Key Takeaways
- The 2017 COSO enterprise risk management framework repositioned ERM from a process layered on operations to something inseparable from strategy and value creation and most organisations are still running the old version.
- According to PwC's Global Risk Survey, organisations that embrace risk management as a strategic capability are twice as likely to expect revenue growth above 11 percent in the following year, a concrete performance argument, not a governance one.
- KPMG's 2025 data shows that only 64 percent of organisations have integrated risk and resilience into their business strategy and planning, which explains why Forrester found that nearly 75 percent experienced at least one critical risk event in the past year.
- Risk appetite must be set during the strategy-setting process, not added as a constraint afterwards, treating it as a post-hoc filter is what produces a register full of risks that nobody connects to the decisions being made in the boardroom.
- The five COSO 2017 components only produce results when each of the 20 underlying principles has a named owner, a structured review cycle, and visible progress. The framework without that infrastructure is a document, not a management discipline.
Why the 2017 revision changed everything and why most organisations missed it
The COSO enterprise risk management framework is the most widely recognised and applied ERM framework in the world. Its 2017 revision, formally titled Enterprise Risk Management: Integrating with Strategy and Performance, went beyond updating the language. It repositioned enterprise risk management from a compliance function layered on top of business operations to something embedded in strategy, performance management, and value creation. The revision represents a different theory of what risk management is for.
The original 2004 COSO framework was built around internal control. Enterprise risk management was conceived as a way to make sure nothing bad happened that the organisation had not accounted for. The 2017 update added a dimension the 2004 version barely touched: the relationship between risk and the pursuit of objectives. COSO 2017 is explicit that organisations face risk when they make strategy, not only when they operate. Choosing the wrong strategic direction, setting objectives that do not account for uncertainty, failing to revisit strategy when conditions shift — these are enterprise risks too.
The performance data behind the COSO enterprise risk management strategic argument is striking. PwC's Global Risk Survey found that organisations embracing risk management as a strategic capability are twice as likely to expect revenue growth of 11 percent or more in the following year compared with those treating it as a compliance obligation. That finding reframes the conversation entirely. The question is no longer whether you can afford a proper ERM programme. It is whether you can afford to keep running a process-focused one.
And the evidence suggests many organisations are doing exactly that. According to KPMG's 2025 Chief Audit Executive Survey, only 64 percent of organisations have integrated risk and resilience into their business strategy and planning. Forrester's research has consistently found that large proportions of enterprises experience at least one critical risk event in any given year, a figure that tracks closely with the share of organisations that have not made risk a genuine input to strategy. The gap between what COSO 2017 intends and what most organisations actually do is where that exposure lives.
The five components of COSO 2017 and what integration actually requires
The COSO 2017 framework is built around five components and 20 underlying principles. Understanding the components is straightforward. Making them operational is the hard part.
Governance and culture carries more weight than most implementation guides acknowledge. It covers board oversight, tone at the top, and the accountability structures that define who is responsible for risk. Culture matters here in a specific way: an ERM programme that exists in a binder but is not reflected in how people behave is not an ERM programme. The 20 principles ask whether risk oversight is genuinely embedded in governance structures, not whether a risk committee exists on paper.
Strategy and objective setting is where the 2017 revision made its boldest move. This component requires that risk appetite be defined during the strategy-setting process. In practice, many organisations define strategy first and then ask the risk function to assess it, which means risk management arrives after the important decisions have already been made. COSO 2017 says that is the wrong sequence. Risk appetite and business context are inputs to strategy.
Performance is the component most familiar to operational risk teams. It covers identifying and assessing risks to the achievement of objectives, prioritising those risks, and implementing responses. This is where the risk register lives. COSO 2017 pushes this beyond the standard probability-and-impact matrix by emphasising the relationship between risk response and value creation. The question is not just whether a risk is high or low, but what the organisation is prepared to accept in pursuit of its objectives and whether its responses reflect that appetite coherently.
Review and revision addresses what happens when conditions change. Many ERM programmes treat the risk register as an annual exercise, reviewed at the start of the financial year and largely forgotten until the next audit. COSO 2017 is explicit that risk assessment should be continuous, responsive to strategic and environmental change, and connected to performance reporting. The register reviewed in January should look different by April if anything material has shifted.
Information, communication, and reporting closes the loop. Risk information needs to flow in two directions: upward to the board and leadership, and downward to the teams responsible for managing specific risks. The 2017 framework distinguishes between risk data and risk intelligence. A board receiving a colour-coded matrix without narrative context is receiving data. A board receiving an assessment of how the risk profile has changed, what the current exposure means for strategic objectives, and what management is actually doing about it is receiving intelligence. These are different things, and they require different disciplines to produce.
Where the gap between document and discipline opens up
Picture a construction company with a well-structured ERM framework. The five components map cleanly to the 2017 update. The risk committee meets quarterly. The register is maintained in a shared folder.
The connection between that register and the strategic planning process does not exist. Risk appetite is defined in a separate policy document that the strategy team consulted three years ago and has not revisited since. Performance discussions happen in the management meeting. Risk discussions happen in the risk committee meeting. The two groups rarely share conclusions. When a major infrastructure project goes over budget by 30 percent, the post-mortem reveals that the risks were logged, but nobody connected them to the original decision to take on that project scope.
This is not a failure of the COSO framework. It is a failure to close the gap between the framework as a document and the framework as a management discipline. COSO 2017 demands that the five components work as an integrated system.
The gap shows up most clearly in the review and revision component. Continuous review sounds achievable in a framework document. In practice, it requires someone to own each risk, a structured cadence for checking in on that risk, and a mechanism for surfacing changes to leadership before they become incidents. Without that infrastructure, the annual review cycle persists by default, and the high proportion of organisations reporting critical risk events becomes predictable.
Translating the 20 principles into daily management practice
The 20 principles underlying the COSO 2017 components are not a checklist to work through once. They describe how a mature ERM programme functions on a continuous basis. And continuity is the challenge.
The principles that tend to fall shortest in practice are the ones requiring ongoing action: reviewing and revising risk responses as conditions change, maintaining communication between risk owners and leadership, and connecting risk performance to strategic performance discussions. None of that can be done in an annual planning cycle. It requires operational infrastructure.
Named ownership is the starting point. Each risk needs a person accountable for monitoring it, responding to it, and reporting on it. Without a name, a risk is something the organisation has noted. With a name, it is something being managed.
Action tracking follows from ownership. Measures attached to risks need owners, due dates, and visible progress. The question of who is doing what by when should have a clear answer at any point in the review cycle, not only when an audit prompts the question.
Structured review cycles replace the annual-review default. Risk owners need a prompt to review their risks on a schedule that reflects the risk's volatility. A risk tied to a fast-moving market condition deserves a review cadence that matches its pace, not the organisation's audit calendar.
Dashboards carry the signal from the register to leadership. The board does not need every risk in the register. It needs an accurate read on risk posture, the movement of high-priority risks over time, and whether mitigation measures are closing the gap between current and target assessments. Producing that view manually is expensive and slow. Producing it automatically, from a register that is current, is what transforms risk data into the risk intelligence COSO 2017 calls for.
Named ownership is the default in Risk Companion, not an option. Measures attach to risks with owners and due dates. Configurable alerts prompt review before deadlines pass. The dashboards surface the current and target assessment gap, mitigation progress, and upcoming deadlines in a view that leadership can read without opening the full register. The risk register is where every risk lives, with its owner, its score, and its next step, so what gets discussed in a workshop does not quietly disappear three weeks later.
Risk Companion's framework configuration means the scoring methodology, matrix, and risk categories can be aligned with the way your organisation already defines strategic objectives, so the tool reflects your method rather than imposing a different one.
The performance argument is stronger than the compliance one
The conversation about enterprise risk management still defaults to compliance in many organisations. Boards ask whether the programme satisfies the auditor. Management asks whether the framework is documented. The questions are reasonable, but they are the wrong frame.
The PwC finding makes the performance argument directly: organisations treating risk management as a strategic capability are twice as likely to expect strong revenue growth. Organisations that connect risk to strategy, that use risk intelligence to inform decisions rather than justify them after the fact, and that maintain a live picture of their exposure are not just better governed. They perform differently.
The KPMG 2025 figure of 64 percent integration tells us that a third of organisations have not yet made that connection, despite eight years of COSO guidance pointing in that direction. That is the gap worth closing.
The shift is not complicated in principle. Risk appetite becomes an input to the strategic planning conversation. Risk information flows into performance discussions. The board receives a narrative, risks have owners and deadlines, and the register reflects current conditions rather than last January's. Each of those changes is achievable without a six-month implementation.
What they require is operational infrastructure: a system that holds the register, maintains accountability, tracks progress, and presents the signal clearly enough that leadership can act on it.
If your enterprise risk management programme is still a process layered on top of operations rather than a strategic instrument integrated with how you set objectives and measure performance, it is worth seeing how Risk Companion supports that shift. The free 14-day trial builds a demo project from your own organisation's profile, so you can see how named ownership, structured review cycles, and current-versus-target dashboards work together before you commit to anything.
Ready to improve your risk management?
See how Risk Companion can help you implement these best practices with powerful, easy-to-use tools. Sign up and we'll prepare a demo project tailored to your company.