This is the fourth in a five-part series on enterprise risk management. The first two parts described the “what” and “why” of ERM—what it actually is and why companies are using it. And last month’s column provided some “nuts and bolts” examples of techniques companies are using to get optimum benefits from their ERM processes (see box below, right for prior columns).