
Structure risk management based on the COSO ERM guidelines
Structure risk management based on the COSO ERM framework, connecting appetite, objectives, risks, controls and responses to qualify decisions and protect value generation.

✦ Challenge
Your organization it still doesn't have a structured risk management process in accordance with ISO 31000?
Symptoms that your organization’s risk management is still not compliant with ISO 31000:
The COSO ERM is present in the policies, but it does not translate into consistent practices.
The risks are assessed without a clear connection to strategic objectives.
The appetite for risk does not guide prioritization and decision-making.
Each area uses different criteria to assess and respond to risks.
Controls and treatment plans are not related to residual exposure.
The revisions depend on manual charges from the Risk area.
The leadership receives fragmented or outdated information about the risks.
The organization cannot demonstrate how the risks influenced its decisions.
✦ Solution
Strengthen risk management with the COSO ERM guidelines
The Risk Management solution operationalizes the COSO ERM guidelines by linking risks to the organization’s strategy, objectives, and performance, structuring the definition of appetite, the identification and assessment of risks, their prioritization, responses, controls, and treatment plans.
With periodic reviews, evidence, indicators, reports, and a history of decisions, it allows demonstrating how risks are considered in the execution of the strategy and in the protection and generation of value.
It centralizes methodologies, criteria, matrices, responsible parties, controls, treatment plans, and evidence, promoting consistent application across the various areas.

Integration with the strategy
Link risks, appetite, objectives, indicators and initiatives to incorporate risk analysis into strategic decisions.
Standardized criteria
Structure categories, evaluation criteria, responsibilities, and responses to maintain a consistent approach across the organization.
Traceability and reporting
Centralize assessments, reviews, evidence, and histories to track the evolution of risks and support accountability to leadership.
✦ Implementation steps
How to operationalize the COSO ERM from governance to reporting
Structure risk management in connected stages, from the definition of the context, criteria, and risk appetite to the identification, assessment, treatment, monitoring, and communication of exposures.
01Governance and culture
- Structuring the hierarchy and the corporate risk model.
- Define policies, roles, responsibilities, and owners of risks.
- Standardizing categories, taxonomies, and evaluation criteria.
- Distributing responsibilities between the Risk area and the managers.
02Strategy and goal setting
- Link risks to strategic objectives and initiatives.
- Define appetite, tolerance and exposure limits.
- Configure probability and impact matrices.
- Evaluate risks associated with strategic choices and priorities.
03Performance
- Identify risks, causes and consequences.
- Evaluate inherent risks and prioritize them according to appetite.
- Define responses, controls and treatment plans.
- Calculate and monitor residual exposure.
- View relationships using the Bow-Tie diagram.
04Revision and improvement
- Program periodic reviews of risks and controls.
- Monitor changes in criticality and exposure.
- Reevaluate risks in the face of internal or external changes.
- Keep historical records, evidence, and versions of the evaluations.
- Monitoring the execution and effectiveness of the treatments.
05Information, communication and reporting
- Consolidate risks, controls, and treatments in dashboards.
- Issue notifications about revisions, deadlines, and relevant changes.
- Generate reports for senior management and committees.
- Integrate data from other systems and corporate sources.
- Support meetings and decisions with up-to-date information.
Who is this solution for?
The solution connects the different roles involved in governance, strategy, management, and risk oversight, distributing responsibilities and enhancing the consistency of the process across the entire organization.
Risk Management Manager
It structures and maintains the corporate model aligned with the COSO ERM.
Governance, Risk and Compliance Leadership
It connects guidelines, policies, responsibilities, and practices.
Strategy Manager
It relates the risks to the objectives, indicators and strategic initiatives.
Manager or owner of the risk
Assess, treat, and monitor the risks under your responsibility.
Senior management and committees
They use risk information to monitor the strategy and make decisions.
Internal Audit
It assesses the consistency and effectiveness of the risk management process.
✦ Features
Resources for to integrate risks, strategy, performance and controls
Resources to centralize risks, controls, assessments, and treatments and to connect risk management to the objectives, processes, and decisions of the organization.
Strategic objectives
Processes

Risks and Controls

Risk Matrix
Control Tests
Self-Assessment Control
Control reviews
Action plan

Continuous Feedback
Custom dashboards
Executive presentations

Meetings
✦ Schedule your demo
Put the COSO ERM guidelines into practice
Learn about the Actio COSO ERM Risk Management solution and discover how to structure a process that integrates strategy, performance, and decision-making.
✦ Frequently Asked Questions
Clear your doubts about Risk Management and COSO ERM
Check out the main questions about how to structure and monitor risk management based on the guidelines of ISO 31000.
What is the COSO ERM?
The COSO ERM is a corporate risk management framework that integrates risk into the organization’s strategy and performance. Its structure guides aspects such as governance, goal setting, risk assessment and response, and review and reporting.
How does the Actio solution help to implement the COSO ERM?
The solution allows for structuring the elements necessary to put the COSO ERM guidelines into practice in a single environment, connecting objectives, risk appetite, assessments, controls, treatments, revisions, evidence, and reports.
Is it possible to relate the risks to the strategic objectives?
Yes. The platform allows you to associate risks with objectives, indicators, and strategic initiatives, making it easier to analyze how different exposures can affect the execution of the strategy and the expected results.
How is appetite for risk incorporated into management?
The organization can establish criteria, tolerances, and exposure limits and use them as a reference to evaluate, prioritize, and respond to risks. This helps to bring risk decisions closer to business priorities and objectives.
Does the solution allow for monitoring inherent and residual risks?
Yes. It is possible to record assessments, relate controls and treatments to risks and track the evolution of exposure, supporting the analysis of the difference between the risk before and after the measures adopted.
How does the platform support reviews and reports?
Assessments, controls, treatments, evidence, and histories can be centralized and monitored through dashboards and reports, providing up-to-date information for managers, committees, audit, and senior management.
Does the use of the platform ensure compliance with the COSO ERM?
Yes. The risks can be related to strategic objectives, processes, projects, and other relevant elements, broadening the view on their possible impacts on the organization.
How does the platform help with risk monitoring?
The platform supports the structuring and execution of processes aligned with the COSO ERM guidelines. Effective adherence to the framework also depends on the governance, policies, processes, responsibilities, and practices adopted by each organization.
How does the platform help with risk monitoring?
The platform supports the structuring and execution of processes aligned with the COSO ERM guidelines. Effective adherence to the framework also depends on the governance, policies, processes, responsibilities, and practices adopted by each organization.