISO) more generally. This piece discusses this challenge to ISO 31000:2018 and its implications.

Environment Canterbury Regional Council

The purpose of the Environment Council is to set out objectives, policies, and methods to resolve resources management issues and to achieve an integrated management of the natural and physical resources of Canterbury.

The Environmental Council’s areas of responsibilities include:

  •             Air quality
  •             Biodiversity and biosecurity
  •             Freshwater management
  •             Climate change, hazards, risk, and resilience
  •             Transport and urban development

Under each of the areas, the Environment Council identifies service level targets. For instance, the 2019-20 Summary Annual Report notes that for Hazards Risk and Resilience, 21 of the 24 target levels were achieved. The interrelationship between the work of the Environment Council and environmental risk faced by local governments can be seen in the Waimakariri Flood Protection Project. The report indicates:

“In August 2019 we celebrated the completion of the 10-year $40 million Waimakariri     Flood Protection Project. Delivered ahead of schedule, it protects an estimated $8 billion of property and assets, and significantly improves the Greater Christchurch and     Waimakariri District’s resilience to a major flood event and climate change.” (1)

Climate change risk and mitigation is a major responsibility of the Environment Council. While the Council is specifically chartered to deal with environmental risks, such risks can impact any organization, public or private, at the operational level. This recognition has increased the interest in environmental risk identification and mitigation. Unfortunately, the growing concern about environmental risks creates a problem for ISO 31000:2018.

ISO 31000:2018 Environmental Risk Problem

The key problem for ISO 31000:2018 is that it does not specifically include environmental risks in the model. While there is nothing that precludes their inclusion, it simply does not focus on environmental risks. This is unlike the approach used by Committee of Sponsoring Organizations’ (COSO) ERM.

In 2018 COSO in conjunction with the World Business Council for Sustainable Development created a supplement to COSO ERM. The supplement is entitled “Enterprise Risk Management: Applying Enterprise Risk Management to Environmental, Social and Governance – related risks”. (2)

The supplement stresses the need for businesses to include Environmental, Social and Governance (ESG) risks in their Enterprise Risk Management (ERM) process and risk register. It also identifies ESG issues and themes an organization should consider. A short list is presented in Table 1 below.

While the list above is extensive, each organization can add or subtract as necessary for its specific circumstances. This makes COSO ERM ESG more competitive with respect to the growing environmental risk management concerns.

The lack of ESG risk in ISO 31000:2018 means that, if ISO 31000:2018 is to remain competitive and the dominate model, at least in the public sector, it will have to include ESG risks. The problem is that ISO has another model to which it recently added risk management. That is ISO 9001:2015, its quality management certification. The presence of the two creates a dilemma for ISO.

ISO Dilemma

The dilemma whether to add ESG to each or just one. ISO 31000 was updated in 2018. Thus, it is not scheduled for an update until 2023. ISO 9001, on the other hand, was scheduled for an update in 2021. The 2021 update has yet to occur. This is because two surveys of 9001 technical committee members recommended no update. Whether the recommendation will be adhered to is uncertain.

There is speculation that ISO corporate is not happy with the results. It badly wants to update 9001. The reason for this speculation is the fact that a second survey was conducted just months after the first. The motivating factor for wanting an update is money. It is believed ISO is not in a strong financial situation. Consequently, it can use the revenue from updating current publications.

Time will tell the veracity of the speculation. What is certain is that 31000 is a guide, while 9001 is a certification. ISO’s money maker is 9001. If, however, ISO moves 9001 further into the risk arena, particularly by adding ESG risks, it dilutes the quality management emphasis. This may cause many corporations to question whether continued ISO 9001 certification is necessary. Under a scenario where organizational and ESG risks are emphasized, poor quality management becomes just another risk corporations must deal with. Under such a scenario, why is 9001 certifications necessary?

With respect to ISO 31000, ISO could issue a ESG supplement. This would make 31000 more competitive with COSO ERM ESG. However, because 31000 is a guide and not a certification ISO will not make as much money. Waiting until 2023 to update ISO 31000 with ESG, means that ISO 31000:2018 will be less competitive in the interim. While ISO 31000:2018 does not make as much money as ISO 9001, as it becomes less competitive relative to COSO ERM ESG, its relevance and the accompanying revenue may decrease.

Conclusion

Concern with environmental related risks is increasing. This creates a problem for ISO. ISO has two risk-oriented models. One is the 31000:2018. It is a guide, which focuses on enterprise-wide risk management. The other is ISO 9001:2015. It is a quality management system certification. In 2015 ISO included risk management to the 9001. Neither 9001:2015 nor 31000 :2018 have environmental risk elements. This is unlike the COSO ERM ESG which has environmental risk elements.

The problem ISO faces is that 31000:2018 is not up for revision until 2023. ISO 9001:2015 is due for revision in 2021. Unfortunately, two recent surveys of ISO 9001 technical committees determined that no revision was necessary.

With the increasing concerns for environmental risks and their mitigation, ISO has a decision to make. That decision is whether to add ESG risks to one or both models. If they do not, then ISO 31000:2018 could be made obsolete by COSO ERM ESG. On the other hand, while adding ESG risks to 9001:2015 would be consistent with current concerns, it could make 9001:2015 less desirable as a certification. This is because a poor-quality management system would be just one of many enterprise-wide risks. Further, it is conceivable that management could decide that given the need to focus on environmental risks, a quality management certification, such as 9001:2015, is not necessary.

Endnotes

  1. Canterbury Regional Council, 2020, “Summary Annual Report 2019/20, page 8, https://www.ccan.govt.nz/get-involved/news-and-events/2020/council-adopts-2019/2020-annual-report
  2. COSO, 2018, “Enterprise Risk Management: Applying Enterprise Risk Management to Environmental, Social and Governance – related risks”, https://www.coso.org/Documents/COSO-WBCSD-ESGERM-Executive-Summary.pdf

Bio:

James J. Kline has a PhD from Portland State University. He has worked for federal, state, and local government. He has consulted on economic, quality and workforce development issues. He has authored numerous articles on quality and risk management. His book “Enterprise Risk Management in Government: Implementing ISO 31000:2018” is available on Amazon. He can be contacted on LinkedIn or jamesjk1236@outlook.com

Filed Under: Articles, CERM® Risk Insights, on Risk & Safety

About Greg Hutchins

Greg Hutchins PE CERM is the evangelist of Future of Quality: Risk®. He has been involved in quality since 1985 when he set up the first quality program in North America based on Mil Q 9858 for the natural gas industry. Mil Q became ISO 9001 in 1987

He is the author of more than 30 books. ISO 31000: ERM is the best-selling and highest-rated ISO risk book on Amazon (4.8 stars). Value Added Auditing (4th edition) is the first ISO risk-based auditing book.

« RCM is Not a Maintenance Program
Process Flowcharts for Better Business Performance »

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

CERM® Risk Insights series Article by Greg Hutchins, Editor and noted guest authors

Join Accendo

Receive information and updates about articles and many other resources offered by Accendo Reliability by becoming a member.

It’s free and only takes a minute.

Join Today

Recent Articles

  • Gremlins today
  • The Power of Vision in Leadership and Organizational Success
  • 3 Types of MTBF Stories
  • ALT: An in Depth Description
  • Project Email Economics

© 2025 FMS Reliability · Privacy Policy · Terms of Service · Cookies Policy