ERM: the global standard for managing uncertainty
Enterprise risk management is the discipline organizations everywhere use to manage uncertainty. Jigsaw applies it to sexual abuse risk. This page explains what that means and why it matters.
What ERM is
ERM defines risk as ’the effect of uncertainty on objectives.’ Everything else follows from that. An organization decides what it’s here to do, identifies the uncertainties that could affect that (positively and negatively), builds controls to manage them, and checks whether those controls are working. Then it keeps doing it, because the organization and its risks keep changing.
That is a different starting point from a checklist, which asks whether required things are in place. ERM asks whether the things that could stop you from achieving your objectives are being managed, and how you know.
Why it fits sexual abuse risk
Sexual abuse risk is uncertainty at every level. Which situations create opportunity. Which controls have quietly stopped working. Whether something that feels off is something or nothing. When to say something, and to whom. None of these have fixed answers; they shift with programs, people, and time.
That is exactly the kind of risk ERM was built for: risk shaped by human behavior and judgment, and by the gap between what an organization intends and what actually happens. Every other high-risk field adopted it for that reason. Instead, up to now, sexual abuse risk has had a toolkit of required controls. The tools stay; ERM is how they’re managed.
What ERM gives you
Objectives. What is your organization here to do, and what does success look like? Protection is part of the answer, along with your mission, programs, and your future. Managing sexual abuse risk well serves them all.
Uncertainties. Where could things go wrong? Where are the gaps between intention and outcome? When or where might sexual abuse be more likely? If sexual abuse risk were demonstrably managed well, what might that gain you? How might sexual abuse create an existential threat?
Controls. What specific measures manage these uncertainties, and who owns each one?
Monitoring. Is each control working now, in practice? Checked on a rhythm rather than at audit time.
Reviewing. Is this still the right control? Asked on a schedule, because the organization changes.
New uncertainties. We can’t expect to identify every uncertainty the first time we look, and new ones will keep emerging. Are we seeing and addressing new uncertainties as they arise?
Measurement. Is the whole protection system working? One question, answered from the record the work leaves behind.
The cycle feeds itself. What monitoring finds changes what you review. What review finds changes what you build next. That is what makes a protection system improvable rather than merely present: an organization can have dozens of policies in place and no way of knowing whether any of them is doing its job.
What it does for the organization
Organizations that manage uncertainty well achieve their objectives more often. They make better decisions under pressure and adapt faster when things change. And they can explain themselves: to a board, a parent, a regulator, or a court, every control has a reason, an owner, and a record. That is what makes risk management defensible, and it is why the work is worth sustaining. It serves the mission instead of sitting beside it or even in conflict with it.
ISO 31000
Jigsaw’s system aligns with the principles of ISO 31000, the global standard for risk management: integrated, structured, customized, inclusive, dynamic, based on the best available information, attentive to human and cultural factors, and committed to continual improvement. That matters because it means the system is built on the same framework boards, insurers, and regulators already recognize, rather than a proprietary method.
How the system measures itself
The Governance Maturity Rating (GMR) is a letter grade, A+ to NR, computed continuously from what the system records: monitoring coverage, review coverage, rhythm, and responsiveness, with emergence as a modifier. It tells an organization whether its protection system is working, and it lets an organization show that to anyone who needs to see it. For a governing body, franchisor, or insurer, it shows that risk is being managed across a network, and how well, without showing how.
The other three foundations
ERM is the architecture. A living system keeps it adapting as the organization changes. Facilitation is how a team surfaces uncertainty and owns the controls it builds. The platform connects what one organization learns to what the field learns.
