The NC State ERM Summit Just Proved the COSO Survey Right
Source: wheelhouseadvisors.com
Last week, more than 110 enterprise risk management practitioners gathered at NC State's Poole College for the 2026 ERM Roundtable Summit. The case studies they shared were compelling. The programs they described were mature, relationship-driven, and genuinely effective at connecting risk functions across large, complex organizations. They also illustrated, with striking precision, exactly why the COSO/Crowe survey published earlier this year found that only 7 percent of ERM programs are seen as strategic partners by the business.
That is not a criticism of the practitioners. It is a diagnosis of where most ERM programs sit on the maturity curve, and what the next investment must accomplish to move beyond it.
What the Summit Cases Actually Showed
Kristy Absher of ExxonMobil described what she called "aligned assurance": ERM connecting compliance, internal audit, legal, and operations into a unified system with shared visibility across the three lines of defense. Chelsea Javorsky Smith of Westinghouse described a program sustained through years of organizational upheaval by embedding ERM in strategic planning and maintaining strong cross-functional relationships. "If I didn't maintain those strong relationships," Smith said, "they would never invite me to the table."
Both programs reflect a successful investment in GRC. That investment is exactly what the IRM Navigator™ Curve prescribes at the Foundational stage, where primary investment in GRC builds the basic compliance elements and policy infrastructure that every mature risk program requires. Both organizations have completed that work. Their programs are coordinated, aligned, and operating with standardized reporting across functions.
That is precisely the Coordinated stage of the IRM Navigator™ Curve, and it is exactly where the COSO data shows most programs are stalled.
The Investment Sequence the Curve Prescribes
The IRM Navigator™ Curve, developed by Wheelhouse Advisors, maps organizational progression from Risk Dysfunction to Risk Agency across five stages: Foundational, Coordinated, Embedded, Extended, and Autonomous. Each stage is driven by a specific investment shift.
GRC investment carries an organization from Foundational to Coordinated. That is its job, and Absher and Smith have demonstrated what excellent GRC investment looks like at scale inside two of the most operationally complex organizations in the world.
The investment that carries an organization from Coordinated to Embedded is ERM, but ERM positioned correctly on the compass. As John A. Wheeler analyzed in The RiskTech Journal this week, the IRM Navigator™ Model places ERM at a specific position bridging Assurance and Performance, anchored to Goals. Its solution areas are Board Risk Oversight, Corporate Governance, Strategic Risk, and Enterprise Legal. These are not assurance outputs for the audit committee. They are decision-support signals for the executive team and the board's strategy committee.
When ERM is defined, as the Poole summit framed it, as the function that integrates compliance, internal audit, legal, and operations across the three lines of defense, it is occupying GRC's position on the compass. The bridge to Performance remains unbuilt. The investment that should be moving the organization toward Embedded is instead reinforcing what GRC already accomplished at Coordinated.
The COSO finding that 54 percent of ERM programs are perceived as compliance or assurance functions is not a failure of execution. It is a predictable outcome of investment misapplied.
Embedded Is Not Just Strategic Planning
This is the second point the summit cases make visible, and it matters as much as the first. The transition to Embedded is not simply about getting ERM into the strategic planning process. That is necessary but not sufficient. Embedded means risk is woven into business processes across the full operational domain, sustained by real-time monitoring and technology infrastructure that does not depend on individual relationships to function.
The IRM Navigator™ Model shows what that domain looks like in practice. The Embedded stage unlocks the ORM position on the compass: Operational Risk Management, spanning Insurance and Claims, ESG and Sustainability Risk, Supplier and Third-party Risk, Environmental Health and Safety, and Business Continuity. These are not abstract categories. They are exactly the domains the Poole summit practitioners identified as their most pressing operational challenges.
Smith's account of the COVID response at Westinghouse, an 18-month cross-functional assessment engaging eight workstreams across supply chain, workforce, and infrastructure, is a description of ORM work executed at Embedded-stage intensity. It worked because Smith built the relationships and the strategic alignment to make it work. The question is whether that capability would survive her departure, an acquisition, or the acceleration of risk events that agentic AI is already producing.
At the Embedded stage, it does, because risk is in the process, not in the relationship.
What the AI Governance Gap Signals
The round-robin discussions that closed the Poole summit surfaced three shared pressures: AI and data governance, geopolitical uncertainty, and elevating ERM's strategic impact. The first two belong squarely in the ORM and Extended-stage domains of the IRM Navigator™ Curve.
AI governance is not a risk topic to be added to the quarterly register. Agentic systems are already making consequential decisions at machine speed across enterprise workflows. Governing that environment requires real-time monitoring embedded in business processes, cross-domain analytics, and third-party risk visibility. These are Embedded and Extended stage capabilities. Organizations that treat AI governance as one more committee agenda item will find themselves governing yesterday's risk while tomorrow's is already executing.
The fact that AI governance surfaced in a round-robin discussion rather than as a structured track at the summit is itself a signal. It is the kind of challenge that feels manageable at the Coordinated stage and becomes urgent at the moment the organization realizes its infrastructure cannot keep pace.
The Path the COSO Guidance and the Curve Share
The COSO/Crowe practitioner guide published this year names the right behaviors for moving ERM toward strategic impact. Wheeler's analysis in The RiskTech Journal this week provides the structural argument for why those behaviors, applied inside the wrong positional frame, will not close the gap on their own.
Used together, they give ERM leaders a complete picture. The COSO disciplines describe what excellent execution looks like. The IRM Navigator™ Model shows where ERM must be positioned to produce the outputs that execution is meant to generate. The IRM Navigator™ Curve shows the investment sequence that gets an organization there, domain by domain, stage by stage.
The Poole summit practitioners are not at the beginning of that journey. They have completed the GRC investment that built their Coordinated-stage programs. They are now at the inflection point where the next investment must shift to ERM in its proper compass position, unlocking not just a seat at the strategy table but the full operational risk domain their organizations are already demanding they govern.
That analysis, and the specific guidance for making that investment shift, is available exclusively on The RTJ Bridge at wheelhouseadvisors.com/rtj-bridge.