Key Takeaways
- The 2017 COSO enterprise risk management framework repositioned ERM from a compliance process layered on operations to something embedded in strategy and value creation. Many organisations are still running the pre-2017 version in practice, even when the framework documentation says otherwise.
- The PwC 2022 Global Risk Survey found that organisations embracing risk management as a strategic capability are almost twice as likely to project revenue growth of 11 percent or more in the following year. The performance argument for ERM is stronger than the compliance one.
- The KPMG 2025 Enterprise Risk and Resiliency Survey found that only 64 percent of organisations have integrated risk and resilience into their business strategy and planning. A third of organisations are still to make that connection despite eight years of COSO guidance pointing in that direction.
- COSO 2017 requires risk appetite to be set during the strategy-setting process, as an input to the decisions being made rather than a constraint applied afterwards. Organisations that define strategy first and ask the risk function to assess it afterwards are running a sequence the framework explicitly rejects.
- The five COSO 2017 components only produce results when the 20 underlying principles have operational infrastructure behind them: named owners, structured review cycles, and visible progress on measures. The framework as a document produces compliance. The framework as a management discipline produces performance.
Why the 2017 revision changed everything and why so many organisations missed it
The COSO enterprise risk management framework is the most widely recognised and applied ERM framework in the world, and its 2017 revision, formally titled Enterprise Risk Management: Integrating with Strategy and Performance, went well beyond updating the language. It repositioned enterprise risk management from a compliance function layered on top of business operations to something embedded in strategy, performance management, and value creation, representing a fundamentally different theory of what risk management is for.
The original 2004 COSO framework was built around internal control, conceiving enterprise risk management primarily as a way to prevent adverse outcomes the organisation had failed to anticipate. The 2017 update added a dimension the 2004 version barely touched: the relationship between risk and the active pursuit of objectives.
COSO 2017 is explicit that organisations face risk when they make strategy as well as when they operate. Choosing the wrong strategic direction, setting objectives without accounting for uncertainty, and failing to revisit strategy when conditions shift are all enterprise risks.
The performance data behind the argument is striking. The PwC 2022 Global Risk Survey found that organisations embracing risk management as a strategic capability are almost twice as likely to project revenue growth of 11 percent or more in the following year, compared with those treating it as a compliance obligation.
That finding reframes the conversation entirely. The question shifts from whether you can afford a proper ERM programme to whether you can afford to keep running a process-focused one.
The evidence suggests many organisations are doing exactly that. The KPMG 2025 Enterprise Risk and Resiliency Survey found that only 64 percent of organisations have integrated risk and resilience into their business strategy and planning.
Forrester's ongoing research into enterprise risk management consistently finds that the majority of enterprises experience at least one critical risk event in any given year. The gap between what COSO 2017 intends and what many organisations actually do is where that exposure lives.
The five components of COSO 2017 and what integration actually requires
The COSO 2017 framework is built around five components and 20 underlying principles, and while the components are straightforward to understand, making them operational is where the real work lies.
Governance and culture carries more weight than many implementation guides acknowledge. It covers board oversight, tone at the top, and the accountability structures that define who is responsible for risk. Culture matters here in a specific way: an ERM programme that exists in a binder but goes unreflected in how people actually behave is a document, not a discipline. The 20 principles ask whether risk oversight is genuinely embedded in governance structures, going beyond whether a risk committee exists on paper.
Strategy and objective setting is where the 2017 revision made its boldest move, requiring that risk appetite be defined during the strategy-setting process. In practice, many organisations define strategy first and then ask the risk function to assess it, which means risk management arrives after the important decisions have already been made. COSO 2017 positions risk appetite and business context as inputs to the strategy-setting process, with the sequence mattering as much as the content.
Performance is the component most familiar to operational risk teams, covering identification and assessment of risks to objectives, prioritisation, and response. The risk register lives here. COSO 2017 pushes this beyond the standard probability-and-impact matrix by emphasising the relationship between risk response and value creation. The question extends beyond whether a risk is high or low to what the organisation is prepared to accept in pursuit of its objectives and whether its responses reflect that appetite coherently.
Review and revision addresses what happens when conditions change. Many ERM programmes treat the risk register as an annual exercise, reviewed at the start of the financial year and largely forgotten until the next audit. COSO 2017 is explicit that risk assessment should be continuous, responsive to strategic and environmental change, and connected to performance reporting. The register reviewed in January should look different by April if anything material has shifted.
Information, communication, and reporting closes the loop by requiring risk information to flow in two directions: upward to the board and leadership, and downward to the teams responsible for managing specific risks.
The 2017 framework distinguishes between risk data and risk intelligence. A board receiving a colour-coded matrix without narrative context is receiving data. A board receiving an assessment of how the risk profile has changed, what the current exposure means for strategic objectives, and what management is actually doing about it is receiving intelligence, and producing that intelligence requires a different discipline from producing the data.
Where the gap between document and discipline opens up
Consider a construction company with a well-structured ERM framework. The five components map cleanly to the 2017 update, the risk committee meets quarterly, and the register is maintained in a shared folder.
The connection between that register and the strategic planning process does not exist. Risk appetite is defined in a separate policy document that the strategy team consulted three years ago and has not revisited since. Performance discussions happen in the management meeting. Risk discussions happen in the risk committee meeting. The two groups rarely share conclusions.
When a major infrastructure project goes over budget by 30 percent, the post-mortem reveals that the risks were logged, but nobody connected them to the original decision to take on that project scope.
The failure here is in closing the gap between the framework as a document and the framework as a management discipline. COSO 2017 demands that the five components work as an integrated system.
The gap shows up particularly clearly in the review and revision component. Continuous review sounds achievable in a framework document, but in practice it requires someone to own each risk, a structured cadence for checking in on that risk, and a mechanism for surfacing changes to leadership before they become incidents. Without that infrastructure, the annual review cycle persists by default, and the high proportion of organisations reporting critical risk events becomes predictable.
Translating the 20 principles into daily management practice
The 20 principles underlying the COSO 2017 components describe how a mature ERM programme functions on a continuous basis, and continuity is precisely the challenge most implementations struggle with.
The principles that tend to prove hardest in practice are those requiring ongoing action: reviewing and revising risk responses as conditions change, maintaining communication between risk owners and leadership, and connecting risk performance to strategic performance discussions. These cannot be satisfied within an annual planning cycle and require operational infrastructure to sustain.
Named ownership is the starting point, with each risk requiring a person accountable for monitoring it, responding to it, and reporting on it. The distinction between a risk that has a named owner and one that does not is the distinction between something being managed and something being noted.
Action tracking follows from ownership, with measures attached to risks requiring their own owners, due dates, and visible progress. The question of who is doing what by when should have a clear answer at any point in the review cycle, without waiting for an audit to prompt the question.
Structured review cycles replace the annual-review default, with risk owners prompted to review their risks on a schedule that reflects each risk's volatility. A risk tied to a fast-moving market condition deserves a review cadence that matches its pace, decoupled from the organisation's audit calendar.
Dashboards carry the signal from the register to leadership. The board needs an accurate read on risk posture, the movement of high-priority risks over time, and whether mitigation measures are closing the gap between current and target assessments. A dashboard that updates automatically from a current register is what transforms risk data into the risk intelligence COSO 2017 calls for.
In Risk Companion, the owner field is visible and prominent on every risk and every measure, with due dates and configurable alerts that prompt review before deadlines pass. The dashboards surface the current and target assessment gap, mitigation progress, and upcoming deadlines in a view that leadership can read without opening the full register. The risk register holds every risk with its owner, its score, and its next step, so what gets discussed in a workshop stays visible and owned in the weeks that follow.
Risk Companion's framework configuration means the scoring methodology, matrix, and risk categories can be aligned with the way your organisation already defines strategic objectives, so the tool adapts to your method and leaves your existing approach intact.
The performance argument is stronger than the compliance one
The conversation about enterprise risk management still defaults to compliance in many organisations, with boards asking whether the programme satisfies the auditor and management asking whether the framework is documented. Those questions are reasonable, but they address the minimum rather than the opportunity.
The PwC 2022 finding makes the performance argument directly: organisations treating risk management as a strategic capability are almost twice as likely to project strong revenue growth. Organisations that connect risk to strategy, use risk intelligence to inform decisions before they are made, and maintain a live picture of their exposure are better governed and perform differently as a result.
The KPMG 2025 figure of 64 percent integration tells us that a third of organisations are still to make that connection, despite eight years of COSO guidance pointing in that direction, and closing that gap is where the performance opportunity lies.
The shift is achievable in principle and in practice. Risk appetite becomes an input to the strategic planning conversation, risk information flows into performance discussions, the board receives a narrative, risks have owners and deadlines, and the register reflects current conditions. Each of those changes can be made without a six-month implementation.
What they require is operational infrastructure: a system that holds the register, maintains accountability, tracks progress, and presents the signal clearly enough that leadership can act on it.
Ready to improve your risk management?
See how Risk Companion can help you implement these best practices with powerful, easy-to-use tools. Sign up and we'll prepare a demo project tailored to your company.