Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Enterprise Risk Management

Performance and Risk Integration

Also known as: Integrating Risk with Performance, Performance-Risk Integration
Simply put

Performance and risk integration is the practice of connecting how an organization manages risk with how it sets and tracks its goals, so that decisions about objectives and decisions about uncertainty are considered together rather than in isolation. The aim is to give leaders a unified view, helping them balance the pursuit of performance targets against the risks that could affect those targets. Approaches to this vary by organization and sector, and much of the guidance in this area is voluntary rather than legally required.

Formal definition

Performance and risk integration refers to aligning risk management activities, such as risk identification, assessment, and treatment, with performance management systems so that uncertainty is evaluated in the context of strategy and objectives. In the COSO framework tradition, this reflects the broader theme of integrating enterprise risk management with strategy and performance, positioning risk considerations within objective-setting and performance measurement rather than treating them as a separate function. In practice, implementation approaches differ across organizations and settings, for example, federal agencies aligning ERM with agency performance management systems, or transportation agencies developing guidance to integrate risk and performance management, and the field continues to evolve conceptually as practitioners and researchers reconcile definitions of performance with concepts of risk and uncertainty. This term primarily spans the risk management and governance pillars; specific frameworks, requirements, and applicability should be verified against the relevant primary sources, as much of this guidance represents leading practice rather than binding obligation.

Why it matters

Organizations routinely set ambitious performance targets while managing risk through a separate function, process, or reporting line. When these two activities operate in isolation, leaders can find themselves pursuing objectives without a clear view of the uncertainties that could undermine them, or conversely managing risks in ways that are disconnected from what the organization is actually trying to achieve. Performance and risk integration addresses this gap by encouraging that decisions about objectives and decisions about uncertainty be considered together, giving decision-makers a more unified basis for balancing the pursuit of goals against the risks to those goals.

This integration reflects a broader theme in the COSO Enterprise Risk Management tradition, which frames risk not as a standalone compliance exercise but as something to be embedded within strategy-setting and performance measurement. Positioning risk considerations inside objective-setting can help organizations avoid treating risk management as an afterthought and can support more informed trade-offs. That said, much of the guidance in this area represents leading practice rather than binding legal obligation, and organizations should be cautious about assuming any single approach guarantees better outcomes.

Because the field continues to evolve conceptually, including academic work reconciling how performance is defined with concepts of risk and uncertainty, practitioners should treat integration as an area of active development rather than settled doctrine. Applicability, maturity, and specific methods vary considerably across organizations and sectors, and specifics should be verified against the relevant primary sources.

Who it's relevant to

Risk Managers and ERM Leaders
Those responsible for enterprise risk management use integration to connect risk identification, assessment, and treatment with the organization's strategy and objectives, helping ensure risk information is considered alongside performance decisions rather than in a separate silo.
Governance Professionals and Senior Leaders
Boards and executives seeking a unified view of objectives and uncertainty benefit from integration, which can support more informed trade-offs when balancing performance targets against the risks that could affect them. This term primarily spans the risk management and governance pillars.
Public Sector and Agency Practitioners
Federal agencies aligning ERM with agency performance management systems, and transportation agencies developing guidance to integrate risk and performance management, illustrate how integration is applied in government settings where performance frameworks are already established.
Practitioners and Researchers Developing the Field
Because definitions of performance continue to be reconciled with concepts of risk and uncertainty in academic and practitioner work, those shaping methodologies and guidance have a stake in how integration evolves. Much of the available guidance reflects leading practice rather than binding obligation and should be verified against primary sources.

Inside Performance and Risk Integration

Objective Alignment
The linking of risk management activities to the organization's strategic and operational objectives, so that risks are assessed in terms of their potential effect on the outcomes the organization is trying to achieve. In many frameworks, such as COSO ERM, this connection between strategy, performance, and risk is a central theme.
Risk-Adjusted Performance View
The practice of evaluating performance not in isolation but alongside the level of risk taken to achieve it, so that results are understood in light of the uncertainty accepted. This typically helps distinguish outcomes driven by sound decisions from those influenced by favorable or unfavorable events.
Shared Metrics and Indicators
The use of measures that connect performance targets with risk information, such as pairing performance indicators with risk indicators. This often supports monitoring of whether the organization is operating within its stated risk appetite while pursuing its goals.
Risk Appetite in Planning
The incorporation of risk appetite, the amount and type of risk an organization is willing to pursue in pursuit of its objectives, into target-setting and performance planning. This should be distinguished from risk tolerance, the acceptable variation around specific objectives, and risk capacity, the maximum risk the organization can bear.
Governance and Reporting Linkage
The structures and reporting channels through which integrated performance and risk information reaches decision-makers, including boards and management. This spans the governance pillar (decision rights and oversight) and the risk pillar (assessment and treatment of uncertainty).

Common questions

Answers to the questions practitioners most commonly ask about Performance and Risk Integration.

Does integrating performance and risk mean that risk management and performance management become the same function?
No. Integration refers to aligning and connecting the two disciplines so that decisions about objectives account for the uncertainties that could affect them, not to merging them into a single undifferentiated activity. Performance management typically concerns setting, pursuing, and measuring progress against objectives, while risk management concerns identifying, assessing, and treating the uncertainty that could affect those objectives. In many frameworks, including COSO ERM, risk is discussed in the context of strategy and performance, but the two retain distinct purposes, methods, and often distinct accountabilities. Treating them as identical can obscure the specific analytical work each requires.
Is the goal of integrating performance and risk simply to minimize or eliminate risk so that targets are met?
Not typically. Integration is generally aimed at making risk visible in the pursuit of objectives so that trade-offs can be made deliberately, not at driving risk toward zero. No control or management approach can eliminate risk, and reducing risk beyond an organization's appetite may forgo value or impose disproportionate cost. In many frameworks the emphasis is on taking the right amount of the right risks in line with a defined risk appetite, rather than avoidance for its own sake. The objective is informed decision-making about how much uncertainty to accept in exchange for expected performance.
How can risk considerations be embedded into the objective-setting and planning process?
A common approach is to consider risk at the point objectives are set, so that targets, budgets, and strategic choices reflect the uncertainties that could affect them rather than being assessed for risk only afterward. This often involves discussing the range of possible outcomes around a target, the assumptions underlying it, and the level of risk the organization is willing to accept in pursuit of it. Applicability and the specific mechanisms vary by organization size, sector, and the framework adopted, and the depth of analysis is typically scaled to the significance of the objective.
What indicators help connect performance measures with risk measures in practice?
Organizations often pair performance indicators, which track progress toward objectives, with risk indicators, which signal changes in exposure or the likelihood of an adverse event. Linking the two can help management see when pursuit of a target is increasing exposure, or when a shift in risk conditions may threaten expected performance. The selection and thresholds of such indicators are context-dependent and should be tied to the specific objectives and the organization's risk appetite and tolerance. These are commonly matters of leading practice rather than binding requirement, and their design varies by jurisdiction, sector, and organizational maturity.
Who should be accountable for performance and risk integration within an organization?
Accountability arrangements vary, but integration generally works best when those responsible for objectives also engage with the associated risks, supported by risk and compliance functions. Many organizations use governance structures that assign decision rights for objective-setting and risk acceptance to management, with oversight from senior leadership and the board or an equivalent body. The precise allocation of roles depends on the organization's governance model, size, and any applicable regulatory expectations, and should be documented to make decision rights and escalation paths clear. Legal or regulatory allocation of specific responsibilities should be verified against the relevant requirements.
How can integration be reflected in reporting to management and the board?
A frequent practice is to present performance information alongside the related risk information, so that decision-makers can see progress toward objectives and the exposures affecting them together rather than in separate reports. This may include how current performance relates to defined risk appetite and tolerance, and what trade-offs underlie the results. The format, frequency, and level of detail are context-dependent and typically calibrated to the audience and the significance of the matters reported. Where specific reporting obligations apply, such as those arising from regulation or listing rules, those requirements should be verified against the primary source and may warrant professional advice.

Common misconceptions

Integrating performance and risk means simply adding a risk section to performance reports.
Integration typically involves connecting the underlying decisions, metrics, and objectives so that risk considerations inform how performance is planned and evaluated, rather than presenting risk as a separate appendix. The depth of integration varies by organization and framework adopted.
Strong performance results indicate that risks were well managed.
Favorable outcomes can occur despite poor risk management, and vice versa, because outcomes are influenced by uncertain events. A risk-adjusted view seeks to separate the quality of decisions and controls from the effect of chance, and no measure guarantees this distinction is captured perfectly.
Performance and risk integration is a compliance requirement.
In many contexts it reflects leading practice and framework guidance (such as COSO ERM) rather than a binding legal obligation. Applicability and any related requirements vary by jurisdiction, sector, and organization size, and specific mandates should be verified against the relevant primary sources.

Best practices

Map key performance objectives to the risks that could affect their achievement, so that risk assessment is anchored to what the organization is trying to accomplish rather than conducted in isolation.
Pair performance indicators with corresponding risk indicators, and monitor both against the organization's stated risk appetite and tolerance.
Distinguish explicitly between risk appetite, risk tolerance, and risk capacity when embedding these concepts into planning and target-setting, to avoid conflating limits that serve different purposes.
Present performance results alongside the level of risk taken, so decision-makers can interpret outcomes in a risk-adjusted context and avoid attributing favorable results solely to good management.
Route integrated performance and risk information through governance and reporting channels that reach management and the board, clarifying decision rights and oversight responsibilities.
Confirm which elements of integration reflect binding obligations versus voluntary framework guidance for your jurisdiction and sector, and consult appropriate professional advice where legal interpretation is required.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide