COSO ERM coverage that connects risk to the strategy it protects
All five components and twenty principles implemented with risk appetite, portfolio view and business objectives sitting in the same record as the register.
Compliance at a glance
What COSO ERM sets out
Risk appetite with measurable thresholds
Appetite statements held per category with quantitative thresholds. The register shows utilisation against them so appetite becomes a line the portfolio is measured against.
Objectives linked to risk
Business objectives recorded with risks attached directly. The board sees which strategic priorities are exposed rather than reviewing a list with no stated consequence for the plan.
Portfolio view without consolidation
Because every business unit works in the same register with the same criteria, the aggregate view is a report rather than a quarter-end project. Concentrations surface automatically.
Review and improvement on the process
Risk and performance reviewed in the same cycle, with change triggers that prompt reassessment and improvement actions tracked on the ERM process itself.
COSO ERM compliance, covered by default
The current framework moved enterprise risk management into the strategy conversation. Dimeri implements all five components and twenty principles with risk appetite, performance and portfolio view sitting in the same record as the register.
Twenty principles structured
All twenty principles across the five components held as the structure of the platform. Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication and Reporting.
Portfolio view
Aggregation across business units and categories with appetite utilisation, concentration and correlation surfaced. The view the framework asks for and spreadsheets cannot produce.
Risk appetite with teeth
Appetite statements per category with thresholds, and the register showing utilisation against them. Appetite stops being a paragraph in a policy and becomes a line the portfolio is measured against.
Objectives linked to risk
Business objectives recorded and risks attached directly, so the board sees which objectives are exposed rather than a list of risks with no stated consequence for the plan.
Review and improvement cycle
Risk and performance reviewed in the same cycle, with change triggers that prompt reassessment and improvement actions tracked on the ERM process itself.
The five components Dimeri implements
Dimeri holds the components and principles as the structure of the platform rather than as a checklist laid over it.
Governance and culture
Board risk oversight, operating structures, desired culture, commitment to core values, and attracting, developing and retaining capable individuals.
- Board and committee oversight recorded with its papers
- Operating structure and accountabilities mapped
- Culture and conduct risks held in the register
- Policy attestation and training tracked to individuals
Strategy and objective-setting
Analysing business context, defining risk appetite, evaluating alternative strategies and formulating business objectives.
- Business context factors recorded and reviewed
- Risk appetite statements per category with thresholds
- Strategic options assessed against their risk profile
- Objectives linked to the risks that threaten them
Performance
Identifying risk, assessing severity, prioritising, implementing responses and developing a portfolio view.
- Risk identification across strategy, operations and projects
- Severity assessed on consistent criteria
- Prioritisation against appetite and objective impact
- Aggregate portfolio view against appetite
Review and revision
Assessing substantial change, reviewing risk and performance together, and pursuing improvement in enterprise risk management.
- Change triggers that prompt reassessment
- Risk and performance reviewed in the same cycle
- Improvement actions tracked on the ERM process
- Maturity movement visible year on year
Information, communication and reporting
Leveraging information systems, communicating risk information, and reporting on risk, culture and performance.
- Single source of risk information across the group
- Role based views for board, executive and line
- Reporting on risk, culture and performance together
- Full audit trail of changes and decisions
Portfolio view
The aggregate position across the organisation, which is where individually tolerable risks can combine into an intolerable whole.
- Aggregation across business units and categories
- Appetite utilisation shown rather than asserted
- Concentration and correlation surfaced
- Scenario and stress views on the portfolio
Getting COSO ERM coverage in place
4 steps from where you are today to a COSO ERM position your auditor can rely on.
Book a demoRisk appetite by category and the business objectives risk will be measured against are configured first, because without them the Performance component has nothing to prioritise against.
How Dimeri covers COSO ERM
Appetite that does something
Risk appetite statements are held per category with thresholds, and the register shows utilisation against them. Appetite stops being a paragraph in a policy and becomes a line the portfolio view is measured against.
Objectives linked to the risks that threaten them
Business objectives are recorded and risks attach to them directly, so the board sees which objectives are exposed rather than a list of risks with no stated consequence for the plan.
A portfolio view without a consolidation exercise
Because every business unit works in the same register with the same criteria, the aggregate view is a report rather than a quarter end project. Concentrations across units are visible instead of hidden by separate spreadsheets.
COSO ERM questions
What is the difference between COSO ERM and COSO Internal Control?
They are separate frameworks from the same body. The Internal Control Integrated Framework deals with internal control over operations, reporting and compliance. Enterprise Risk Management, Integrating with Strategy and Performance, deals with risk in relation to strategy and performance. Organisations commonly use both, with internal control sitting inside the wider risk picture.
How many principles does COSO ERM have?
Twenty, grouped into five components: Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication and Reporting. Dimeri maps obligations and controls to the principle level rather than only to the component, so gaps are specific enough to act on.
What does a portfolio view actually require?
It requires risk information captured consistently enough across the organisation to be aggregated: the same criteria, the same scales and the same categories. That is straightforward in a single register and effectively impossible across business unit spreadsheets, which is why the portfolio view is usually the last thing to arrive.
Can we run COSO ERM and ISO 31000 at the same time?
Yes, and many organisations do. The process steps map closely, and the difference is mostly emphasis: COSO ERM frames risk around strategy and performance, ISO 31000 offers a leaner general method. Dimeri records each control once and reflects it in both scorecards, so you are not maintaining two registers.
Is this a substitute for the framework itself?
No. This page describes how Dimeri implements COSO ERM. The framework is a copyrighted publication of COSO and should be obtained from COSO if you intend to work to it.
Ready to Transform Your GRC?
Join governance, risk, and compliance teams using AI to work smarter.