Hello Mae-Yu- this is a complex subject governed by the needs of the board. In simple terms, you should be concerned that the following elements in ERM are in place: Education- of directors and executive team; Process-specifically that Management is following steps in risk for: identification; assessment; control and mitigate risks; monitoring; reporting; Governance- that structures are in place for board and executive team, roles in risk defined, and an ERM Policy in place; Board Oversight- briefly, 5 steps: correct structure and correct committee chosen; governance best practices followed; Risk Appetite set; Risks aligned with Objectives; Risk Culture established; Strategy- proper processes in place in strategy setting. I can delve further into these areas as you wish, a current paper I'm writing will outline these items in full. Steve