Beginning in the third quarter of 2008, Standard & Poor’s credit review process of nonfinancial companies now includes an evaluation of the organization’s management of enterprise risk programs as a component of management effectiveness. The credit reviews focus on an evaluation of the risk management culture within the organization and an investigation of the strategic use of risk management data. This AICPA Audit Committee Brief describes the ERM assessment processes and methodology employed by the S&P in evaluating risk management programs in non-financial issuers.