Enterprise Risk Management  Advisory

Cherry Hill Advisory helps organizations build enterprise risk programs that are practical, owned, and connected to the internal audit plan, so risk work informs decisions instead of filling a binder.

Most Risk Registers
Never Reach a Decision

Boards and audit committees are asking sharper questions about exposure that does not sit inside any one function. AI adoption, third-party dependencies, cybersecurity, supply chain concentration, and climate disclosure all cross departmental lines. The answers rarely come from a single owner.

Risk programs stall for structural reasons. The register lives in a spreadsheet one team maintains. Ownership is unclear at the moment a decision is needed. Appetite has never been stated, so nobody can say whether a given exposure is acceptable. The list gets refreshed annually and consulted rarely.

Cherry Hill Advisory helps organizations build and mature enterprise risk programs that are practical, integrated, and used in decision-making. We work alongside finance, risk, and internal audit leaders, then connect the program directly to the internal audit plan. The risks you rank become the risks that get assurance.

Our Enterprise Risk Management Services

Enterprise Risk Support for Finance, Risk, and Internal Audit Teams

ERM Framework Design

We design enterprise risk frameworks aligned to COSO and ISO 31000, built to your organization's scale, industry, and risk profile. The work runs from initial design through board-ready reporting, and leaves a structure your team can maintain after we step back.

Risk Appetite and Tolerance

Risk appetite statements, tolerance thresholds, and executive dashboards that make risk conversations concrete at the board level. Appetite is what turns a list of exposures into a decision. It defines what the organization is willing to accept before the question arrives.

Risk Register and Heat Maps

We build and maintain enterprise risk registers with visual heat maps, named risk owners, and treatment plans for every entry. Each register is structured so it feeds audit planning rather than sitting beside it.

Internal Audit and ERM Integration

We link the enterprise risk assessment directly to the internal audit plan, so audit resources are deployed where risk is highest. This is the connection most programs never make, and it is the one former Chief Audit Executives are built to make.

Third-Party Risk Management

Vendor risk programs, contract review frameworks, and continuous monitoring for supply chain and third-party exposure. We align these programs to the IIA Third-Party Topical Requirement, so the work supports conformance as well as coverage.

Risk Workshops and Facilitation

Executive facilitation sessions that surface exposure before it materializes. Interactive, focused, and grounded in your business rather than a generic risk taxonomy. Sessions are run by practitioners who have presented risk to audit committees themselves.

ERM Maturity Assessment

We assess where your enterprise risk program sits today and what the next stage of maturity requires. The output is a practical roadmap covering governance, methodology, reporting, and the integration points with internal audit.

Risk assessment and audit planning

Two Exercises, and Most Organizations
Run Them Separately

The risk assessment names the exposure. The audit plan decides where assurance goes. When they are built by different people in different quarters, the plan covers what it covered last year.

01 Exercise one

The enterprise risk assessment

Run by risk or finance. It produces a register, named owners, and a heat map, and it answers what could stop the organization meeting its objectives.

Where it fails: the output stays a list rather than a ranking anyone has agreed to act on, because appetite was never stated.

02 Exercise two

The internal audit plan

Run by internal audit. It decides where testing and assurance go this year, and it answers where independent evidence is needed most.

Where it fails: the plan gets built from last year's plan, the auditable entity universe, and whoever asked loudest, rather than from the register.

What connecting them changes

The register stops being an annual artifact and starts deciding where assurance actually goes.

Audit coverage is defensible to the audit committee because it traces to a ranked risk, not to a rotation schedule
Ranked risks carrying no assurance become visible, which is the gap view boards ask for and rarely get
The register gets used, and a register that gets used is a register that gets maintained
Exposure that appears mid-year has a route into the plan without waiting for the next annual cycle
Third-party and technology risk stop being exposures that nobody owns
FRAMEWORKS AND STANDARDS

Enterprise Risk Programs Built on Recognized Frameworks

Cherry Hill Advisory aligns enterprise risk programs to recognized frameworks and professional standards. Our approach keeps the methodology defensible to a board or an external assessor while remaining practical for finance, risk, and internal audit teams to run.

We work with organizations to align enterprise risk activity with established governance, risk, and control frameworks, including:

  • Enterprise risk frameworks designed against COSO Enterprise Risk Management and ISO 31000
  • Internal control alignment under COSO 2013 where the risk program touches financial reporting
  • Risk assessment methodology aligned to the 2024 Global Internal Audit Standards for functions that rely on it for audit planning
  • Third-party risk programs aligned to the IIA Third-Party Topical Requirement, and integration of enterprise risk activity with internal audit plans and governance oversight
Why Cherry Hill?

Big 4 Expertise. Boutique Delivery.

Many advisory firms bring rigid methodologies and layered reporting structures. That model does not always fit internal audit environments that require agility and discretion.

Cherry Hill adopts a white-glove service model that combines Big 4 experience with boutique attention. We integrate directly with internal teams. We move with tech-enabled speed, and communicate clearly with stakeholders at every level.

Senior professionals lead every engagement. There is no bait-and-switch model. There is no unnecessary overhead.
 We are brought in to solve problems, not create them.

Risk work that lands in the audit plan

Cherry Hill runs both sides. The risk assessment and the audit plan are built by the same practitioners, so the connection is structural rather than a handoff between two vendors.

Former Chief Audit Executives in the room

Our team have run internal audit functions and presented risk to audit committees. The practitioner facilitating your risk workshop has sat on the other side of that table.

A bench, added when a topic comes into scope

Discipline leads across SOX and internal controls, IT audit, cyber, fraud, third-party risk, AI governance, and privacy.

IIA Authorized Licensee and NASBA-accredited CPE provider.

The practitioners who scope your engagement are the practitioners who execute it.

Enterprise Risk Management Questions, Answered

What is the difference between enterprise risk management and internal audit?

Enterprise risk management is a management activity. It identifies, ranks, and treats the exposures that could stop the organization meeting its objectives, and it is owned by management. Internal audit is an independent assurance activity. It tests whether the controls management relies on are actually working. The two are separate by design, and they should still be connected, because the risk assessment is what tells internal audit where assurance is worth the most.

What is a risk appetite statement and does our board need one?

A risk appetite statement says how much of a given exposure the organization is willing to accept in pursuit of its objectives, set before a specific decision is on the table. Without one, a risk register is a list rather than a ranking, because there is no agreed line between acceptable and unacceptable. Boards are not required to adopt one, and most find that risk conversations get concrete only once they do.

How often should an enterprise risk assessment be refreshed?

An annual refresh tied to planning is the common baseline. In practice, an annual cycle alone means exposure that appears in month three waits nine months for a route into the plan. Most organizations are better served by an annual full refresh plus a lighter quarterly review, with a defined trigger for reassessing when conditions change materially.

What is the difference between a risk register and a heat map?

The register is the record. It holds each risk, its owner, its rating, the controls in place, and the treatment plan. The heat map is a view of that record, plotting risks by impact and likelihood so the relative position is visible at a glance. The heat map is what gets presented. The register is what does the work.

Do we need ERM if we already have a SOX program?

They cover different ground. A SOX program addresses risks to financial reporting and the controls that mitigate them. Enterprise risk management covers the full set of exposures that could affect strategy and operations, including many that never touch the financial statements. A mature SOX program is useful groundwork, because the control documentation and the risk assessment discipline already exist.

Who should own enterprise risk management without a Chief Risk Officer?

Most organizations without a Chief Risk Officer place the program with the CFO or the General Counsel, with individual risks owned by the executive closest to each one. Internal audit can facilitate the process and should not own it, because owning the risk assessment compromises the independence that makes its assurance worth anything. Where there is no internal audit function, an outside facilitator preserves the same separation.

How does enterprise risk management connect to the internal audit plan?

The connection runs through the ranking. Each risk in the register is mapped to the assurance currently covering it, whether that is internal audit, a second-line function, an external assessor, or nothing. Audit effort then goes where the risk is highest and the existing coverage is thinnest. The output boards ask for most often is the gap view: ranked risks that no line of assurance is currently testing.

What frameworks does an ERM program follow?

COSO Enterprise Risk Management and ISO 31000 are the two in general use. COSO ties risk to strategy and performance and is the more common choice in US public companies. ISO 31000 is a lighter, principles-based standard that adapts well to organizations without a large risk function. Either is defensible, and the framework matters less than whether the program is actually used.

How do you decide which risks deserve the most attention?

Risks are positioned by impact and likelihood. High impact combined with high likelihood takes priority and earns sustained mitigation. High impact with low likelihood calls for contingency planning and risk transfer where it is available. High likelihood with low impact is a process problem rather than an attention problem. The value of the exercise is the conversation it forces between the board and management about where resources go.

How is an enterprise risk engagement scoped and priced?

Scope depends on the size of the organization, the number of entities and locations in play, and how much of a program already exists. A first framework build is a different engagement from a refresh of a register that has drifted. We develop the scope with you rather than quote a figure before understanding the environment. Fixed-fee and time-and-materials structures are both available.

ConnectYour Risk Program to the Work That Follows It

If your organization needs to build an enterprise risk program, refresh one that has drifted, or connect the risk assessment to the internal audit plan, Cherry Hill Advisory can help you put a structure in place that senior leadership will actually use.

Get In Touch

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Explore Our Internal Audit Services

Internal Audit Co-Sourcing

External Quality Assessments (EQA)

Fraud Risk and Investigations

Sarbanes-Oxley (SOX) Compliance & Advisory

AI Governance & Emerging Risk

Cybersecurity and Technology Risk

Thought 
Leadership

Tech Product Roadmap And Advisory

IT & Cybersecurity Expert Witness