Skip to main content
Category: Corporate Governance

Governance and Culture Component

Also known as: Governance and Culture, Governance & Culture Component, COSO ERM Governance and Culture
Simply put

Governance and Culture is one of the components of the COSO Enterprise Risk Management (ERM) framework. Governance refers to the structures and oversight, such as board involvement, that set the organization's tone and reinforce the importance of managing risk, while culture reflects the shared attitudes and behaviors that shape how people approach risk in their daily work. Together, this component establishes the foundation that influences how the rest of an organization's risk management is carried out.

Formal definition

Within the COSO ERM framework, Governance and Culture is a foundational component addressing how an organization's governance arrangements and cultural attributes shape its approach to enterprise risk management. Governance typically encompasses board risk oversight, the establishment of operating structures, and the setting of organizational tone, while culture concerns the ethical values, desired behaviors, and shared understanding of risk that influence decision-making. In some articulations of COSO's work, culture is framed as a measurable and manageable governance function rather than an intangible attribute. This component provides the context within which the remaining ERM components operate; it should not be conflated with the specific risk assessment or control activities it supports, and its precise sub-principles and application vary by organization and by the framework version referenced.

Why it matters

Governance and Culture sits at the foundation of the COSO ERM framework because it establishes the context within which all other risk management activities operate. Governance arrangements, such as board risk oversight and the establishment of operating structures, set the organizational tone that reinforces the importance of managing risk, while culture reflects the shared attitudes and behaviors that shape how people approach risk in their daily work. Without a sound foundation in this component, the remaining ERM components may be applied inconsistently or lack the organizational commitment needed to function as intended.

A distinctive feature of COSO's articulation is that culture can be framed as a measurable, manageable, and mission-critical governance function rather than an intangible attribute. This reframing matters because it moves culture from something organizations aspire to describe qualitatively toward something they can attempt to observe, assess, and influence through governance mechanisms. Good governance provides the structures for identifying, assessing, and managing risks, while a strong culture supports responsible decision-making across an organization.

Because this component provides the context for the rest of ERM rather than performing risk assessment or control activities itself, it should not be conflated with those downstream activities. Its practical value lies in shaping the environment in which risk decisions are made. Note that the precise sub-principles and their application vary by organization and by the version of the framework referenced.

Who it's relevant to

Board members and directors
Boards commonly hold responsibility for risk oversight and for setting the organizational tone that reinforces the importance of managing risk. This component speaks directly to how governance structures and board involvement establish the foundation for enterprise risk management.
Risk managers and ERM practitioners
Those responsible for implementing the COSO ERM framework rely on Governance and Culture as the foundational context within which the other ERM components operate. Understanding this component helps practitioners distinguish it from the risk assessment and control activities it supports rather than performs.
Compliance officers
Because governance and culture influence how compliance risk is managed, through board oversight and shared attitudes toward risk, compliance professionals may find this component relevant to fostering an environment that supports adherence to laws, regulations, and internal policies. Its application to compliance risk management varies by organization.
Internal auditors and assurance functions
Assurance providers may evaluate whether an organization's governance arrangements and cultural attributes are established and operating as intended, while maintaining independence from the governance and management activities they assess. This component offers a reference point for such evaluations without prescribing specific audit procedures.

Inside Governance and Culture Component

Board Risk Oversight
The governing body's responsibility to oversee the strategy and to exercise oversight of the risk management processes established by management. This concerns the direction and challenge role of the board rather than the day-to-day execution of risk activities.
Operating Structures
The establishment of operating structures, including reporting lines, decision rights, and authorities, through which the organization pursues its strategy and objectives. This element ties governance decision rights to how risk responsibilities are allocated across the organization.
Desired Culture
The definition of the behaviors and attitudes that characterize how the organization approaches risk. Culture in this context reflects the collective values that influence risk-related decisions, and it may vary across parts of an organization.
Commitment to Core Values
The demonstration of a commitment to integrity and ethical values, typically communicated through codes of conduct and reinforced through leadership behavior. This element connects governance tone-setting to compliance expectations around ethical conduct.
Attracting, Developing, and Retaining Capable Individuals
The organization's commitment to building the human capital needed to execute its strategy and objectives, including competence relevant to risk management responsibilities. This addresses the people dimension of governance rather than specific staffing tools or methods.

Common questions

Answers to the questions practitioners most commonly ask about Governance and Culture Component.

Is the governance and culture component just about having a code of conduct in place?
No. A code of conduct is one artifact that can express desired behaviors, but the governance and culture component is broader. It typically encompasses the board's risk oversight role, the operating structures and reporting lines that assign decision rights, the definition of desired behaviors and ethical values, and the practices that attract, develop, and retain capable people. Treating it as a single document understates its scope, which spans how an organization is directed and the behavioral environment in which risk decisions are made.
Does this component mean the board is responsible for managing risk day to day?
No. In many frameworks the board exercises risk oversight, which is an accountability and challenge function, while management is responsible for the day-to-day identification, assessment, and treatment of risk. Conflating oversight with hands-on management blurs an important distinction. The governance and culture component addresses how these responsibilities are structured and separated, not a transfer of operational risk management to the board itself. Specific allocations of responsibility may vary by jurisdiction, sector, and organization size.
How can an organization begin to embed desired behaviors and values consistently across its operations?
Common approaches include articulating the desired behaviors and ethical values explicitly, aligning them with the organization's strategy and objectives, and reinforcing them through leadership example, communication, and human resource practices such as hiring, development, and reward structures. The effectiveness of these practices can vary, and this entry does not prescribe specific implementation methods or tooling. Organizations typically tailor the approach to their context rather than applying a single template.
What structures might an organization establish to support this component?
Organizations commonly define operating structures and reporting lines that clarify decision rights, authority, and accountability, and may establish committees or roles at board and management levels to oversee risk. In many organizations these structures are described alongside a lines-of-responsibility model, such as the three lines model associated with the IIA, which distinguishes operational management, risk and compliance functions, and independent internal audit. The precise structures adopted depend on the organization's size, complexity, and regulatory environment.
How might an organization assess whether its culture supports its risk management objectives?
Assessment approaches may include reviewing behavioral indicators, results of employee surveys, patterns in reported concerns or whistleblowing channels, and how decisions are made under pressure relative to stated values. Culture is difficult to measure directly, so such indicators are typically interpreted qualitatively and in combination rather than as definitive metrics. This entry does not cover specific assessment tools, and any evaluation should be adapted to the organization's context.
How does this component relate to the other components of the framework?
Governance and culture is often described as a foundational component that influences how the other components operate, because the tone set by the board and management and the behaviors it encourages affect strategy setting, performance, review, and information and communication activities. It is generally treated as interdependent with the other components rather than as a standalone stage. How the components are grouped and labeled may differ across frameworks.

Common misconceptions

The Governance and Culture component is primarily a compliance matter concerned with adherence to codes of conduct.
While a commitment to ethical values and codes of conduct is one element, this component sits within an enterprise risk management framing and concerns governance structures, decision rights, and risk-related behaviors. Governance, risk management, and compliance are distinct pillars, and treating this component as purely a compliance exercise understates its role in setting direction and risk oversight.
Board risk oversight means the board manages the organization's risks.
Oversight is an assurance and direction-setting role that is distinct from management's responsibility to design and operate risk management processes. The governing body typically challenges, oversees, and holds management accountable rather than executing risk activities itself; conflating the two blurs the independence of oversight from operational management.
A single desired culture can be defined and applied uniformly across an entire organization.
Culture reflects behaviors and attitudes that may differ across business units, geographies, and functions. Defining a desired culture is intended to guide risk-related behavior, but practitioners commonly find that culture varies in practice and requires ongoing attention rather than a one-time uniform declaration.

Best practices

Distinguish the board's oversight responsibilities from management's execution responsibilities in writing, so that decision rights and accountability for risk are clearly allocated.
Define operating structures with explicit reporting lines and authorities that connect governance decision rights to who is responsible for identifying, assessing, and treating risk.
Articulate the desired risk-related behaviors and attitudes, and assess where actual culture varies across parts of the organization rather than assuming uniformity.
Reinforce the commitment to integrity and ethical values through leadership behavior and communication, recognizing that tone at the top influences risk decisions.
Align human capital practices with the competencies needed to carry out risk management responsibilities across relevant roles.
Review governance and culture elements periodically, treating culture as an ongoing area of attention rather than a fixed, one-time definition.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps