COSO ERM 2017 in practice: turning the five components into an operating model
COSO ERM 2017 in practice: turning the five components into an operating model
The 2017 update to COSO's Enterprise Risk Management framework — Enterprise Risk Management — Integrating with Strategy and Performance — moved the conversation past control checklists and toward the strategic choices a board actually makes. Nine years in, most organisations have adopted the vocabulary. Far fewer have turned the five components into a running operating model. This article sets out a pragmatic mapping: what each component looks like on a Monday morning, what artefacts prove it is working, and where the common failure modes sit.
From framework to operating model
The framework defines five components — Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, Information, Communication & Reporting — and 20 principles underneath them. Treating these as an assurance checklist produces a binder. Treating them as the design specification for an operating system produces something that influences decisions.
A workable operating model has three layers:
- Governance layer — who owns risk, how appetite is set, and how it cascades.
- Process layer — how risk is identified, analysed, responded to, and monitored within the annual cycle.
- Information layer — the data, systems, and reports that connect the other two.
Each COSO component shows up in at least two of these layers. The mistake is to build the governance layer in isolation and then wonder why the process and information layers never catch up.
Governance & Culture — make the choices visible
This component fails quietly. A risk committee charter exists, a code of conduct exists, yet no one on the executive team can articulate the organisation's risk appetite in a way that would change a real decision.
Three artefacts matter:
- A risk appetite statement that is directional (growth vs. preservation) and quantitative where it can be (earnings-at-risk, capital ratios, loss tolerances). If every statement is "acceptable" or "moderate", the statement is decorative.
- A decision rights map that names who approves what — which executive signs off a new country, a new product line, a new third-party dependency — and at what threshold the decision escalates.
- Board reporting that connects risks to the strategy, not to a heat map. If the board paper leads with a five-by-five matrix, the framework is being assured, not used.
The cultural layer is harder to demonstrate. The most useful proxy: in the last four quarters, how many times did a proposed initiative get reshaped or declined explicitly because of the risk appetite? If the answer is zero, the culture hasn't landed regardless of what the survey says.
Strategy & Objective-Setting — integrate, don't bolt on
COSO's central claim in 2017 was that ERM must be integrated with strategy. In practice this means the risk function is in the room when business objectives are set, not called in afterwards to rubber-stamp them.
A working pattern:
- Strategy process surfaces the top five to seven strategic objectives.
- For each objective, management identifies the critical assumptions that must hold for it to succeed.
- The risk function stress-tests those assumptions — competitive response, macro conditions, regulatory change, talent — and quantifies the downside if they fail.
- The board approves the strategy and the residual risk envelope together.
The output is a small number of strategic risks tied to specific objectives, plus the appetite boundary within which management may operate. This is a very different artefact from the bottom-up risk register most organisations already have — and it should drive the top of the pyramid, with operational and compliance risks feeding up underneath.
Performance — one process, two speeds
Principles 10 through 14 cover the core mechanics: identify, assess, prioritise, respond, portfolio view. Most organisations have these. The failure mode here is uniformity — running the same quarterly refresh on every risk type.
Run the process at two speeds:
- Slow loop, annually: refresh the strategic-risk set during the planning cycle. Update appetite and capacity. Validate the risk taxonomy.
- Fast loop, continuously: a risk-event and near-miss intake that escalates within 24–72 hours, driven by KRIs and incident data. This is where operational, cyber, and conduct risks actually surface.
Tie the two loops together with a portfolio view — a single place where a risk owner can see all the exposures relevant to an objective, across business units. If you cannot answer "what is our aggregate exposure to third-party cloud concentration?" in one query, the portfolio view is notional.
Review & Revision — evidence the learning loop
This is the component most assurance work underweights. It asks: does the organisation actually change behaviour in response to what it learned?
Three practical checks:
- Post-event reviews for every significant incident, with findings tracked to closure and a six-month look-back on whether the change stuck.
- Control rationalisation — a standing workstream to retire duplicative or low-value controls, not just add new ones. Control inventories only grow unless someone is paid to prune them.
- Framework self-assessment every two years against the 20 principles, with the board seeing the gap list and the remediation plan.
Information, Communication & Reporting — the under-engineered component
This is where most ERM operating models break. The framework is coherent, the governance is in place, but the data layer is a patchwork of spreadsheets. A few design principles help:
- A single controlled risk taxonomy that the register, the KRI library, the control library, and the obligations register all reference.
- Clear separation between source systems (incident tickets, audit findings, compliance breaches) and the analytical layer that aggregates them.
- One version of the risk register, with history. If reports diverge because three copies are in circulation, the information layer has failed.
Organisations that treat this component as an IT project — with a proper data model, ideally semantic — get leverage out of the other four components that spreadsheet-based setups never do.
Key takeaways
- Treat the five COSO components as the specification for an operating model, not an assurance checklist — build governance, process, and information layers together.
- Make risk appetite concrete enough to change real decisions, and track how often it actually does.
- Integrate risk into strategy by stress-testing the assumptions behind each strategic objective, not by appending a risk register afterwards.
- Run performance at two speeds — an annual strategic loop and a continuous operational loop — and tie them together with a real portfolio view.
- Invest in the information layer. ERM without a coherent data model stays decorative.