Skip to main content

Important Improvements Included in COSO’s New Enterprise Risk Management Framework

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) released the final version of its revised enterprise risk management (ERM) Framework, Enterprise Risk Management–Integrating with Strategy and Performance, in September 2017. In the Framework, COSO has come a long way since its initial exposure draft. The Framework takes important steps toward breaking down the siloed nature of managing risk and integrating the responsibly throughout the organization.
In IFAC’s response to the 2016 exposure draft, we noted that, while the Executive Summary stressed the importance of integration of risk management, the draft Framework itself did not yet sufficiently live up to those aspirations. The final version of the framework now highlights the importance of considering integrating risk in both determining strategy and in driving performance. In this respect it is now closely aligned with the central theme of IFAC’s thought paper From Bolt-on to Built-in, which addresses the centrality of managing risk as an integral part of the overall management of an organization.
For starters, the subtitle of the Framework has been changed from “Aligning Risk with Strategy and Performance” to “Integrating with Strategy and Performance,” highlighting the importance of integration in the final framework. In addition, a new chapter has been included on integrating risk management with strategy-setting through performance. In addition, the new signature graph—no longer a cube—now clearly depicts how the various enterprise risk management components are aligned with elements of common business models. 
Also, the components themselves are now, rightfully, stripped from their siloed risk focus and placed in a more logical order, following the business model.
Exposure Draft
1. Risk Governance and Culture
2. Risk, Strategy, and Objective-Setting
3. Risk in Execution
4. Risk Information, Communication, and Reporting
5. Monitoring Enterprise Risk Management Performance
Final Document
1. Governance and Culture
2. Strategy and Objective-Setting
3. Performance
4. Review and Revision
5. Information, Communication, and Reporting

While the subsequent guidance can support organizations in evaluating and improving their enterprise risk management arrangements, not all of the practice recommendations fully support the new approach. There is still a fair bit of inevitable “risk hunting” to satisfy those organizations that cannot say (yet?) goodbye to the old guard (think risk registers). Ultimately, it is not about managing risk or being in control, but about effectively setting and achieving your organization’s objectives. As long as you keep this big picture in mind, the revised framework provides many tips and hints.
The main recommendation in our 2016 comment letter was to: “reverse the perspective from risk-based to (strategic) objective-based: placing organizational strategy and execution at the forefront and then showing how organizations could actually integrate the management of risk into their (already existing) ‘culture, capabilities, and practices.’” We at IFAC believe that, in this final version, COSO has come a long way since the exposure draft, and by making this turn is now better following through with its own intentions.
Take a read through the framework yourself, and let us know your thoughts!
IFAC actively participated in the COSO Board’s Advisory Council for this update and we congratulate the COSO Board on this landmark revision.

Vincent Tophoff
Vincent Tophoff is senior technical manager with the Professional Accountants in Business (PAIB) Committee of IFAC. Previously, he was a partner at INTE-Q Integration Management, a management accountancy consulting firm in The Netherlands and senior lecturer at the postgraduate accountancy program of the Vrije University in Amsterdam. 
See more by Vincent Tophoff 

Comments

Popular posts from this blog

IFRS FOUNDATION PUBLISHES CASE STUDY REPORT: BETTER COMMUNICATION—MAKING DISCLOSURES MORE MEANINGFUL

The IFRS ®  Foundation has published a case study report showing how companies from different parts of the world have improved communication in their IFRS financial statements.  Better Communication in Financial Reporting—Making disclosures more meaningful  contains six case studies from varied industries. Its aim is to illustrate how improvements can be made and inspire other companies to initiate their own improvement projects. The report explains the process these companies have gone through to improve disclosures in the notes to their IFRS financial statements and shows examples of the improvements made. By identifying what information is relevant, prioritising it appropriately and presenting it in a clear and simple manner, they have made their financial statements easier for investors to read and understand. Through the use of examples, the report shows that relatively small changes can significantly improve the quality of the financial information that compa...

List of IFRIC Interpretations

The IFRS Foundation provides free access (through Basic registration) to the PDF files of the current year's IFRIC ®  Interpretations (Part A of the Issued Standards—the Red Book), as well as available translations of Interpretations. This section also provides high level and non-technical summaries for the Interpretations.  The full Standards with all accompanying documents are available for  Premium subscribers on eIFRS . For more information about what is provided for free and why, visit our unaccompanied Standards FAQ page . Interpretation name IFRIC 1 Changes in Existing Decommissioning, Restoration and Similar Liabilities IFRIC 2 Members’ Shares in Co-operative Entities and Similar Instruments IFRIC 4 Determining whether an Arrangement Contains a Lease IFRIC 5 Rights to Interests arising from Decommissioning, Restoration and Environmental Rehabilitation Funds IFRIC 6 Liabilities arising from Participating in a S...

IFRS Foundation Trustees publish findings on independent perception research

The Trustees of the IFRS ®  Foundation, responsible for the governance and oversight of the International Accounting Standards Board (Board), today published the findings of independent research commissioned to better understand stakeholder attitudes towards the work of the IFRS Foundation and the Board. The research found that the IFRS Foundation is perceived as being successful in achieving its public interest mission, and is highly rated for transparency, independence and professionalism. The research also identifies areas for further development, mainly around the complexity of its Standards, the timeliness of its standard-setting process and the need to respond quickly in a changing world. The research was conducted between February and May 2017 by Ebiquity, an independent research agency. Ebiquity interviewed 50 senior stakeholders from around the world. That research was then supplemented with online surveys of members of the IFRS Foundation’s advisory bod...