Why Your ERM Program Cannot Get a Seat at the Strategy Table


Every chief risk officer reading this knows the conversation. The CEO asks what the top three strategic risks are this quarter. The answer comes from a quarterly risk register refresh and a heat map. The CEO nods, thanks the CRO, and moves on. Nothing changes.

The new COSO/Crowe practitioner guide, From Guidance to Action: Exploring Practical Enterprise Risk Management, just put a number on how widespread this pattern is. Ninety-three percent of enterprise risk management programs are stuck on the wrong side of the strategy conversation, and the reason is not what most risk leaders have been told.

What the Survey Actually Found

The numbers are stark. Ninety-eight percent of risk leaders believe ERM should play a more strategic role. Seven percent say it actually does. Fifty-four percent of programs are perceived as a compliance or assurance function, against only twenty-eight percent seen as a strategic partner. And just twenty percent of respondents report high psychological safety in leadership risk discussions.

The COSO/Crowe authors interpret these findings as an implementation problem. They prescribe ten operating disciplines, a five-hour-a-week minimum viable rhythm, and a cultural shift toward candor. Each prescription is sound. After three decades observing and advising on integrated risk management programs, I can say with confidence that none of them will close the gap. The reason is not behavioral. It is structural. Most organizations have conflated ERM with GRC, and that single conflation explains almost every finding in the COSO survey.

The Conflation That Sends ERM Down the Wrong Path

In most organizations, ERM and GRC are treated as the same function. They report through the same leader. They run on the same technology platform. They produce the same artifacts. They serve the same primary audience: the audit committee. Many organizations cannot articulate the difference between the two when asked directly.

The difference is fundamental. GRC bridges the risk objectives of Compliance and Assurance. Its job is to produce evidence that policies are in place, controls are operating, and the organization can demonstrate to auditors, regulators, and oversight committees that risks have been identified and managed. This work is essential and in many jurisdictions legally required.

ERM bridges the risk objectives of Assurance and Performance. Its job is to produce decision-useful uncertainty signals that help executives, capital allocators, and boards understand whether strategic assumptions are holding and where the organization needs to adjust. Performance is the risk objective on the strategic edge of the compass, and ERM is the only function structurally positioned to bridge to it.

When ERM is conflated with GRC, the bridge to Performance is severed. The function becomes a second instance of GRC running on GRC infrastructure with GRC reporting lines, producing GRC outputs for GRC audiences. The 54 percent of programs perceived as compliance functions are not failing to be strategic. They are succeeding at being GRC, which is what they were structurally built to do. No amount of better discipline moves a function back to its proper position. That requires a structural decision.

Why Performance Is the Risk Business Leaders Actually Care About

The 98 percent who want ERM to be more strategic are not asking for more compliance attestations. They are asking for Performance signals. Performance is the risk tied directly to whether the organization achieves its goals: missed targets, failed strategic bets, capital allocated to the wrong initiatives, competitive position lost to a pivot the executive team did not see coming. It is the risk every CEO, CFO, and board member loses sleep over.

When a board endorses a major capital investment, the question on every director's mind is not whether the right controls are in place. It is whether the underlying assumptions will hold, what would signal that they are not holding, and how quickly the organization can adjust. These are Performance questions, and they determine whether the organization wins or loses in the market.

This is also why the 20 percent psychological safety figure matters. Compliance-anchored work rewards certainty: a control either passed or failed. Performance-anchored work rewards informed uncertainty: a range is wider than expected, an assumption is weakening, a trigger is approaching. An ERM program conflated with GRC cannot produce Performance signals because it is wired for certainty outputs. Business leaders have been saying this for years in language that sounds like criticism: "You are slowing us down. You are checking boxes. You are not adding value." What they are actually saying is that the function in front of them is bridging to the wrong objectives.

How the IRM Navigator Model Resolves the Conflation

The IRM Navigator Model maps integrated risk management as a compass with four domains arranged around a central risk core. GRC anchors the west position with policies. ERM anchors the north with goals. Operational Risk Management (ORM) anchors the east with processes. Technology Risk Management (TRM) anchors the south with assets.

The four risk objectives sit between the domains, and each domain bridges the two adjacent to it. GRC bridges Compliance and Assurance. ERM bridges Assurance and Performance. ORM bridges Performance and Resilience. TRM bridges Resilience and Compliance. This geometry defines what each domain can and cannot produce, and it makes the conflation problem visible. When organizations conflate ERM with GRC, the north anchor empties out, the Performance objective loses its bridge, and the entire strategic edge of the model goes unserved.

Properly positioned ERM is anchored to goals, not policies. Its data feeds come from operational, financial, and external systems that reveal whether strategic assumptions are holding. Its reporting cadence aligns to planning cycles, capital allocation gates, and major delivery checkpoints. Its outputs are scenario ranges, leading indicators, trigger thresholds, and portfolio-level exposure views. Its primary audience is the executive team and the strategy committee of the board, with the audit committee as a secondary consumer. GRC continues to do its work at the west position. Each domain produces what it is structurally capable of producing. Integrated risk management actually integrates.

What This Means for the Risk Leader Reading the COSO Paper

The COSO paper is worth reading and worth applying. Its ten disciplines describe the right behavior for an ERM function that occupies the correct position on the compass. What the paper does not give the risk leader is the structural argument for separating ERM from GRC and repositioning it to its proper anchor point. That argument lives in the compass. A risk leader who walks into her CFO's office asking for more headcount to run better ERM meetings will be denied. A risk leader who walks in with a diagnosis that her ERM function has been conflated with GRC, severing the bridge to the Performance objective business leaders most want addressed, has a structural conversation worth having.

GRC is not the problem. GRC is doing exactly what it is positioned to do. The problem is that ERM has been stacked on top of GRC instead of occupying its own position at the north of the compass. Separating the two does not diminish GRC. It restores the integrated structure that lets both functions produce what they are designed to produce.

The 98 percent who want ERM to be strategic are right to want it. The 7 percent who have achieved it have done something more than improve discipline. They have separated ERM from GRC and positioned it where it belongs. The path from one number to the other runs through the compass, not the calendar.

John A. Wheeler

John A. Wheeler is the founder and CEO of Wheelhouse Advisors, a global risk management strategy and technology advisory firm. With over three decades of experience spanning executive management, finance, risk management, audit, and IT, John is a world-renowned expert in integrated risk management technology, executive leadership, and corporate governance.

https://www.linkedin.com/in/johnawheeler/
Previous
Previous

The NC State ERM Summit Just Proved the COSO Survey Right

Next
Next

What ServiceNow Just Announced Is Bigger Than a Security Story