A lot of organizations that are just embarking upon their enterprise risk management journey have questions about the basic terminology involved. In this blog post, we want to tackle some basic terms that are often—incorrectly!—used interchangeably. Enterprise risk management vs. business continuity management: Let’s break it down.

How to define enterprise risk management and business continuity?

In our webinar with Sphera [formerly riskmethods] customer Clariant, we got asked a very interesting question from one of the participants: “What’s the difference between enterprise risk management and business continuity management?”

Great question. And, like most great questions, the answer is a little fuzzy.

At the end of the day, enterprise risk management and business continuity management are tightly linked. The best way to think about it is probably this: Enterprise risk management (ERM) is about processes that are enacted before a disaster occurs, because enterprise risk management is concerned with protecting a business from risk by identifying the existence of vulnerabilities and defining a way to minimize their probability.

Business continuity management (BCM), on the other hand, is about processes that are designed to be enacted after a disaster has occurred, because business continuity management is the process of maintaining business operations during or after an actual disaster, which is executed through the use of business continuity plans.

To put a different spin on it, let’s use a hiking analogy. Enterprise risk management is the part of the hike where you pack your survival kit full of flares—and business continuity management is the part of the hike where you shoot off those flares because you’ve broken your leg and can’t move.

The difference between ERM and BCM

One of the key differences between ERM and BCM is their approaches. Due to the preventive nature of ERM programs, enterprise risk management is a largely strategic undertaking—it’s focused on understanding and planning for hypothetical situations. Business continuity management, on the other hand, is much more tactical—it’s focused on the actual way that an organization should act when a business disruption occurs.

How ERM and BCM work together?

In many organizations, enterprise risk management and business continuity management are likely managed by the same team, since they’re so tightly intertwined—after all, it’s not possible to create a business continuity plan for a risk event if you don’t have a good sense of what risk events are likely to occur. By the same token, it’s not possible to adequately protect a business against disruption without a plan to address it when it happens. In other words: if your business has risk managers and business continuity managers, you better make sure they’re the best of friends.

But regardless of how your company is set up, here’s the bottom line: risk management and business continuity management are both critical functions if you want to keep your organization running. And although ERM and BCM are large topics that encompass a number of types of risk, a significant chunk of those risks have to do with your organization’s ability to produce its product—which is heavily impacted by your supply network.

riskmethods was acquired by Sphera in October 2022. This content originally appeared on the riskmethods website and was slightly modified for sphera.com.

Latest insights from Sphera

The Sustainability Regulations Shaping 2026: What Companies Need to Know

The Sustainability Regulations Shaping 2026: What Companies Need to Know

Navigate the 2026 EU sustainability landscape. From CSRD and Digital Product Passports (DPP) to CBAM and EUDR, get…
March 30, 2026
Seven Ways to Build a Strong and Resilient Safety System

Seven Ways to Build a Strong and Resilient Safety System

Close the EHS data gap. Learn why 40% of firms still risk safety with spreadsheets and discover Sphera’s…
March 23, 2026
Supply Chain Risk Report 2026: Manufacturing Executive Brief

Supply Chain Risk Report 2026: Manufacturing Executive Brief

Prevent production downtime with Sphera’s 2026 Manufacturing Risk Brief. Bridge the confidence paradox, gain N-tier visibility, and eliminate…
March 20, 2026