D368 Enterprise Risk Management, catalog number FINC 3105, is a three-CU course examining risk management from the organization's perspective rather than the individual's. The shift matters. A household buys insurance to survive a single bad event; an organization holds a portfolio of risks that interact, some of which it should deliberately keep because bearing them is how it earns a return. The competency is governing that portfolio rather than eliminating it.
Risk as a portfolio the organization chooses to hold
The central idea of enterprise risk management is that risks cannot be managed one at a time by whoever happens to own them. A firm that hedges a currency exposure in treasury while its procurement team signs a supply contract that recreates the same exposure has spent money to achieve nothing. Enterprise-wide means aggregated, compared and governed centrally, with a stated appetite for how much total exposure the organization will accept.
That appetite is the concept students most often skip and evaluators most often look for. Risk appetite is a deliberate statement of how much of what kind of risk the organization is willing to carry in pursuit of its objectives, and every subsequent decision refers back to it. Without it, a risk assessment produces a list with no way to decide what to do about anything on it.
The four responses are then straightforward and worth naming precisely: avoid the activity, reduce the likelihood or the impact through controls, transfer the financial consequence through insurance or contract, or accept the exposure knowingly and monitor it. Acceptance is a legitimate answer and students under-use it. An organization that treats every risk as requiring mitigation will spend more on controls than the exposures are worth, and saying so in a submission demonstrates exactly the judgment the course is testing.
Turning many aspects into a governed document
Each rubric aspect in your Course of Study is scored independently and needs a 2. Risk tasks tend to carry a high aspect count because the subject decomposes into identification, assessment, response, monitoring and governance, each of which can be scored separately.
Worked example at high aspect count. Suppose your rubric lists eight scored aspects and the directions ask for roughly 2,300 words alongside a risk register. Reserve 180 for the organizational context, leaving 2,120, or 265 per aspect. The register carries the itemized detail, so prose does not need to repeat it; each aspect's words go to explaining method and judgment instead.
Then protect two aspects from compression. The one covering risk appetite needs 400, because it has to connect a tolerance statement to the organization's objectives rather than assert a number. The one covering monitoring needs 350, because a risk framework with no review cycle is a document rather than a system. Take 60 from each of the other six, which yields 360, and the two protected aspects land near 400 and 350 while the rest sit at 205 with the register doing the heavy lifting. The document still totals 2,120.
The risk register, and what each column has to earn
Almost every enterprise risk deliverable produces a register in some form. These columns cover what the aspects usually assess. Where task directions specify a format, follow it.
| Column | What belongs there | The test it must pass |
|---|---|---|
| Risk description | A specific event with a cause and a consequence | Reads as something that could happen on a date, not as a category |
| Category | Strategic, operational, financial, compliance or reputational | Consistent classification across the register, so aggregation means something |
| Owner | A named role accountable for the response | A person or role, never a department in the abstract |
| Inherent likelihood and impact | The exposure before controls, on a stated scale | The scale is defined somewhere, with what a rating of 4 actually means |
| Existing controls | What is already in place and whether it operates | Distinguishes designed controls from ones actually working |
| Residual rating | The exposure after existing controls | Lower than inherent for a stated reason, not by assertion |
| Response | Avoid, reduce, transfer or accept, with the action named | Matches the residual rating against the appetite, rather than defaulting to reduce |
| Monitoring | The indicator watched and how often it is reviewed | A measurable indicator with a threshold, not a promise to keep an eye on it |
Interdependence deserves a note beneath the register. Risks that share a cause materialize together, and a portfolio view exists precisely to catch the correlation that a line-by-line list conceals. One paragraph naming which entries would move as a group is often the most sophisticated content in a student submission.
Making risk judgments defensible
Risk ratings are judgments, and a judgment without a basis is indistinguishable from a guess. The evidence discipline here is about making the basis visible.
- Define your scales before you use them. What separates a likelihood of 3 from a 4 must be written down, in frequency terms where possible.
- Anchor ratings in something: incident history, industry loss data, the organization's own capacity or a stated assumption.
- Quantify impact in the organization's own units, whether that is dollars, downtime hours or customers affected.
- Cite frameworks and standards in paraphrase with APA references, since submissions are checked for similarity.
- Where you accept a risk, record why the acceptance is within appetite. Unexplained acceptance looks like neglect.
Opportunity is the half of risk that student submissions almost always omit. An organization that only catalogues threats will systematically underinvest, because every proposal will arrive attached to a list of things that could go wrong and none will arrive attached to what could go right. Where a framework treats uncertainty in both directions, a register entry can record an upside case with the same discipline as a downside one: the event, its likelihood, its potential benefit and what the organization would need to do to be positioned for it. Including two such entries costs a paragraph and demonstrates that risk management is understood as a decision tool rather than as a defensive exercise.
Governance is evidence too. Naming who approves the risk framework, who reviews the register and at what interval turns a static document into a functioning process, and several aspects in this course are written specifically to test whether the student understands that distinction.
What a Competent risk submission demonstrates
Aspects are scored on their own against the competency standard, and this course rewards documents that an executive committee could actually use.
- Risks are described as events with causes and consequences, not as categories.
- Rating scales are defined and applied consistently across every entry.
- Risk appetite is stated and every response decision refers to it.
- All four response types appear where appropriate, including acceptance.
- Monitoring names a measurable indicator, a threshold and a review frequency.
WGU records Competent or Not Competent, with no letter grade and no ordinary grade point average, and performance assessment work can be revised and resubmitted with no penalty. The real cost of a return is calendar time inside a six-month flat-rate term, which is what decides how many courses you close and therefore your effective cost per course. Where your version of this course carries a proctored objective assessment, we prepare only: framework review, scenario drills and an honest readiness call, never a sitting and never a request for credentials.
Six mistakes in enterprise risk work
- Writing risk categories as risks. Cybersecurity risk is a heading; a supplier outage that halts order processing for three days is a risk.
- Rating without a defined scale. Numbers that mean nothing in particular cannot be aggregated or compared.
- Skipping risk appetite. Without it there is no basis for deciding which residual exposures are acceptable.
- Defaulting every response to reduce. Transfer and acceptance are legitimate and often cheaper, and the choice is what is being assessed.
- Ignoring correlation. Independent-looking entries that share a single cause will arrive together, which is the whole reason for an enterprise view.
- Assigning ownership to a department. Accountability that belongs to everyone belongs to nobody, so name the role.
How the risk framework gets built with you
Send the rubric, the directions and the organizational scenario. The draft returns with defined rating scales, a register where every entry is an event with a cause and a consequence, a stated appetite that the response decisions actually reference, a correlation note beneath the register and monitoring indicators with thresholds attached. The walkthrough covers how each rating was reached, because defending a judgment is the competency here rather than producing a list.
D368 pairs with D367 Innovation in Finance, which introduces the new exposures a modern finance function has to govern, and it prepares the ground for the capstone in D369 Finance Capstone, where risk thinking has to appear inside a larger integrated document.
Questions students ask about D368
Is D368 the same course as FINC 3105?
How is this different from the personal finance risk material?
Do I need a real organization for the assessment?
Risk register due?
Send the organizational scenario and the rubric. You get defined scales, a register of real events and responses that reference a stated appetite.
Where D368 sits in WGU's programs
The July 2026 catalog places this code in 1 current WGU program. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.
The assessments, one by one
The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.