Enterprise Risk Management

COSO ERM 2017 in practice: turning the five components into an operating model

📅 April 22, 2026 🏷️ Enterprise Risk Management

COSO ERM 2017 in practice: turning the five components into an operating model

The 2017 update to COSO's Enterprise Risk Management framework — Enterprise Risk Management — Integrating with Strategy and Performance — moved the conversation past control checklists and toward the strategic choices a board actually makes. Nine years in, most organisations have adopted the vocabulary. Far fewer have turned the five components into a running operating model. This article sets out a pragmatic mapping: what each component looks like on a Monday morning, what artefacts prove it is working, and where the common failure modes sit.

From framework to operating model

The framework defines five components — Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, Information, Communication & Reporting — and 20 principles underneath them. Treating these as an assurance checklist produces a binder. Treating them as the design specification for an operating system produces something that influences decisions.

A workable operating model has three layers:

Each COSO component shows up in at least two of these layers. The mistake is to build the governance layer in isolation and then wonder why the process and information layers never catch up.

Governance & Culture — make the choices visible

This component fails quietly. A risk committee charter exists, a code of conduct exists, yet no one on the executive team can articulate the organisation's risk appetite in a way that would change a real decision.

Three artefacts matter:

The cultural layer is harder to demonstrate. The most useful proxy: in the last four quarters, how many times did a proposed initiative get reshaped or declined explicitly because of the risk appetite? If the answer is zero, the culture hasn't landed regardless of what the survey says.

Strategy & Objective-Setting — integrate, don't bolt on

COSO's central claim in 2017 was that ERM must be integrated with strategy. In practice this means the risk function is in the room when business objectives are set, not called in afterwards to rubber-stamp them.

A working pattern:

  1. Strategy process surfaces the top five to seven strategic objectives.
  2. For each objective, management identifies the critical assumptions that must hold for it to succeed.
  3. The risk function stress-tests those assumptions — competitive response, macro conditions, regulatory change, talent — and quantifies the downside if they fail.
  4. The board approves the strategy and the residual risk envelope together.

The output is a small number of strategic risks tied to specific objectives, plus the appetite boundary within which management may operate. This is a very different artefact from the bottom-up risk register most organisations already have — and it should drive the top of the pyramid, with operational and compliance risks feeding up underneath.

Performance — one process, two speeds

Principles 10 through 14 cover the core mechanics: identify, assess, prioritise, respond, portfolio view. Most organisations have these. The failure mode here is uniformity — running the same quarterly refresh on every risk type.

Run the process at two speeds:

Tie the two loops together with a portfolio view — a single place where a risk owner can see all the exposures relevant to an objective, across business units. If you cannot answer "what is our aggregate exposure to third-party cloud concentration?" in one query, the portfolio view is notional.

Review & Revision — evidence the learning loop

This is the component most assurance work underweights. It asks: does the organisation actually change behaviour in response to what it learned?

Three practical checks:

Information, Communication & Reporting — the under-engineered component

This is where most ERM operating models break. The framework is coherent, the governance is in place, but the data layer is a patchwork of spreadsheets. A few design principles help:

Organisations that treat this component as an IT project — with a proper data model, ideally semantic — get leverage out of the other four components that spreadsheet-based setups never do.

Key takeaways

More on Enterprise Risk Management

New practitioner-grade analysis published weekly across all five OntoRisk pillars.