Skip to main content
Category: Enterprise Risk Management

Performance

Also known as: Organisational performance, Business performance
Simply put

Performance refers to how well systems, processes, teams, or an organisation carry out their intended activities and achieve their goals, typically assessed through measurable outcomes such as efficiency and goal attainment. In a business setting, it is a central measure of whether an entity is doing what it set out to do. The specific meaning and the metrics used generally depend on the context, the objectives being pursued, and the standards a given organisation chooses to apply.

Formal definition

In a governance and management context, performance denotes the measurable capability, efficiency, and degree of goal achievement of systems, processes, teams, or an organisation, typically evaluated against defined objectives and metrics. Performance measurement is generally an operational and management responsibility, while the board and its committees typically retain oversight of performance frameworks and outcomes rather than day-to-day execution. The evidence supplied treats performance broadly and does not establish jurisdiction-specific requirements, prescribed metrics, or any binding framework; the appropriate definition, indicators, and thresholds depend on the entity, its objectives, and applicable standards. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Performance sits at the heart of what a governance system is meant to protect and enable: whether an organisation actually does what it set out to do. Boards and executives use performance information to judge whether strategy is being executed, whether resources are being used efficiently, and whether stated objectives are being met. Without reliable performance measurement, oversight becomes guesswork, and decisions rest on impressions rather than evidence of goal attainment.

The discipline matters because performance is not a single, fixed quantity. Its meaning depends on context, the objectives being pursued, and the standards a given organisation chooses to apply. The same activity can look strong against one set of metrics and weak against another, which is why the selection and integrity of performance indicators is itself a governance concern. Poorly chosen metrics can create incentives that undermine the very goals they were meant to track.

Performance is best understood as related to, but distinct from, risk and compliance. Strong performance on an operational metric does not on its own demonstrate that risks are being managed or that legal and regulatory obligations are being met, and the evidence supplied here treats performance broadly rather than tying it to any particular framework or requirement. Governance professionals should be alert to the difference between measuring what is easy and measuring what genuinely reflects goal achievement.

Who it's relevant to

Board members and committee chairs
Boards typically hold oversight of performance frameworks and outcomes rather than executing measurement themselves. Directors rely on performance information to assess whether strategy is being delivered and to challenge management where results diverge from objectives, while resisting the temptation to step into operational execution.
Executives and operational management
Performance measurement is generally a management and operational responsibility. Executives define objectives, select context-appropriate metrics, and interpret whether systems, processes, and teams are achieving their intended goals efficiently.
Internal auditors and assurance functions
Assurance professionals may examine whether performance information is reliable and whether the metrics and thresholds an organisation uses genuinely reflect goal attainment. Their focus is typically on the integrity of measurement rather than on setting performance targets.
General counsel and compliance officers
Because strong performance on a business metric does not by itself demonstrate that legal or regulatory obligations are met, these professionals should treat performance as distinct from compliance and remain alert to metrics or incentives that could conflict with obligations. The appropriate treatment depends on the entity, its objectives, and applicable standards.

Inside Performance

Performance Monitoring
The ongoing tracking of how effectively an entity, function, or control operates against defined objectives, targets, or expected outcomes. In a governance context, monitoring is typically distributed across the lines of defense, with management owning day-to-day performance and assurance functions providing independent evaluation.
Performance Metrics and Indicators
Quantitative and qualitative measures used to assess results, such as key performance indicators (KPIs) for operational and strategic goals and, in some frameworks, key risk indicators (KRIs) that signal changes in risk exposure. These measures should be defined with clear ownership and are generally selected by management, subject to board or committee oversight.
Control Operating Effectiveness
A distinct dimension of performance concerning whether a control functions as designed over a period of time. This should not be conflated with control design; a well-designed control can still fail in operation. Assessing operating effectiveness is typically a focus of internal audit and, where applicable, external assurance.
Board and Committee Oversight of Performance
The board's role in overseeing management's performance and the entity's results, generally exercised through committees (for example, audit, risk, or remuneration committees where they exist). This is an oversight function and should be distinguished from management's operational responsibility for delivering performance.
Performance Against Risk Appetite
The evaluation of whether activities and outcomes remain within the level of risk the entity is willing to accept. This links performance to risk appetite and tolerance and, under certain frameworks such as COSO ERM or ISO 31000, connects strategy execution to risk-taking; the specifics depend on the framework adopted and the entity's own choices.
Performance Reporting and Assurance
The structured communication of performance results to management, the board, regulators, or other stakeholders, along with any independent assurance over the reliability of that reporting. Reporting obligations vary by jurisdiction, sector, and entity type, and may be a legal requirement in some contexts or a voluntary practice in others.

Common questions

Answers to the questions practitioners most commonly ask about Performance.

Is the board responsible for managing the organization's day-to-day performance?
Generally, no. The board's role in relation to performance is typically one of oversight: setting or approving strategic objectives, monitoring progress against them, and holding management accountable. Day-to-day performance management, executing strategy, allocating resources operationally, and delivering results, usually sits with management. Conflating these roles risks either the board straying into operational detail or management escaping accountability. The precise boundary depends on the entity type, jurisdiction, and the board's own delegated authority framework. This entry is educational and not legal or governance advice.
Does strong financial performance mean an organization's governance and risk controls are effective?
Not necessarily. Financial performance and the effectiveness of governance, risk, and control processes are related but distinct. An organization can post strong results while carrying significant unaddressed risks, weak control design, or controls that are well-designed but not operating effectively. Conversely, sound controls do not guarantee favorable outcomes. Assurance functions typically assess control design and operating effectiveness separately from performance results, and boards generally consider both when evaluating whether performance is sustainable and within the agreed risk appetite.
How should a board committee structure its oversight of performance against strategy?
Practices vary by entity and jurisdiction, but boards commonly assign performance oversight to the full board or delegate specific aspects to committees, for example, a remuneration or compensation committee reviewing performance-linked pay, or an audit committee scrutinizing the integrity of performance reporting. Effective oversight typically involves agreed metrics, clear reporting cadence, and defined thresholds that trigger board attention. The board sets or approves objectives and monitors them; it generally does not manage delivery itself. The appropriate structure depends on the organization's size, sector, and applicable governance code or listing rules.
What is the relationship between performance targets and risk appetite when setting objectives?
Performance targets and risk appetite are typically considered together so that objectives can be pursued within the level and type of risk the organization is willing to accept. Setting aggressive targets without reference to risk appetite can incentivize behavior that breaches tolerances. In many frameworks, management proposes targets and the board or a designated committee approves both the targets and the associated appetite, with tolerances defining acceptable variation. This is a design consideration rather than a fixed rule, and its application depends on the organization's own framework and judgment.
How can assurance functions provide confidence over the accuracy of performance reporting?
Assurance over performance reporting is commonly organized along the lines of defense: management owns the reporting and its controls, a compliance or risk function may provide oversight and challenge, and internal audit typically provides independent assurance over the design and operating effectiveness of relevant controls. External audit, where applicable, may address certain financial performance disclosures. The specific scope depends on the reporting in question, the applicable requirements, and whether the metrics are financial or non-financial. Not all performance data is subject to formal assurance.
What should management consider when linking incentive compensation to performance metrics?
Management, and often a remuneration committee, generally consider whether metrics are measurable, aligned with strategy, resistant to manipulation, and balanced across short- and long-term horizons. Consideration is typically given to whether incentives could encourage excessive risk-taking beyond appetite, and to mechanisms such as deferral or clawback where used. In some jurisdictions and for certain entity types, aspects of executive pay are subject to disclosure requirements or governance code provisions, while others remain matters of voluntary best practice. Specific arrangements depend on jurisdiction, sector, and professional judgment; this entry is not legal or remuneration advice.

Common misconceptions

Performance measurement is solely the board's responsibility.
Management typically owns the operational responsibility for delivering and measuring day-to-day performance, while the board and its committees generally exercise oversight. Attributing operational performance duties to the board, or oversight duties to management, conflates distinct roles.
If a control is well designed, it is performing effectively.
Control design and operating effectiveness are separate concepts. A control that is appropriately designed can still fail in practice due to inconsistent execution, override, or changing conditions. Performance assessment generally requires evaluating both dimensions.
Strong financial or operational performance means risk is being well managed.
Favorable results do not necessarily indicate that outcomes fall within the entity's risk appetite or that residual risk is acceptable. Performance and risk are related but distinct; good outcomes can coexist with excessive or poorly understood risk-taking.

Best practices

Assign clear ownership for each performance measure, distinguishing management's operational responsibility for results from the board's and committees' oversight role.
Evaluate controls on both design and operating effectiveness over time, rather than assuming a sound design guarantees reliable operation.
Link performance evaluation to the entity's stated risk appetite and tolerance, so that results are assessed against acceptable risk levels and not on outcomes alone.
Select performance indicators that are clearly defined and, where relevant, complement KPIs with risk indicators, ensuring each measure has an accountable owner.
Route performance reporting through the appropriate governance channels and confirm which reporting obligations are legal requirements versus voluntary practices in the relevant jurisdiction, sector, and entity type.
Involve independent assurance functions, such as internal audit, to provide objective evaluation of performance and reporting reliability separate from the functions being assessed.