Beyond the Risk Register: An ERM Playbook for CFO Decision-Making

Alexis Brubaker – Chief Compliance & Privacy Officer, Cornell University

Jake Braunsdorf – Senior Manager, Deloitte


Chief Financial Officers are being asked to make faster, higher-stakes decisions amid cyber threats, regulatory volatility, persistent enrollment and financial pressures. This session translates a research-backed approach into practical steps for strengthening Enterprise Risk Management (ERM) so it reliably improves governance and resource allocation—not just compliance.

We’ll show how applying risk processes consistently across units and tying them to how leaders actually allocate attention and funds makes ERM actionable at the cabinet and board levels.

Participants will learn how simple statistical techniques (e.g., structured scoring, ranges, and basic normalization) can reduce overreliance on anecdote, surface hidden assumptions, and improve comparability of risks across departments and over time—enabling more confident prioritization of limited mitigation resources.

We’ll connect these methods to today’s most disruptive higher-ed risks and illustrate how a measurable, current, and adaptable ERM program becomes an operational capability that protects people, resources, and reputation while advancing teaching, research, and service.

Learning Objectives

  • Describe how consistent Enterprise Risk Management (ERM) processes strengthen governance and improve resource allocation decisions across units.
  • Demonstrate how basic statistical techniques (e.g., structured scoring, ranges, normalization) make risk assumptions explicit and improve comparability across departments and over time.
  • Conduct a risk calibration and prioritization exercise for a disruptive higher-ed risk (cyber, regulatory, or enrollment/financial), and justify mitigation selections within constrained resources.

CPE Available

  • 1 Credit: Management Services