Enterprise risk management (ERM) is how organisations systematically identify, assess, treat, and monitor the risks that could prevent them from achieving their objectives. In the African context, with its unique combination of political risk, currency volatility, infrastructure constraints, and rapidly evolving regulation, ERM is not just best practice; it is an operational necessity. This guide explains how to build an ERM framework that works in practice for South African and broader African organisations. Organisations ready to implement ERM with technology can explore GRC software designed for South Africa.
Why ERM Is Not Optional in Africa
African organisations face a risk environment that differs significantly from developed markets:
- Regulatory complexity: Multiple overlapping frameworks, King IV, FICA, POPIA, sector regulators, JSE requirements, create a dense compliance environment
- Political and sovereign risk: Policy changes, expropriation risk, and political instability affect planning horizons
- Infrastructure dependency: Electricity supply reliability, logistics disruptions, and telecommunications reliability create operational risks that are more pronounced than in many developed markets. Load shedding has been largely suspended, but the underlying supply risk remains a scenario worth planning for
- Currency volatility: Rand depreciation and cross-border currency risk affect financial planning and performance
- Governance expectations: King IV, the JSE Listings Requirements, and international investors all expect mature risk governance
In our experience, organisations that manage these risks systematically tend to make better decisions than those that do not, not because they avoid all risk, but because they choose more deliberately which risks to accept and which to mitigate.
COSO ERM: The Five Components
The COSO ERM framework (updated 2017) is one of the most widely adopted globally and aligns well with South African governance expectations. It organises ERM across five interconnected components, which are supported by twenty underlying principles:
| Component | Focus | Key Activities |
|---|---|---|
| Governance & Culture | Sets the tone for risk management | Board risk oversight, risk culture, risk appetite setting |
| Strategy & Objective-Setting | Links risk to strategy | Risk tolerance aligned to strategy, scenario analysis |
| Performance | Identifies and manages risk to objectives | Risk identification, assessment, prioritisation, response |
| Review & Revision | Ensures ERM remains current | Ongoing monitoring, periodic review, improvement cycles |
| Information, Communication & Reporting | Enables informed decision-making | Risk registers, dashboards, board reporting, disclosures |
ISO 31000 vs COSO ERM
ISO 31000 sets out principles, a framework, and a process for managing risk. COSO ERM is a management framework that focuses on how risk integrates with strategy and performance. The two are complementary: ISO 31000 guides the risk management process and how it is embedded, while COSO ERM shapes how ERM connects to decision-making at the executive and board level.
Building Your ERM Framework: 6 Steps
Step 1: Establish Risk Governance
Define who is responsible for risk at every level, the board's risk committee, the Chief Risk Officer (or equivalent), business unit risk owners, and control function oversight. Document this in a Risk Management Policy approved by the board. Without clear accountability, ERM degenerates into a documentation exercise.
Step 2: Define Risk Appetite
Risk appetite is the amount of risk the organisation is willing to accept in pursuit of its objectives. It must be set by the board, expressed in measurable terms (not vague statements), and cascaded into risk tolerances at the business unit level. A risk appetite statement that says "we have low appetite for compliance risk" is meaningless without specifying what "low" means in measurable terms.
Step 3: Establish a Risk Taxonomy
A risk taxonomy is the organisation's standardised classification of risk types. Common top-level categories include: Strategic, Operational, Financial, Compliance/Regulatory, Reputational, and Technology risk. Consistent taxonomy allows comparability across business units and supports portfolio-level risk analysis.
Step 4: Build Your Risk Register
The risk register is the operational core of ERM. It captures risk descriptions, inherent ratings, control effectiveness, residual ratings, risk owners, and treatment plans. Critically, it must be a living document, reviewed regularly and updated when the risk environment changes, not produced once a year for board consumption.
Step 5: Implement Controls and Monitoring
Each risk with a residual rating above the risk appetite threshold must have an active treatment plan. Controls must be documented, tested for effectiveness, and linked directly to the risks they mitigate. Monitoring calendars confirm controls are tested at appropriate intervals.
Step 6: Report to Governance Bodies
ERM only adds value if risk information reaches decision-makers. Board-level reporting should focus on the risk profile, changes in top risks, appetite breaches, and emerging risks. Management reporting should drive accountability for risk treatment actions. The frequency and format of reports should match the governance structure.
ERM Maturity Levels
Most organisations progress through recognisable ERM maturity stages:
| Level | Description | Typical Characteristics |
|---|---|---|
| 1, Initial | Ad hoc risk management | Risks managed reactively, no consistent process, no risk register |
| 2, Developing | Risk register exists but limited use | Annual risk assessments, limited board engagement, risk in silos |
| 3, Defined | Formal ERM process in place | Consistent methodology, risk appetite defined, quarterly reporting |
| 4, Managed | ERM integrated into business processes | Risk-informed decisions, control effectiveness measured, real-time monitoring |
| 5, Optimising | ERM drives competitive advantage | Predictive risk analytics, continuous improvement, strategic risk-taking |
In our experience, many South African organisations sit around Level 2 to 3. Moving from Level 3 to Level 4 usually takes a combination of leadership, capability, and culture, with technology as one enabler, for example replacing spreadsheets and email with an integrated GRC platform. This maturity view is our own summary, aligned to widely used models such as the RIMS Risk Maturity Model.
The Cost of Poor ERM in Africa
The consequences of inadequate ERM are not hypothetical in the African context:
- State capture and SOE failures: The findings of the Zondo Commission into state capture set out how weak governance and risk oversight at entities such as Eskom, SAA, and Transnet carried a systemic cost
- Greylisting: South Africa's 2023 FATF greylisting followed the 2021 Mutual Evaluation, which pointed to gaps in the systemic management of financial crime risk. The country exited the grey list in October 2025 after addressing those gaps
- Regulatory action: Listed companies have at times faced regulatory action, restatements, or loss of investor confidence where risk oversight fell short
- Operational disruption: Infrastructure-dependent businesses without risk-aware contingency planning have felt energy and logistics disruptions more acutely
How Technology Supports ERM at Scale
Manual ERM, spreadsheets, email, and disconnected documents, creates four structural problems:
- Version control failures: Multiple risk register versions circulate simultaneously
- Accountability gaps: Risk owners don't receive automatic reminders; treatment actions are not tracked
- Reporting delays: Consolidating risk data from multiple sources takes weeks
- Audit trail absence: No record of when risks were reviewed, by whom, and what decisions were made
A purpose-built ERM platform resolves all four, providing a single risk register, automated workflows, real-time dashboards, and complete audit trails. For organisations implementing King IV and COSO ERM simultaneously, platform support is often the difference between a functional programme and one that exists only on paper.
Summary
- African organisations face distinctive risk factors, such as political risk, currency volatility, and electricity supply reliability, that make ERM especially valuable
- COSO ERM's five components provide a solid framework that aligns with King IV and JSE requirements
- Building ERM requires six steps: governance, risk appetite, taxonomy, risk register, controls/monitoring, and reporting
- In our experience many South African organisations are around ERM maturity Level 2 to 3, and progressing to Level 4 takes leadership, capability, and culture as well as technology
- Manual ERM processes create version control, accountability, reporting, and audit trail failures
- Effective ERM produces measurable business value, better decisions, fewer surprises, stronger governance
Frequently Asked Questions
What is the difference between ERM and risk management?
Traditional risk management operates in departmental silos, IT manages IT risk, finance manages financial risk. ERM takes an organisation-wide view that connects risk to strategy, integrates information across business units, and ensures the board has a complete picture of risk exposure.
Which ERM framework is best for South African organisations?
Most South African organisations align with COSO ERM for the overall framework, ISO 31000 for the risk process, and King IV for governance and oversight. These are complementary, not competing, use King IV to define board accountability, COSO ERM to connect risk to strategy, and ISO 31000 to guide the day-to-day risk management process.
How long does it take to implement ERM?
A basic ERM framework, governance structure, risk appetite, initial risk register, and board reporting, can be established in 3 to 6 months. Reaching ERM maturity Level 3 (defined, consistent process) typically takes 12 to 18 months. Technology accelerates implementation significantly by providing pre-built frameworks, workflows, and reporting.
Does King IV require ERM?
King is a voluntary code rather than legislation, so it does not "require" ERM in a legal sense, and it does not use the term ERM as a mandate. What it does do is ask the governing body to govern risk in a way that supports the organisation's strategy and objectives (King IV Principle 11, and King V Principle 8 for financial years starting on or after 1 January 2026). Because King applies on an "apply and explain" basis, the governing body explains how it applies that principle, and investors and regulators pay close attention to how risk is governed in practice.
References
1. COSO. Enterprise Risk Management, Integrating with Strategy and Performance, 2017.
2. ISO 31000:2018. Risk Management, Guidelines. International Organisation for Standardisation.
3. Institute of Directors South Africa. King IV Report on Corporate Governance for South Africa, 2016.
4. World Bank. Africa's Pulse: Economic Overview. 2025.
5. JSE Limited. Listings Requirements. Updated 2024.
6. South African Reserve Bank. Financial Stability Review. 2025.
7. Institute of Risk Management South Africa (IRMSA). IRMSA Risk Report (annual). irmsa.org.za.
8. Judicial Commission of Inquiry into State Capture (Zondo Commission). Reports, 2022.
This guide is provided for educational purposes only. It draws on a combination of Dimeri's project and advisory work, interviews with practitioners, our own research, academic literature, and publications from standard-setters, regulators, and professional bodies. It reflects our view of good practice at the date of publication and is not legal, regulatory, audit, or financial advice.
Laws, codes, and standards change, and how they apply depends on your organisation's circumstances. Please consult the primary sources and obtain professional advice before acting. Last reviewed: September 2026.

