COSO ERM, tied to strategy rather than parked beside it
The 2017 framework moved enterprise risk management out of the control department and into the strategy conversation. Dimeri implements all five components and their twenty principles, with risk appetite, performance and strategy sitting in the same record as the register.
What COSO ERM sets out
COSO published Enterprise Risk Management, Integrating with Strategy and Performance in 2017, replacing the 2004 integrated framework. The change of title is the change of substance. The 2004 framework was built around the familiar cube and read, in practice, as an extension of internal control. The 2017 framework argues that the most consequential risk an organisation faces is choosing the wrong strategy, or executing a sound strategy in a way that does not deliver, and it organises itself around that.
The framework has five components containing twenty principles. Governance and Culture sets the tone, covering board oversight, operating structures, desired culture, commitment to core values and the attraction and retention of capable people. Strategy and Objective-Setting connects risk to the business context, defines risk appetite and evaluates alternative strategies before objectives are formulated. Performance identifies, assesses and prioritises risk, implements responses and develops a portfolio view. Review and Revision looks at substantial change, reviews risk and performance, and pursues improvement. Information, Communication and Reporting deals with the information systems, the communication and the reporting on risk, culture and performance.
The portfolio view in the Performance component is the part most organisations find hardest and most valuable. It asks the organisation to look at risk in aggregate against its appetite rather than risk by risk, because a set of individually acceptable risks can add up to an unacceptable position. That is a data problem before it is a judgement problem, and it is where a register held across many spreadsheets stops being usable.
The five components Dimeri implements
Dimeri holds the components and principles as the structure of the platform rather than as a checklist laid over it.
Governance and culture
Board risk oversight, operating structures, desired culture, commitment to core values, and attracting, developing and retaining capable individuals.
- Board and committee oversight recorded with its papers
- Operating structure and accountabilities mapped
- Culture and conduct risks held in the register
- Policy attestation and training tracked to individuals
Strategy and objective-setting
Analysing business context, defining risk appetite, evaluating alternative strategies and formulating business objectives.
- Business context factors recorded and reviewed
- Risk appetite statements per category with thresholds
- Strategic options assessed against their risk profile
- Objectives linked to the risks that threaten them
Performance
Identifying risk, assessing severity, prioritising, implementing responses and developing a portfolio view.
- Risk identification across strategy, operations and projects
- Severity assessed on consistent criteria
- Prioritisation against appetite and objective impact
- Aggregate portfolio view against appetite
Review and revision
Assessing substantial change, reviewing risk and performance together, and pursuing improvement in enterprise risk management.
- Change triggers that prompt reassessment
- Risk and performance reviewed in the same cycle
- Improvement actions tracked on the ERM process
- Maturity movement visible year on year
Information, communication and reporting
Leveraging information systems, communicating risk information, and reporting on risk, culture and performance.
- Single source of risk information across the group
- Role based views for board, executive and line
- Reporting on risk, culture and performance together
- Full audit trail of changes and decisions
Portfolio view
The aggregate position across the organisation, which is where individually tolerable risks can combine into an intolerable whole.
- Aggregation across business units and categories
- Appetite utilisation shown rather than asserted
- Concentration and correlation surfaced
- Scenario and stress views on the portfolio
How Dimeri covers COSO ERM
COSO ERM asks for risk to be connected to strategy, performance and culture. That connection is a data architecture question, and it is what Dimeri is built around.
Appetite that does something
Risk appetite statements are held per category with thresholds, and the register shows utilisation against them. Appetite stops being a paragraph in a policy and becomes a line the portfolio view is measured against.
Objectives linked to the risks that threaten them
Business objectives are recorded and risks attach to them directly, so the board sees which objectives are exposed rather than a list of risks with no stated consequence for the plan.
A portfolio view without a consolidation exercise
Because every business unit works in the same register with the same criteria, the aggregate view is a report rather than a quarter end project. Concentrations across units are visible instead of hidden by separate spreadsheets.
Shared with ISO 31000 and King V
Organisations applying COSO ERM alongside ISO 31000 or reporting under King V map each control once. The assessment that satisfies principle 11 also satisfies ISO 31000 clause 6.4 and supports the governing body's risk oversight disclosure.
Implementing COSO ERM in Dimeri
- 1
Start with appetite and objectives
Risk appetite by category and the business objectives risk will be measured against are configured first, because without them the Performance component has nothing to prioritise against.
- 2
Build the register against objectives
Risks are captured and linked to the objectives they threaten and the controls that treat them, assessed on criteria applied consistently across every business unit.
- 3
Turn on the portfolio view
Aggregation, appetite utilisation and concentration views are produced from the register, giving the board the portfolio position the framework asks for.
- 4
Review risk and performance together
The review cycle brings risk and performance into the same conversation, and improvement actions are tracked against the ERM process itself rather than only against individual risks.
COSO ERM questions
What is the difference between COSO ERM and COSO Internal Control?
They are separate frameworks from the same body. The Internal Control Integrated Framework, updated in 2013, deals with internal control over operations, reporting and compliance. Enterprise Risk Management, Integrating with Strategy and Performance, published in 2017, deals with risk in relation to strategy and performance. Organisations commonly use both, with internal control sitting inside the wider risk picture.
How many principles does COSO ERM 2017 have?
Twenty, grouped into five components: Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication and Reporting. Dimeri maps obligations and controls to the principle level rather than only to the component, so gaps are specific enough to act on.
What does a portfolio view actually require?
It requires risk information captured consistently enough across the organisation to be aggregated: the same criteria, the same scales and the same categories. That is straightforward in a single register and effectively impossible across business unit spreadsheets, which is why the portfolio view is usually the last thing to arrive.
Can we run COSO ERM and ISO 31000 at the same time?
Yes, and many organisations do. The process steps map closely, and the difference is mostly emphasis: COSO ERM frames risk around strategy and performance, ISO 31000 offers a leaner general method. Dimeri records each control once and reflects it in both scorecards, so you are not maintaining two registers.
Is this a substitute for the framework itself?
No. This page describes how Dimeri implements COSO ERM. The framework is a copyrighted publication of COSO and should be obtained from COSO if you intend to work to it.
Go further on COSO ERM
Put COSO ERM on one register
Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.