Paul Sobel, the COSO Chairman, asserted recently that ERM frameworks can provide valuable principles during organisational recovery from crises. I disagree. ERM is fundamentally flawed and cannot improve how organisations decide. The evidence for this claim is nearly fifty years of observation and the pandemic itself.

COSO ERM is a published governance framework that links strategy, performance, and oversight through formal enterprise-wide processes for discussing uncertainty.

A marketing-driven belief system

ERM is a marketing-driven belief system without scientific validation. The term originated as a label invented by RIMS to distinguish new business services. COSO adopted it to reinvigorate the Internal Control Framework after the Enron scandal. Neither origin suggests a sound basis for the concept.

First, the word “risk” lacks consistency. It possesses dozens of formal definitions, which renders it useless as a transactional term in a conversation about what to do. Second, one-size-fits-all systems cannot integrate into the distinct operational processes of distinct organisations. They sit beside the business. They do not enter it. As Roger Estall and I argued in Deciding, this is a structural flaw, not an implementation gap. The IIA’s Three Lines Model exhibits the same defect: it draws lines on a chart and calls it governance.

COSO’s 2017 revision of the ERM framework attempted to address some criticism by shifting language from “risk” to “strategy and performance.” The shift was cosmetic. The underlying structure remained a set of generic principles that an organisation is expected to superimpose on its operations. Superimposition is the problem. A framework that sits on top of the business rather than inside its decisions cannot influence those decisions. It can only produce documentation that demonstrates it was consulted. That documentation is compliance, not thinking.

The evidence of ineffectiveness

The evidence of ineffectiveness is not hidden. Across nearly fifty years in this field, I have observed that organisations practising “risk management” maintain entirely separate processes for deciding. The register is in one room. The decision is in another. Survey after survey shows low ERM maturity, yet the standard excuse is that leaders do not understand the concept. They understand it. They recognise it as ineffective. Their risk registers do not help them decide.

COVID-19 was the test. When the pandemic arrived, organisations did not consult their risk registers, risk appetite statements, or business continuity plans. They focused on reducing vulnerability and identifying opportunities. They made decisions. That apparatus was not present in the room where the decisions happened, because it has never been present in that room.

Consider what actually occurred. Boards convened emergency meetings. Executives made rapid decisions about workforce safety and liquidity. They did what every person deciding under pressure does: stated a purpose, identified what they could do, assessed what they were assuming, and acted. Not one of those conversations began with “let us consult the enterprise risk management framework.” The conversations began with “what are we trying to protect, and what do we need to do now?” That sequence is the Universal Decision-Making Method in compressed form. The ERM framework was irrelevant to it.

No credible evidence demonstrates that ERM improves organisational performance. When ERM adoption correlates with success, it is because already-successful companies can afford such systems, or because regulators required them. The framework did not create the success. The entire apparatus is a millstone around the Decider’s neck.

Why “risk appetite” collapsed on contact

One of ERM’s central constructs is “risk appetite,” the notion that an organisation can specify in advance how much uncertainty it is willing to accept. The concept has always been problematic. In practice, risk appetite statements are drafted by consultants, approved by boards who do not use them, and filed alongside the register. They are abstract declarations disconnected from specific decisions.

COVID-19 exposed the absurdity. No risk appetite statement prepared by any organisation in 2019 contemplated a global shutdown of commerce. When the pandemic arrived, every prior calibration of acceptable uncertainty became meaningless overnight. Organisations did not recalibrate their risk appetite. They abandoned the concept entirely and did what they should have been doing all along: they assessed the assumptions underlying their most consequential decisions and acted on what they found.

The lesson is not that risk appetite fails only during black swan events. It fails during ordinary decisions too, because it attempts to quantify something that can only be judged in context. How much uncertainty a Decider should accept depends on what is at stake, what assumptions the decision rests on, and what the Decider’s confidence is in each one. That judgement is situational. It cannot be pre-set on a corporate dashboard and applied uniformly.

The compliance trap

ERM persists not because it works but because it is required. Regulators in banking, insurance, energy, and public administration mandate some form of enterprise risk management. Stock exchanges include it as a listing condition. The requirement creates a market. Consultants build practices around it. Auditors check for it. Academics publish about it. Each group has a legitimate interest in studying uncertainty. Not one of those groups exists to help someone facing a real decision work through it and act.

The compliance obligation produces a circular effect. Organisations adopt ERM to satisfy regulators. Regulators point to adoption rates as evidence the framework works. Neither party examines whether the decisions improved. Enron had Arthur Andersen publicly praising its enterprise risk management. Both collapsed. The Australian banks passed regulatory reviews for years while engaging in systematic misconduct. The apparatus was fully assembled. The decisions were terrible. No one connected the two observations, because the framework was never designed to be connected to specific decisions.

This is why decision-making under uncertainty cannot be improved by adding more apparatus. The apparatus is the problem. It creates the illusion that due diligence has been done, which is worse than having no apparatus at all, because at least then the Decider would know they still needed to decide.

The alternative

The alternative is to help people make better decisions directly. State the purpose. Name the assumptions. Classify their significance. Decide what to monitor. That is what the Universal Decision-Making Method does. Roger Estall and I developed the method to replace this failed orthodoxy with something that actually enters the room where decisions happen. It does not require a framework, a committee, or an acronym. I discuss this trajectory at length in my conversations with Mark Siwik on the SandRun Risk blog.

When COVID-19 arrived, the organisations that responded best were not the ones with the most elaborate ERM structures. They were the ones whose leaders did the thinking. They identified what they were trying to achieve. They named what they were assuming about the situation. They assessed which assumptions were Critical and which were Limited. They acted, and they built monitoring into their decisions so they could adapt as conditions changed. That is not ERM. That is deciding well. The two have never been the same thing.

You could reopen the ERM binder while the next shock ignores every category.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.