KITE 2025 New Product Award โ€” Local IT | SACEEC
Risk

COSO ERM coverage that connects risk to the strategy it protects

All five components and twenty principles implemented with risk appetite, portfolio view and business objectives sitting in the same record as the register.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What COSO ERM sets out

Risk appetite with measurable thresholds

Appetite statements held per category with quantitative thresholds. The register shows utilisation against them so appetite becomes a line the portfolio is measured against.

Objectives linked to risk

Business objectives recorded with risks attached directly. The board sees which strategic priorities are exposed rather than reviewing a list with no stated consequence for the plan.

Portfolio view without consolidation

Because every business unit works in the same register with the same criteria, the aggregate view is a report rather than a quarter-end project. Concentrations surface automatically.

Review and improvement on the process

Risk and performance reviewed in the same cycle, with change triggers that prompt reassessment and improvement actions tracked on the ERM process itself.

COSO ERM compliance, covered by default

The current framework moved enterprise risk management into the strategy conversation. Dimeri implements all five components and twenty principles with risk appetite, performance and portfolio view sitting in the same record as the register.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Twenty principles structured

All twenty principles across the five components held as the structure of the platform. Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication and Reporting.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Portfolio view

Aggregation across business units and categories with appetite utilisation, concentration and correlation surfaced. The view the framework asks for and spreadsheets cannot produce.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Risk appetite with teeth

Appetite statements per category with thresholds, and the register showing utilisation against them. Appetite stops being a paragraph in a policy and becomes a line the portfolio is measured against.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Objectives linked to risk

Business objectives recorded and risks attached directly, so the board sees which objectives are exposed rather than a list of risks with no stated consequence for the plan.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Review and improvement cycle

Risk and performance reviewed in the same cycle, with change triggers that prompt reassessment and improvement actions tracked on the ERM process itself.

The five components Dimeri implements

Dimeri holds the components and principles as the structure of the platform rather than as a checklist laid over it.

Governance and culture

Board risk oversight, operating structures, desired culture, commitment to core values, and attracting, developing and retaining capable individuals.

  • Board and committee oversight recorded with its papers
  • Operating structure and accountabilities mapped
  • Culture and conduct risks held in the register
  • Policy attestation and training tracked to individuals

Strategy and objective-setting

Analysing business context, defining risk appetite, evaluating alternative strategies and formulating business objectives.

  • Business context factors recorded and reviewed
  • Risk appetite statements per category with thresholds
  • Strategic options assessed against their risk profile
  • Objectives linked to the risks that threaten them

Performance

Identifying risk, assessing severity, prioritising, implementing responses and developing a portfolio view.

  • Risk identification across strategy, operations and projects
  • Severity assessed on consistent criteria
  • Prioritisation against appetite and objective impact
  • Aggregate portfolio view against appetite

Review and revision

Assessing substantial change, reviewing risk and performance together, and pursuing improvement in enterprise risk management.

  • Change triggers that prompt reassessment
  • Risk and performance reviewed in the same cycle
  • Improvement actions tracked on the ERM process
  • Maturity movement visible year on year

Information, communication and reporting

Leveraging information systems, communicating risk information, and reporting on risk, culture and performance.

  • Single source of risk information across the group
  • Role based views for board, executive and line
  • Reporting on risk, culture and performance together
  • Full audit trail of changes and decisions

Portfolio view

The aggregate position across the organisation, which is where individually tolerable risks can combine into an intolerable whole.

  • Aggregation across business units and categories
  • Appetite utilisation shown rather than asserted
  • Concentration and correlation surfaced
  • Scenario and stress views on the portfolio

Getting COSO ERM coverage in place

4 steps from where you are today to a COSO ERM position your auditor can rely on.

Book a demo

Risk appetite by category and the business objectives risk will be measured against are configured first, because without them the Performance component has nothing to prioritise against.

How Dimeri covers COSO ERM

Appetite that does something

Risk appetite statements are held per category with thresholds, and the register shows utilisation against them. Appetite stops being a paragraph in a policy and becomes a line the portfolio view is measured against.

Objectives linked to the risks that threaten them

Business objectives are recorded and risks attach to them directly, so the board sees which objectives are exposed rather than a list of risks with no stated consequence for the plan.

A portfolio view without a consolidation exercise

Because every business unit works in the same register with the same criteria, the aggregate view is a report rather than a quarter end project. Concentrations across units are visible instead of hidden by separate spreadsheets.

COSO ERM questions

What is the difference between COSO ERM and COSO Internal Control?

They are separate frameworks from the same body. The Internal Control Integrated Framework deals with internal control over operations, reporting and compliance. Enterprise Risk Management, Integrating with Strategy and Performance, deals with risk in relation to strategy and performance. Organisations commonly use both, with internal control sitting inside the wider risk picture.

How many principles does COSO ERM have?

Twenty, grouped into five components: Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication and Reporting. Dimeri maps obligations and controls to the principle level rather than only to the component, so gaps are specific enough to act on.

What does a portfolio view actually require?

It requires risk information captured consistently enough across the organisation to be aggregated: the same criteria, the same scales and the same categories. That is straightforward in a single register and effectively impossible across business unit spreadsheets, which is why the portfolio view is usually the last thing to arrive.

Can we run COSO ERM and ISO 31000 at the same time?

Yes, and many organisations do. The process steps map closely, and the difference is mostly emphasis: COSO ERM frames risk around strategy and performance, ISO 31000 offers a leaner general method. Dimeri records each control once and reflects it in both scorecards, so you are not maintaining two registers.

Is this a substitute for the framework itself?

No. This page describes how Dimeri implements COSO ERM. The framework is a copyrighted publication of COSO and should be obtained from COSO if you intend to work to it.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.