KITE 2025 New Product Award — Local IT | SACEEC
Risk

COSO ERM, tied to strategy rather than parked beside it

The 2017 framework moved enterprise risk management out of the control department and into the strategy conversation. Dimeri implements all five components and their twenty principles, with risk appetite, performance and strategy sitting in the same record as the register.

What COSO ERM sets out

COSO published Enterprise Risk Management, Integrating with Strategy and Performance in 2017, replacing the 2004 integrated framework. The change of title is the change of substance. The 2004 framework was built around the familiar cube and read, in practice, as an extension of internal control. The 2017 framework argues that the most consequential risk an organisation faces is choosing the wrong strategy, or executing a sound strategy in a way that does not deliver, and it organises itself around that.

The framework has five components containing twenty principles. Governance and Culture sets the tone, covering board oversight, operating structures, desired culture, commitment to core values and the attraction and retention of capable people. Strategy and Objective-Setting connects risk to the business context, defines risk appetite and evaluates alternative strategies before objectives are formulated. Performance identifies, assesses and prioritises risk, implements responses and develops a portfolio view. Review and Revision looks at substantial change, reviews risk and performance, and pursues improvement. Information, Communication and Reporting deals with the information systems, the communication and the reporting on risk, culture and performance.

The portfolio view in the Performance component is the part most organisations find hardest and most valuable. It asks the organisation to look at risk in aggregate against its appetite rather than risk by risk, because a set of individually acceptable risks can add up to an unacceptable position. That is a data problem before it is a judgement problem, and it is where a register held across many spreadsheets stops being usable.

The five components Dimeri implements

Dimeri holds the components and principles as the structure of the platform rather than as a checklist laid over it.

Principles 1 to 5

Governance and culture

Board risk oversight, operating structures, desired culture, commitment to core values, and attracting, developing and retaining capable individuals.

  • Board and committee oversight recorded with its papers
  • Operating structure and accountabilities mapped
  • Culture and conduct risks held in the register
  • Policy attestation and training tracked to individuals
Principles 6 to 9

Strategy and objective-setting

Analysing business context, defining risk appetite, evaluating alternative strategies and formulating business objectives.

  • Business context factors recorded and reviewed
  • Risk appetite statements per category with thresholds
  • Strategic options assessed against their risk profile
  • Objectives linked to the risks that threaten them
Principles 10 to 14

Performance

Identifying risk, assessing severity, prioritising, implementing responses and developing a portfolio view.

  • Risk identification across strategy, operations and projects
  • Severity assessed on consistent criteria
  • Prioritisation against appetite and objective impact
  • Aggregate portfolio view against appetite
Principles 15 to 17

Review and revision

Assessing substantial change, reviewing risk and performance together, and pursuing improvement in enterprise risk management.

  • Change triggers that prompt reassessment
  • Risk and performance reviewed in the same cycle
  • Improvement actions tracked on the ERM process
  • Maturity movement visible year on year
Principles 18 to 20

Information, communication and reporting

Leveraging information systems, communicating risk information, and reporting on risk, culture and performance.

  • Single source of risk information across the group
  • Role based views for board, executive and line
  • Reporting on risk, culture and performance together
  • Full audit trail of changes and decisions

Portfolio view

The aggregate position across the organisation, which is where individually tolerable risks can combine into an intolerable whole.

  • Aggregation across business units and categories
  • Appetite utilisation shown rather than asserted
  • Concentration and correlation surfaced
  • Scenario and stress views on the portfolio

How Dimeri covers COSO ERM

COSO ERM asks for risk to be connected to strategy, performance and culture. That connection is a data architecture question, and it is what Dimeri is built around.

Appetite that does something

Risk appetite statements are held per category with thresholds, and the register shows utilisation against them. Appetite stops being a paragraph in a policy and becomes a line the portfolio view is measured against.

Objectives linked to the risks that threaten them

Business objectives are recorded and risks attach to them directly, so the board sees which objectives are exposed rather than a list of risks with no stated consequence for the plan.

A portfolio view without a consolidation exercise

Because every business unit works in the same register with the same criteria, the aggregate view is a report rather than a quarter end project. Concentrations across units are visible instead of hidden by separate spreadsheets.

Shared with ISO 31000 and King V

Organisations applying COSO ERM alongside ISO 31000 or reporting under King V map each control once. The assessment that satisfies principle 11 also satisfies ISO 31000 clause 6.4 and supports the governing body's risk oversight disclosure.

Implementing COSO ERM in Dimeri

  1. 1

    Start with appetite and objectives

    Risk appetite by category and the business objectives risk will be measured against are configured first, because without them the Performance component has nothing to prioritise against.

  2. 2

    Build the register against objectives

    Risks are captured and linked to the objectives they threaten and the controls that treat them, assessed on criteria applied consistently across every business unit.

  3. 3

    Turn on the portfolio view

    Aggregation, appetite utilisation and concentration views are produced from the register, giving the board the portfolio position the framework asks for.

  4. 4

    Review risk and performance together

    The review cycle brings risk and performance into the same conversation, and improvement actions are tracked against the ERM process itself rather than only against individual risks.

COSO ERM questions

What is the difference between COSO ERM and COSO Internal Control?

They are separate frameworks from the same body. The Internal Control Integrated Framework, updated in 2013, deals with internal control over operations, reporting and compliance. Enterprise Risk Management, Integrating with Strategy and Performance, published in 2017, deals with risk in relation to strategy and performance. Organisations commonly use both, with internal control sitting inside the wider risk picture.

How many principles does COSO ERM 2017 have?

Twenty, grouped into five components: Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication and Reporting. Dimeri maps obligations and controls to the principle level rather than only to the component, so gaps are specific enough to act on.

What does a portfolio view actually require?

It requires risk information captured consistently enough across the organisation to be aggregated: the same criteria, the same scales and the same categories. That is straightforward in a single register and effectively impossible across business unit spreadsheets, which is why the portfolio view is usually the last thing to arrive.

Can we run COSO ERM and ISO 31000 at the same time?

Yes, and many organisations do. The process steps map closely, and the difference is mostly emphasis: COSO ERM frames risk around strategy and performance, ISO 31000 offers a leaner general method. Dimeri records each control once and reflects it in both scorecards, so you are not maintaining two registers.

Is this a substitute for the framework itself?

No. This page describes how Dimeri implements COSO ERM. The framework is a copyrighted publication of COSO and should be obtained from COSO if you intend to work to it.

Put COSO ERM on one register

Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.