Senior management ultimately owns the identification and mitigation of risk, but the recommendation for ERM can — and often does — come from other stakeholders, such as the full board of directors (board), the audit and/or risk committee, or internal