The COSO guide "From Guidance to Action: Exploring Practical Enterprise Risk Management" hits on a critical issue in enterprise risk management: Many systems are visibly active but have little impact on the management of a company. They produce risk registers, qualitative heat maps, control inventories, and extensive reporting packages (sometimes in language that no one understands) without altering strategic alternatives, reprioritizing investments, or triggering escalations in a timely manner. In response, COSO sets forth a clear and compelling test: Risk management only delivers value when it improves a decision, accelerates implementation, or clarifies what needs to change in the face of shifting conditions. This decision-oriented approach is the strongest contribution of the new COSO guide.
Equally compelling is the consistent linking of strategy and risk. Strategic decisions are always decisions made under uncertainty. Anyone who formulates a strategy simultaneously defines—whether explicitly or implicitly—a risk position. COSO therefore calls for risks not to be treated retrospectively as a control and reporting issue, but rather for assumptions, ranges, trade-offs, triggers, and potential course corrections to be incorporated into the strategic decision-making process from the outset.
My criticism of the guide begins where it shifts from setting the right objectives to methodological implementation. It recommends scenarios, ranges, thresholds, triggers, and a portfolio perspective, but remains vague on the question of how these elements can be developed in a quantitatively robust manner. There is a lack of concrete guidance on modeling frequencies and loss amounts, on mapping dependencies, on stochastic risk aggregation, on sensitivity analysis, on stress and reverse stress tests, and on integrating the aggregated total risk position into earnings, balance sheet, cash flow, and covenant planning. Above all, it remains unclear how risk-bearing capacity and risk coverage potential are to be derived from equity, liquidity reserves, financing flexibility, and minimum requirements.
Corporate distress, liquidity crises, and insolvencies repeatedly reveal a fundamental pattern: risk management systems existed in theory but often played no discernible role in actual corporate management. Risk reports, key performance indicators, stress tests, scenario analyses, and risk-bearing capacity concepts existed on paper, but did not influence strategic decisions, financing, capital allocation, liquidity planning, or the limitation of critical risk positions. In some cases, risks were assessed using methods that sounded methodologically sophisticated, yet the results were not used to derive timely measures, limits, or escalations. In other cases, the analyses were based on unreliable data, unrealistic assumptions, or a governance structure that did not allow for critical counterarguments. Even compliance with formal capital, liquidity, or control requirements does not prevent a crisis if concentration risks, interdependencies, loss of trust, and cumulative pressures are not considered in terms of their interactions. The central problem therefore often lies not in a complete lack of risk management, but in its lack of relevance to decision-making and effectiveness: risks were documented, classified, and reported without this leading to changes in decisions, priorities, or resource allocations (I have referred to this for many decades as "risk accounting").
This calls for a two-fold expansion of the COSO approach. First, effective enterprise risk management requires a minimum quantitative framework for all material risks and those that could potentially threaten the company's continued existence. This includes transparent scenario ranges for a rigorous description of potential risks, stress scenarios, sensitivity analyses, consideration of interdependencies, and an aggregation of risks along with their impacts on earnings, equity, and liquidity. Second, it requires a governance framework that does not merely verify whether models, reports, and committees exist, but whether the insights actually lead to consequences for decisions, capital allocation, liquidity reserves, limits, actions, and escalations. A risk model is not an end in itself and cannot compensate for poor data or weak leadership. Without a robust quantitative foundation, however, the assertion that a risk portfolio is sustainable often remains an unsubstantiated claim.
Purpose and Nature of the COSO Guidance
"From Guidance to Action: Exploring Practical Enterprise Risk Management" is neither a new technical standard nor a methodological handbook. Published in 2026, the guidance is intended as a practical translation of the COSO-ERM framework into leadership and decision-making behavior. It is addressed to chief risk officers, risk teams, executive boards, senior management, supervisory and audit committees, and internal audit. Its underlying principle is this: A framework describes what good risk management is intended to achieve; an effective operating system determines how it actually functions within the organization.
The guide deliberately uses short practical vignettes, role models, and ten "Operating Disciplines." These include linking strategy and risk, considering value creation, a usable risk appetite, the portfolio perspective, prioritizing decisions over documentation, measuring impact rather than activity, governance as a behavioral system, integration into operational rhythms, a lived risk culture and openness, as well as continuous learning. This structure is easy to understand and particularly appealing to organizations whose risk management has, over the years, become an isolated "silo system" consisting of workshops, questionnaires, and reports.
Its principle-based approach is both a strength and a limitation. It allows for application across a wide range of industries and maturity levels. However, it also leaves companies with the difficult task of translating these principles into practice. It is precisely at this point that it is determined whether a concise management concept will become a robust control system—or merely a new vocabulary for a system that remains weak.
Methodological Gap: The guide should not be criticized for not being a comprehensive textbook on quantitative risk analysis. Rather, it is open to criticism for not highlighting key methodological gaps clearly enough and for failing to specify minimum requirements regarding when qualitative ranges and triggers must be supplemented by quantitative aggregation, risk-bearing capacity calculations, and stress analysis.
The Major Strength: Decision-Orientation Rather Than Artifact Production
The guide's most important contribution lies in its uncompromising focus on decision-making. Many risk management systems confuse process evidence with effectiveness. A well-populated risk register proves that risks have been identified. A heat map proves that they have been classified in some way—albeit not on a methodologically sound basis. An RCSA proves that risks and controls were assessed. A control inventory proves that controls are documented. However, none of these documents proves that a strategic or operational decision has improved.
COSO therefore shifts the yardstick for evaluation: It is not the quantity of deliverables that counts, but their impact on decisions. This is a question of the effectiveness of risk management. A risk report can be technically accurate, formally complete, and visually professional—and yet fail to alter a single decision option. Conversely, a one-page decision memo with two scenarios, three critical assumptions, and two clear termination criteria can be far more valuable to leadership than a hundred-page risk manual.
There is a particularly strong call to answer three questions with every risk update: What has changed? Which decision is affected by this? What trigger would necessitate a different plan? This shifts risk management from a retrospective description to prospective steering. Risks are not merely "acknowledged", but linked to a decision point, a responsible party, and a course of action.
This perspective also corrects a common misinterpretation of governance. Committees, guidelines, and meeting cycles do not in themselves constitute governance. Governance only emerges when (even) unpleasant information becomes visible in a timely manner, decision-making authority is clarified, escalations are reliably triggered, and actions are tracked. The guide thus formulates a practical concept of effectiveness that is lacking in many established maturity models.
Practical Effectiveness Test: For every recurring ERM deliverable, the responsible function should be able to specify: What specific decision is being prepared as a result? Which option could change? Which resource, deadline, limit, or measure is affected? If there is no reliable answer to these questions, the deliverable must either be revised, replaced, or eliminated.
Strategy and Risk: An Indispensable Unity
The second major strength of the guide is its consistent integration of strategy and risk. Strategy not only describes goals and opportunities but also defines resource allocations, dependencies, assumptions, and thus a specific risk-return profile. Internationalization, for example, increases market potential and diversification but can simultaneously exacerbate political, regulatory, currency, supply chain, and integration risks. An acquisition can accelerate growth but also increase debt, reliance on refinancing, and integration risk. An ambitious digital strategy can boost productivity while simultaneously generating new cyber, data protection, model, and third-party risks.
If risk is not considered until after the strategic decision has been made—in a separate workshop—the scope for maneuver is often already lost. The purchase price, financing, timeline, contract structure, and public commitments have already been set. Risk management can then document, issue warnings, or propose controls, but it can hardly influence the fundamental decision anymore. COSO therefore rightly calls for incorporating risk preventively, as long as options remain open and course corrections are still relatively inexpensive.
Methodologically, this requires making strategic assumptions explicit. What market prices, interest rates, sales volumes, approvals, personnel availability, or levels of technological maturity must materialize? What range is plausible? What combination of deviations would tip the balance of benefit? What outcomes would no longer be acceptable? And what signal would trigger a pause, renegotiation, additional financing, or termination?
However, the link between strategy and risk must not stop at moderated questions. As soon as a decision has significant impacts on earnings, the balance sheet, or liquidity, the strategic planning itself must be risk-adjusted. This means that planned figures are not only assigned optimistic, realistic, and pessimistic scenarios, but the key uncertainties are modeled as drivers and integrated into corporate planning. Only then can one assess the probability that earnings targets, covenants, minimum liquidity requirements, or rating requirements will be breached.
From Decision Usefulness to Management Relevance
The concept of "decision usefulness" is compelling, but it is not yet sufficient for effective risk management. Information can enhance a discussion without having a binding impact on management. Risk information is only relevant for management control if it has an observable consequence for direction, resource allocation, risk-bearing capacity, risk exposure, or escalation.
Risk information is particularly relevant to management when a risk analysis changes at least one of the following factors:
- the choice between strategic options or the design of an option;
- the amount and timing of an investment;
- financing, liquidity reserves, or hedging strategy;
- a limit, risk appetite, tolerance threshold, or covenant buffer;
- an operational measure, a responsible party, or an implementation date;
- the sequence of projects or the allocation of scarce management, IT, and financing resources;
- escalation to the Executive Board, Supervisory Board, lenders, or other stakeholders;
- the updating of earnings, balance sheet, and cash flow forecasts.
This definition tightens the COSO test. It is not enough for a report to be "helpful." It must show which course of action is influenced by which uncertainty, how significant the impact might be, and at what point a response is required. This also serves as the bridge to quantification: Without an order of magnitude, probability distribution, temporal impact, and dependencies, it is often impossible to determine whether a measure is economically viable, what risk reduction it generates, or whether the remaining risk remains acceptable.
Management relevance is therefore not the opposite of decision-orientation, but rather its operationalization. The decision question determines which analysis is necessary. The quantitative analysis determines whether the decision is compatible with risk coverage potential, liquidity, covenants, and strategic limits. Governance ensures that action follows from the result.
Heat Maps: Justified Criticism, Insufficient Consistency
The guide's criticism of heat maps is justified. COSO explicitly states that ERM useful for decision-making does not consist of periodically updating (qualitative or semi-quantitative) heat maps. Elsewhere, it essentially states: Heat maps add color, but not necessarily insight. This criticism strikes at the heart of widespread risk management practices.
Traditional risk matrices combine ordinally ranked probabilities of occurrence and impacts. This results in colored fields that suggest a ranking and comparability. Methodologically, this approach presents several problems:
- Ordinal scales do not allow for reliable multiplication or other mathematical operations. The distance between "low" and "medium" is not necessarily equal to the distance between "medium" and "high."
- Broad classes compress very different risks into the same cell. A loss of 5 million EUR and a loss of 49 million EUR can be represented identically, even though their impact on risk management is completely different.
- Multiplying a probability value by a loss value focuses attention on the expected value. However, business viability and capital requirements are often determined by rare, high losses, volatility, and combination effects.
- Risk matrices largely obscure interdependencies. Several "yellow" individual risks can collectively create a "red" overall risk position.
- The time horizon and risk velocity remain unclear. A scenario with slow-acting consequences and a liquidity outflow that escalates within days can be assigned the same color.
- The choice of class boundaries and colors is often subjective. As a result, risks can be visually downgraded through assessment negotiations without changing their economic exposure.
- An optimal decision on risk mitigation measures cannot be derived from a single color. The costs and effects of risk mitigation measures, residual uncertainty, and alternative uses of capital remain invisible.
The scientific criticism has long been known [see Gleißner / Romeike 2009]. Risk matrices have low resolution, can reverse quantitative rankings, and do not provide a robust basis for allocating risk management budgets. The color thus often creates a false sense of precision: it reduces complexity without providing the information necessary for a decision.
COSO outlines better principles—but no sufficient alternative
Instead of a single score, the guide recommends ranges, scenarios, explicit assumptions, triggers, and trends. This represents significant progress. A baseline scenario and a disruption scenario force us to discuss real differences in outcomes. Triggers turn an observation into a decision point. Time series and leading indicators are more meaningful than a static color.
Nevertheless, the alternative remains methodologically thin. The guide does not explain how scenarios are derived consistently, how probabilities or ranges are estimated, how common drivers are taken into account, or how multiple risks are linked to an overall distribution of results and liquidity. Sensitivity analyses are also not developed as a systematic tool, even though they are precisely what can reveal which assumptions and risk drivers actually dominate the decision.
Added to this is a contradiction: The guide criticizes heat maps but uses a simple traffic-light model as a positive example for risk appetite. A traffic-light model can be useful for communication if the underlying thresholds are quantitatively sound, measurable in real time, and linked to a pre-agreed course of action. Without this foundation, however, the traffic-light model merely replicates the weaknesses of the heat map in a more compact form.
Better visualization is no substitute for better analysis: Dynamic dashboards, trend arrows, and traffic lights can support decision-making. However, they are merely presentation tools. The methodological substance lies in the underlying methods, drivers, stochastic distributions, dependencies, thresholds, and rules of action. A dashboard is not a risk model.
The Quantitative Blind Spot
The central weakness of the guide is the lack of a concrete minimum quantitative framework. While COSO does refer to "unexpected loss," volatility, tail scenarios, concentration, and interactions, in practice the guide is limited to a few scenarios, ranges, and triggers. This may suffice for decisions of minor importance. For capital-intensive, highly leveraged, regulated, or highly interconnected companies, however, it is insufficient.
A valid concern is that quantitative models could create a false sense of accuracy. This is fundamentally correct. Poor data, unrealistic distribution assumptions, and overly complex models can create more confidence than is objectively justified. Models can also be manipulated to deliver a desired result. However, this does not mean that quantification should be abandoned. Rather, it is essential to model uncertainty transparently, use ranges, disclose assumptions, and validate results through sensitivity and stress tests.
This is often not understood in practice. Thus, the most recent financial and banking crisis did not provide an argument against risk models, but rather an argument for their further development—many weaknesses of the models commonly used in practice have long been known. Overall, the focus must be on devoting more time and resources to genuinely serious reflection on the essential critical future scenarios and risks—and less on modeling the "details" of risk models. This requires a broad understanding, interdisciplinary collaboration, and new mathematical methods—at least new in their application to this segment. Risk management must focus on what can truly lead to crises for the company. And when developing risk models, it is essential to avoid defining away the largest portion of the risk—namely, the possibility of model errors and data uncertainties—a priori [see Gleißner / Romeike 2010, pp. 59–88].
Not every risk needs to be modeled in euros with a detailed probability distribution. However, material risks that could affect earnings, liquidity, equity, covenants, credit ratings, or the company's continued existence do require quantitative quantification. Otherwise, it remains unclear whether the risk is merely inconvenient, strategically significant, or a threat to the company's continued existence.
COSO rightly calls for managing risks as a portfolio and making interactions visible. The proposed "Quick Start" solution—identifying three known interactions, designating a coordinating manager, and defining common triggers—is helpful from an organizational perspective. However, it is no substitute for aggregation using stochastic methods.
An overall risk position does not arise from adding expected values, nor from counting red or yellow dots in a risk matrix or heat map. Risks interact through common drivers, correlations, and cascades. A rise in interest rates can simultaneously increase financing costs, reduce the value of real estate and equity investments, slow customer investments, and shrink covenant buffers. A cyberattack can simultaneously affect revenue, business interruption, recovery costs, contractual penalties, and reputation. A supply chain disruption can impact multiple business units and draw on the same liquidity buffer.
A stochastic simulation allows such combinations to be factored into integrated corporate planning. The result is not a single "risk figure," but rather a distribution of possible trajectories for earnings, cash flow, equity, and liquidity. From this, quantiles, expected shortfall, probabilities of covenant breaches and minimum liquidity requirements, as well as the probability of a development that threatens the company's continued existence, can be derived.
Sensitivity Analysis as the Missing Link
Sensitivity analyses would be an obvious, pragmatic addition to the COSO framework. They answer a simple question for decision-makers and senior management: Which assumptions have the greatest impact on the outcome or the desirability of a decision? Where should I invest my scarce resources to end up with an optimal risk portfolio?
A tornado analysis, for example, can transparently and clearly show whether the enterprise value of an investment depends more heavily on sales volume, price, raw material costs, exchange rates, cost overruns, or delays. A threshold analysis shows the interest rate, decline in sales, or selling price at which a covenant is breached or the net present value becomes negative. In more complex models, global sensitivity analysis can determine which uncertainties account for the largest share of earnings variance.
The benefit is directly relevant to management: management's attention can be focused on the key drivers, and more informed decisions, hedging, and action budgets can be concentrated on the dominant drivers. A sensitivity analysis is thus a methodologically sound decision-making tool that aligns precisely with the strategic COSO framework.
Risk-bearing capacity and risk coverage potential
The guide makes risk appetite actionable through thresholds, triggers, and actions. What is missing is the economic derivation of these limits. Risk appetite without risk-bearing capacity can remain arbitrary. An organization can only determine how much risk it is willing to take (risk appetite) if it knows how much risk it can bear (risk-bearing capacity)—and what buffers must be maintained for strategy, credit rating, financing, and crisis response.
Risk-bearing capacity refers to a company's ability to absorb losses and negative deviations without jeopardizing defined minimum targets or its continued existence. Risk coverage potential comprises the actually available coverage resources. Depending on the management perspective, these may include economic equity, retained earnings, free liquidity, undrawn and available credit lines, hidden reserves, marketable assets, or other loss-absorption and financing potentials.
These figures must not be added together indiscriminately. Accounting equity is not automatically liquid. A credit line constitutes coverage potential only if it remains available under stress conditions and covenants have not already been breached. An asset is relevant only to the extent that it can be sold in a timely manner, in a legally secure way, and at a realistic discount. Risk coverage potential is therefore dependent on time, stress, and liquidity.
A robust viability analysis should combine at least three perspectives:
- Income and equity perspective: What aggregate losses can be absorbed before falling below minimum capital, balance-sheet equity, or strategically required buffers?
- Liquidity perspective: What cumulative cash outflows can be covered over different time horizons if refinancing is restricted, collateral requirements are increased, or receivables are paid later?
- Financing and covenant perspective: What is the probability that debt, interest coverage, minimum liquidity, or rating thresholds will be breached, and what are the resulting consequences?
A company may be formally solvent yet still face a liquidity crisis due to accelerated deposit withdrawals, supplier cuts, margin calls, counterparty limits, or a loss of customer confidence.
Risk appetite should not be formulated as an isolated statement, but rather as a hierarchical system of limits. The starting point consists of non-negotiable limits—such as minimum liquidity, solvency, legal requirements, and business continuity. These are followed by strategic buffers, such as a target rating or a minimum investment grade. Only the remaining portion can be deployed as consciously utilized risk capacity for growth, innovation, or acquisitions.
This gives a trigger economic significance. An interest coverage ratio approaching a covenant threshold is not merely "yellow." It indicates how much loss absorption or financing leeway remains, what combination of additional risks is still tolerable, and what measures will be required and when. Without this connection, a traffic-light system may attract attention but cannot provide robust risk management.
Specific Additions for a COSO Practical Guide 2.0
This guide should not be replaced by a comprehensive mathematical or statistical compendium. A supplementary quantitative annex describing minimum requirements and scalable procedures would be useful. The following additions would significantly strengthen the "From Guidance to Action" approach:
- Define decision classes: Distinguish between simple operational decisions, significant investments, strategic transformations, and decisions that could potentially threaten the company's continued existence. Specify minimum analyses for each class.
- Specify quantitative thresholds: Risks must be quantified in integrated planning if they have a material impact on earnings, cash flow, equity, liquidity, or covenants.
- Specify scenario quality: Include guidelines for driver selection, consistency, ranges, probabilities, time horizon, and documentation of assumptions.
- Make sensitivity analysis mandatory: Identify the dominant uncertainties and tipping points for every major strategic decision.
- Describe aggregation in a scalable manner: Offer a tiered model ranging from simple common stress drivers to stochastic simulation (Monte Carlo simulation) with dependencies.
- Operationalize risk-bearing capacity: Explain the equity, liquidity, and covenant perspectives, as well as haircuts and the temporal availability of coverage potential.
- Account for tail risks and expected shortfall: Require not only expected values and standard quantiles, but also extreme combinations, expected shortfall, and reverse stress tests.
- Address model risk and data integrity: Treat independent validation, a register of assumptions, data sources, backtesting, and manipulation risks as governance issues.
- Quantify the impact of measures: Compare costs, risk reduction, residual exposure, and effects on financial viability before and after implementing measures.
- Add a capacity section to the board report: In addition to "What has changed?", provide a concise overview of the overall risk position, coverage potential, probability of breaching limits, and key sensitivities.
- Link triggers to decision-making authority: Each trigger requires a data source, frequency, responsible party, decision-making body, response time, and a pre-agreed action.
- Refine impact measurement: It is not only the decisions influenced that matter, but also documenting how capital allocation, liquidity, risk costs, probability of loss, or strategic options have changed.
Conclusion: A Necessary Cultural Shift
"From Guidance to Action" is an important and long-overdue alternative to a risk management approach that measures its maturity by the number of registers, heat maps, RCSAs, guidelines, and report pages. The guide poses the right leadership question: What has risk management changed in a specific investment decision, a strategic course correction, an escalation, or a result? This decision-oriented approach deserves unreserved support.
Equally valid is the link between strategy and risk. Strategy without risk analysis is planning with hidden assumptions. Risk management without strategy is a collection of threats without a prioritization framework. Only by considering them together do trade-offs, opportunities, limitations, and courses of action become visible.
However, the guide falls short of its own aspirations when it largely limits methodological implementation to ranges, two scenarios, triggers, and a qualitative view of the portfolio. Precisely where risks can affect the company's continued existence, financing, or key strategic goals, individual risks must be quantified, dependencies aggregated, and the resulting overall risk position compared with robust risk coverage measures. Sensitivity analyses, stochastic simulations, stress tests, and reverse stress tests are not merely academic add-ons. When used correctly, they are tools for decision-making and corporate management.
The decisive criterion for ERM is therefore not "qualitative or quantitative," but rather "relevant to management or inconsequential." An effective system integrates strategic issues, quantitative analysis, and governance. It reveals the uncertainty shaping the decision, the potential magnitude of the overall impact, whether the organization can withstand it, and what happens when a threshold is reached. Only then does "guidance" truly become "action."
Bibliography and further reading:
- COSO (2026): From Guidance to Action: Exploring Practical Enterprise Risk Management, Committee of Sponsoring Organizations of the Treadway Commission, 2026 [Authors: Luttenton, Ryan C./Samp, Stefany/Stone, Alexa], Download www.coso.org/new-erm-guidance
- COSO (2017): Enterprise Risk Management – Integrating with Strategy and Performance. Committee of Sponsoring Organizations of the Treadway Commission, 2017.
- Gleißner, Werner / Romeike, Frank (2010): Risikoblindheit und Methodikschwächen im Risikomanagement [Risk Blindness and Methodological Weaknesses in Risk Management], in: Romeike, Frank (ed.): The Banking Crisis – Causes and Consequences in Risk Management, Bank Verlag, Cologne 2010, pp. 59–88.
- Gleißner, Werner / Romeike, Frank (2011): Die größte anzunehmende Dummheit im Risikomanagement - Berechnung der Summe von Schadenserwartungswerten als Maß für den Gesamtrisikoumfang [The Greatest Assumed Stupidity in Risk Management—Calculating the Sum of Expected Loss Values as a Measure of Total Risk Exposure], in: Risk, Compliance & Audit (RC&A), 01/2011, pp. 21–26.
- Gleißner, Werner / Romeike, Frank (2020): Entscheidungsorientiertes Risikomanagement nach DIIR RS Nr. 2 [Decision-Oriented Risk Management According to DIIR RS No. 2], in: Der Aufsichtsrat, Issue 04/2020, pp. 55–57.
- Romeike, Frank (2025): Risiken seriöse und fundiert bewerten – Einführung in die spannende Welt der Stochastik (nicht nur für Juristen) [Assessing Risks Seriously and Soundly—An Introduction to the Exciting World of Stochastics (Not Just for Lawyers)], in: ZInsO (Zeitschrift für das gesamte Insolvenz- und Sanierungsrecht) [Journal of Insolvency and Restructuring Law], Vol. 28, No. 44/2025, Oct. 30, 2025, pp. 2263–2284.




