{"id":9277,"date":"2017-09-07T16:40:00","date_gmt":"2017-09-07T15:40:00","guid":{"rendered":"https:\/\/naris-prod.azurewebsites.net\/nooit-meer-strategiepijn-copy\/"},"modified":"2025-08-08T13:45:52","modified_gmt":"2025-08-08T11:45:52","slug":"nieuwe-coso-2017-koppelt-risicomanagement-aan-strategie-en-prestatiemanagement","status":"publish","type":"post","link":"https:\/\/www.naris.com\/nl\/nieuwe-coso-2017-koppelt-risicomanagement-aan-strategie-en-prestatiemanagement\/","title":{"rendered":"COSO ERM 2017: strategie, risicomanagement en prestatiemanagement"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"9277\" class=\"elementor elementor-9277\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-fc636ed elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"fc636ed\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3fa720c\" data-id=\"3fa720c\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9fe565e elementor-widget elementor-widget-text-editor\" data-id=\"9fe565e\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"content-wrapper section-theme-white full-width\"><div class=\"container\"><div class=\"col-sm-12\"><div class=\"vc_column-inner\"><div class=\"wpb_wrapper\"><div class=\"wpb_text_column wpb_content_element \"><div class=\"wpb_wrapper\"><h3>Risicomanagement<\/h3><p>De door COSO nieuw uitgegeven\u00a0standaard Enterprise Risk Management\u00a0&#8211; Integrating with Strategy and Performance \u2013 heeft veel te bieden. De standaard geeft managers, controllers, risicomanagers en internal auditors nieuwe handvatten voor de inrichting van <a href=\"https:\/\/www.naris.com\/nl\/risicomanagement\/\">risicomanagement<\/a>.<\/p><p>En het was nodig! Er is immers veel veranderd in risicomanagementland sinds het oorspronkelijke COSO ERM-kader in 2004 werd ingevoerd. De wereld is sinds die tijd sterk getransformeerd; de technologische vooruitgang bracht geweldige nieuwe kansen maar ook risico\u2019s als cybercriminaliteit met zich mee. Daarnaast nam de informatiesnelheid in razend tempo toe. Ketens van dienstverlening werden complexer, er ontstond versplinterde compliance\u00a0<a href=\"https:\/\/robertthart.risicomanagement.nl\/2013\/12\/03\/kaplan-externe-risicos-big-bangs-en-sluipmoordenaars\/\" target=\"_blank\" rel=\"noopener\">en ga zo maar door<\/a>.<\/p><p>Maar ook kreeg de COSO-kubus zelf kritiek te verduren, want ondanks deze standaard en miljarden aan adviesuren bleken vele risico\u2019s niet zo geweldig gemanaged. Zo schreef powel een artikel \u201crisk management is the management of nothing\u201d Tot slot ontstond er ook concurrentie door andere normen als ISO31000 en ISO9001.<\/p><h3>Koppeling strategie<\/h3><p>Binnen deze kritiek werd de bal nadrukkelijk bij het C-level gelegd. In deze tijd van disruptie dient het C-level namelijk te beseffen dat risico\u2019s de strategie, maar ook de prestaties van organisaties be\u00efnvloeden en dat dit onderwerp serieus genomen moet worden.<\/p><p>Zij zouden moeten erkennen dat het hier om meer gaat dan een checklist of afdeling (die makkelijk zijn te delegeren), maar om een cultuur die aansluit bij de waarde en strategie van de organisaties.<\/p><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-173d8be elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"173d8be\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e42ae93\" data-id=\"e42ae93\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-50fed14 elementor-widget elementor-widget-image\" data-id=\"50fed14\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"768\" height=\"282\" src=\"https:\/\/www.naris.com\/wp-content\/uploads\/2021\/07\/COSO2017-768x282.png\" class=\"attachment-medium_large size-medium_large wp-image-5400\" alt=\"coso-2017\" srcset=\"https:\/\/www.naris.com\/wp-content\/uploads\/2021\/07\/COSO2017-768x282.png 768w, https:\/\/www.naris.com\/wp-content\/uploads\/2021\/07\/COSO2017-300x110.png 300w, https:\/\/www.naris.com\/wp-content\/uploads\/2021\/07\/COSO2017-1024x375.png 1024w, https:\/\/www.naris.com\/wp-content\/uploads\/2021\/07\/COSO2017.png 1462w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-392fdbe elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"392fdbe\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3def3ee\" data-id=\"3def3ee\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-193d063 elementor-widget elementor-widget-text-editor\" data-id=\"193d063\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"content-wrapper section-theme-white full-width\"><div class=\"container\"><div class=\"col-sm-12\"><div class=\"vc_column-inner\"><div class=\"wpb_wrapper\"><div class=\"wpb_text_column wpb_content_element \"><div class=\"wpb_wrapper\"><h3>5 thema\u2019s COSO<\/h3><p>Het nieuwe COSO- raamwerk legt de nadruk op de wisselwerking tussen risico, prestatie, strategie en waarde. Ze is opgebouwd uit vijf onderling verbonden thema\u2019s (uitgewerkt in principes) die essentieel zijn voor modern ERM:<\/p><ul><li>Governance en\u00a0<a href=\"https:\/\/robertthart.risicomanagement.nl\/2015\/12\/18\/dinsdag-09-00-risicoanalyse-aanwezigheid-verplicht\/\" target=\"_blank\" rel=\"noopener\">cultuur<\/a>: heldere taken en verantwoordelijkheden en aandacht voor cultuur, integriteit en risicobewustzijn.<\/li><li>Strategie en doelstelling: risico\u2019s meewegen in de strategische keuzes en het vaststellen van risk appetite. Doelstellingen dienen als basis voor het identificeren, beoordelen en reageren op risico\u2019s.<\/li><li>Prestatiemanagement: Risico\u2019s die invloed kunnen hebben op het behalen van strategie en doelstellingen moeten worden ge\u00efdentificeerd en beoordeeld. Aan risico\u2019s wordt prioriteit gegeven afhankelijk van de ernst in de context van\u00a0<a href=\"https:\/\/robertthart.risicomanagement.nl\/2016\/03\/31\/risicobereidheid-of-risk-appetite\/\" target=\"_blank\" rel=\"noopener\">risicobereidheid<\/a>. De organisatie selecteert dan risicogerechten en neemt een portefeuilleweergave van het risico dat zij heeft aangenomen. De resultaten van dit proces worden gerapporteerd aan belangrijke risicogroepen.<\/li><li>Review en herziening: goed kijken en herzien of het werkt; zijn er inderdaad betere prestaties en worden risico\u2019s effici\u00ebnt gemanaged?<\/li><li>Informatie, communicatie en rapportage: het delen van kennis intern en extern vanuit de organisatie. Dit geldt zowel top down als bottum up.<\/li><\/ul><h3>Tot slot:<\/h3><p>De komende weken zal ik dieper op de thema\u2019s ingaan, in de hoop hier concrete acties voor te kunnen benoemen. Want dat is wat mijn eigen kritiek op COSO ERM 2004 was, te veel verplichtingen en te weinig concrete stappen.<\/p><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5c620bf elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5c620bf\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-170129a\" data-id=\"170129a\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-540c163 elementor-widget elementor-widget-image\" data-id=\"540c163\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"768\" height=\"265\" src=\"https:\/\/www.naris.com\/wp-content\/uploads\/2017\/09\/coso-2017-768x265.png\" class=\"attachment-medium_large size-medium_large wp-image-9285\" alt=\"\" srcset=\"https:\/\/www.naris.com\/wp-content\/uploads\/2017\/09\/coso-2017-768x265.png 768w, https:\/\/www.naris.com\/wp-content\/uploads\/2017\/09\/coso-2017-300x104.png 300w, https:\/\/www.naris.com\/wp-content\/uploads\/2017\/09\/coso-2017-1024x354.png 1024w, https:\/\/www.naris.com\/wp-content\/uploads\/2017\/09\/coso-2017-1536x531.png 1536w, https:\/\/www.naris.com\/wp-content\/uploads\/2017\/09\/coso-2017.png 1540w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Risicomanagement De door COSO nieuw uitgegeven\u00a0standaard Enterprise Risk Management\u00a0&#8211; Integrating with Strategy and Performance \u2013 heeft veel te bieden. De&#8230;<\/p>\n","protected":false},"author":20,"featured_media":5760,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[18],"tags":[84,52,56],"class_list":["post-9277","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artikel","tag-coso","tag-risicomanagement-modellen","tag-strategie-en-performance-management"],"_links":{"self":[{"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/posts\/9277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/comments?post=9277"}],"version-history":[{"count":16,"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/posts\/9277\/revisions"}],"predecessor-version":[{"id":27946,"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/posts\/9277\/revisions\/27946"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/media\/5760"}],"wp:attachment":[{"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/media?parent=9277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/categories?post=9277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.naris.com\/nl\/wp-json\/wp\/v2\/tags?post=9277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}