The COSO ERM Framework: What Every CHRO Must Own in Enterprise Risk

A. What is it?

CHROs: If you’re not in the ERM conversation, you’re the risk.

Your board discusses credit risk, cyber risk, and market risk quarterly. People risk — the thing most likely to blow up your P&L — rarely makes the agenda. That silence is expensive.

B. The Expensive Problem

Across Africa’s fastest-growing companies, people risk is now the least governed risk category on the balance sheet. A single unresolved harassment case, a payroll compliance gap, or an unmanaged succession vacancy can trigger regulatory exposure, reputational damage, and multi-million-naira litigation.

Globally, companies with weak internal controls lose an estimated 5% of annual revenue to fraud and governance failures — and HR-related control gaps (ghost workers, unauthorized payroll changes, undocumented terminations) sit at the center of many of those losses.

For a company scaling from 100 to 500 employees, that’s not a rounding error. That’s EBITDA. Regulators, auditors, and investors increasingly expect people risk to be governed with the same rigor as financial risk — and most CHROs have no seat at that table.

C. Why The Old Way Fails

Three mistakes keep HR out of the boardroom.

First, CHROs report engagement scores and turnover percentages — vanity metrics that say nothing about exposure or control failure.

Second, HR risk lives in disconnected spreadsheets: one for compliance, one for grievances, one for background checks. No single owner, no audit trail.

Third, most HR functions have never mapped their processes against a recognized enterprise risk framework — so when auditors or board risk committees ask “how do you control this?”, there’s no structured answer. That gap is what erodes CHRO credibility at the top table.

D. The Framework: COSO ERM for HR

COSO ERM is the global standard, boards and auditors already use. It has five components. Here’s how to own each one as CHRO.

Step 1: Governance & Culture — Own the Tone
Define who is accountable for people risk at board level. Build an HR risk charter: what gets escalated, to whom, and how fast. Culture isn’t a soft metric here — it’s your first control.

Step 2: Strategy & Objective-Setting — Link Risk to the Business Plan
Map every strategic priority (expansion, restructuring, M&A) to its people risk exposure: leadership pipeline gaps, attrition risk in critical roles, compliance exposure in new markets. If your workforce plan doesn’t reference risk appetite, it’s incomplete.

Step 3: Performance — Build the HR Risk Register
Identify and rate your top 10-15 HR risks: payroll integrity, statutory compliance (Pension, NHF, PAYE, NSITF), background verification, disciplinary due process, data privacy, succession gaps. Score each by likelihood and impact. This register becomes your audit evidence.

Step 4: Review & Revision — Test Your Controls Quarterly
Don’t wait for an external audit to discover a gap. Run internal control checks quarterly: sample employee files, verify statutory remittances, test exit-process compliance. Treat this like a financial controls review, not an HR admin task.

Step 5: Information, Communication & Reporting — Report Risk, Not Just Metrics
Replace the engagement-score slide with a People Risk Dashboard: control status, open exposures, remediation timelines. This is the artifact that earns you a permanent seat in the ERM conversation.

E. What Good Looks Like

A fintech scaling to 300 staff in Lagos built its HR function around a live risk register before its Series B raise. When investor due diligence hit, every statutory, disciplinary, and payroll control had an owner, an evidence trail, and a review date. The round closed on schedule — with no people-risk red flags. That’s what board-grade HR governance buys you.

F. The Executive Takeaway

People risk is enterprise risk. Boards, regulators, and investors already treat it that way — the only question is whether your HR function is structured to prove control, or just to report morale.

To help you build this, we developed the CHRO’s HR Risk & Control Matrix, aligned to COSO ERM. It’s the same tool we use with our clients to prepare for board risk reviews and investor due diligence.

Comment TOOL and I’ll send it to you.

Leave Comment

Your email address will not be published. Required fields are marked *

Call Us