According to the Committee of Sponsoring Organizations (COSO 2017), two important elements of an organization’s enterprise risk management (ERM) framework are its risk management philosophy, and its risk appetite and tolerance. Based on Construal Level Theory (CLT), we posit that the effectiveness of ERM depends on the extent of alignment (non-fit or fit) between mental representations (high versus low construal) of those two ERM elements. We test our hypothesis across two risk cases: safety and confidentiality. Results of our experiment suggest that employees are more proactive when there is a construal fit between the emphasis placed on a firm’s risk management philosophy and its expression of the key risk indicators (KRIs). This benefit is observed in the confidentiality case, but not in the safety case. Implications are discussed.

