Introduction
The U.S. market today is increasingly composed of large, multi-entity organizations – those with several subsidiaries, legal entities or decentralized operating units such as private equity firms, hospital systems or higher education systems. Managing risk in today’s complex world is difficult, at best, however these multi-entity organizations face the unique challenge of managing risk across the vast enterprise. The myriads of risks across these large, diverse entities can threaten financial stability, damage reputation, disrupt operations and hinder successful scaling and growth. The need for consistent and effective risk management has never been more critical.
Enterprise risk management (ERM) as a discipline has been widely known to enable organizations to generate consistent risk intelligence across business units and operating entities. When executed in alignment with recognized frameworks—such as COSO[1] and ISO 31000[2] — standardization improves strategic alignment, transparency and comparability of risk information, while strengthening governance and overall performance.

Unbox your potential with strategic risk management
ERM in the Box™, Baker Tilly’s proprietary platform, is designed exclusively for large, multi-entity organizations, enabling ERM programs to build at scale and drive operational excellence, growth and transformation.
The unique challenge
By nature, large diverse organizations tend to be siloed and autonomous, while still aligning with the parent for funding, guidance or other unique benefits. This diversity introduces added complexity in understanding risks across entities, making it more challenging to drive operational efficiencies, maximize value and minimize volatility or the potential impact of those risks.
While ERM provides risk intelligence and drives value, many large, multi-entity organizations don’t have a standardized ERM methodology across their diverse entities. These organizations frequently struggle with operationalizing ERM, viewing it as bureaucratic, complex or a compliance exercise rather than a strategic tool. Some key challenges for large, complex organizations implementing a comprehensive ERM program include:
- Competing priorities and budget limitations: ERM is resource-intensive, requiring investment in personnel and technology. Other operational priorities often take precedence, particularly when the immediate, tangible ROI of ERM is difficult to measure.
- Lack of leadership alignment: There is often an inconsistent understanding among entity leadership regarding ERM’s purpose – whether as a compliance exercise or a strategic tool – and regional leaders may perceive it as corporate oversight rather than a value-adding function.
- Unclear risk ownership: Confusion over first-, second- and third-line responsibilities, along with overlapping roles between global, regional and local functions, can lead to inefficiencies and gaps in accountability.
- Perception as bureaucracy: ERM is frequently viewed as an "academic" or "paper-pushing" exercise that adds unnecessary paperwork rather than practical value.
- Inconsistent risk appetite: It is difficult to define a unified global risk appetite when markets have different volatility, regulations and growth strategies.
- Cultural resistance and silos: Organizations with multiple entities often operate in silos, making a cohesive, enterprise-wide approach difficult. A "risk-aware" culture is hard to establish, especially if there is a fear of reporting negative information.
- Cumbersome and fragmented systems: Many organizations rely on disjointed, manual processes and spreadsheet-based systems that make aggregating, analyzing and reporting on risk data across different departments difficult and time intensive, often requiring weeks to implement every quarter.
At its core, ERM in dispersed organizations falls short when it becomes a reporting exercise rather than a tool for decision support. The biggest challenge is shifting from simply collecting risks across entities to empowering leadership to make more informed strategic decisions using risk intelligence.
The case for uniformity and a standardized ERM approach
Implementing a standardized ERM approach across the entities of a diverse organization can help protect value and capital by identifying risks early, mitigating threats to investments and reducing the costs associated with crises and other disruptive events. By standardizing how risks are captured and evaluated, organizations can enhance strategic decision-making at both the entity and parent levels. A consistent ERM structure provides clearer visibility into operational risks, empowering leaders to make more informed, risk-aware decisions that support efficient resource allocation, sustainable growth and long-term stability across the enterprise.
In addition, implementing a uniform ERM framework strengthens governance and oversight by promoting disciplined, repeatable processes for identifying, prioritizing, managing, reporting and mitigating risks across all entities. This integrated approach provides higher quality, comparable risk information that benefits both entity leadership and the parent organization. A few examples of how ERM approaches are standardized across industries with large, diverse organizations are provided below.
Industry illustrations for standardizing ERM across diverse entities
Private equity
Adoption of standardized processes, reporting templates and taxonomies reduces bespoke requests and enhances comparability across funds and portfolio companies. The Institutional Limited Partners Association (ILPA) recently introduced a new performance template with updates explicitly aimed at improving investor transparency and consistency in private equity reporting practices. Adoption of a standardized ERM approach can go a long way to aligning to the templates, and thereby positioning firms as having more attractive, forward-thinking management, appealing to today’s sophisticated investors.[3]
Hospital systems
An optimal approach in today’s healthcare environment of increasing uncertainty, complexity and continuous change is to adopt a comprehensive ERM program that considers all aspects of risk across the entire organization and to monitor and address emerging risks before they become significant events.[4] ERM can help to aggregate patient safety risks across hospitals and detect patterns that may not be visible at a single facility. Enterprise-level insight allows leadership to implement coordinated corrective actions and reduce overall exposure.
Higher education
A university system implementing ERM can identify systemic risks such as declining enrollment trends or cybersecurity vulnerabilities affecting multiple campuses using a standardized methodology. By addressing these risks collectively, leadership can allocate resources more effectively and avoid duplication of effort.
A new tool designed to standardize ERM across diverse entities
Baker Tilly ERM professionals have worked with a number of organizations with this unique challenge and developed a tool to assist large, diverse organizations in standardizing ERM. Our proprietary Baker Tilly platform, ERM in the Box™, is designed exclusively for these organization types, enabling ERM programs to build at scale and drive operational excellence, growth and transformation.
ERM in the Box provides tools and templates to help diverse organizations independently and consistently identify and prioritize top risks, as well as implement and evaluate risk management efforts on an ongoing basis. The platform delivers a complete toolkit with step-by-step guidance designed to help the user effectively execute an ERM program, along with support options for evolving needs and program maturity. Each step is supported by a combination of brief videos, instructional resources and program templates.
How ERM in the Box assists multi-entity organizations
ERM in the Box can help organizations establish a standardized risk taxonomy and scoring methodology. This ensures that risks identified at individual campuses or hospitals are evaluated using consistent criteria, enabling meaningful aggregation and comparison at the system level. The tool also provides templates to help establish effective governance and program oversight, including documenting and clarifying roles and responsibilities across the first-, second- and third-lines[5]. This reduces ambiguity regarding risk ownership and fosters accountability across entities. In addition, ERM in the Box includes practical implementation guides, risk registers, reporting templates and facilitation materials. These resources reduce the administrative burden on individual entities and accelerate adoption by providing structured processes rather than abstract guidance.
ERM in the Box supports organizations by:
- Having leadership set a targeted maturity level of ERM for each company or entity, driving buy-in from executives and risk awareness across the entities’ levels of management.
- Enabling self-service ERM execution for boards, senior leaders and management across a set of large, diverse organizations helping to minimize the perception of bureaucratic exercise.
- Providing education and continuous learning as a core function of the platform to develop a shared culture of risk across silos.
- Achieving cost effectiveness with a pre-designed tool to implement ERM across diverse entities with reasonable pricing and effort that is not resource intensive.
The goal of the ERM in the Box platform is to quickly and easily enable a common methodology and taxonomy, supported by tools and templates, to drive cross‑entity risk information. This in turn can improve an organization’s operational resilience by better anticipating, withstanding and adapting to risks, opportunities and other potential uncertainties. A standardized ERM platform also supports cultural maturity across the entities by embedding common practices, roles and accountabilities.
Recommendations for large, diverse organizations
- Adopt a standardized risk management methodology anchored to recognized frameworks (COSO/ISO)
- Establish expectations from the parent organization along with clear accountability, governance and reporting cadence to which the entities can execute
- Leverage Baker Tilly’s proprietary ERM in the Box platform to quickly and efficiently enable consistent ERM processes and a common taxonomy while leveraging leading practice templates to facilitate the roll-out across multiple entities
Conclusion
Standardized, repeatable enterprise risk management is a strategic capability for large, diverse organizations in today’s ever-changing world. It enables comparability, strengthens governance and elevates enterprise‑level insight across complex, multi‑entity organizations. A standardized ERM methodology also improves operational resilience by enabling large, diverse organizations to better anticipate, withstand and adapt to disruptions, ultimately supporting a stronger, more cohesive enterprise.
Connect with us
Baker Tilly’s enterprise risk management professionals deliver value by aligning strategy, risk and compliance.


[1] Committee of Sponsoring Organizations of the Treadway Commission (COSO). (2017). Enterprise Risk Management—Integrating with Strategy and Performance.
[2] International Organization for Standardization (ISO). (2018). ISO 31000:2018 Risk Management—Guidelines.
[3] ILPA/BDO (2025). Preparing for Q1 2026: The New Era of ILPA Reporting and Performance Templates.
[4] HFMA (2018/updated 2025). Building an ERM Framework for Value‑Focused Health Care.
[5] The Institute of Internal Auditors (IIA). (2020/updated 2024). The IIA’s Three Lines Model.

