Skip to main content
Category: Enterprise Risk Management

Strategy and Objective-Setting

Also known as: Strategy and Objective Setting, Strategy & Objective-Setting Component
Simply put

Strategy and objective-setting is the part of an organization's risk management approach that connects its long-term direction and the specific goals it sets to the risks it faces. The idea is that an organization considers risk when it chooses its strategy and defines what it wants to achieve, so that its plans and its risk-taking are aligned. This helps ensure that goals are realistic and that decisions account for the uncertainties that could affect them.

Formal definition

Strategy and objective-setting is one of the components of the COSO Enterprise Risk Management (ERM) framework, under which enterprise risk management, strategy, and objective-setting are intended to work together. In practice, strategy generally reflects an organization's longer-term direction (often framed over multiple years), while objectives are the more specific, shorter-term goals that support that strategy; strategies, in turn, are the initiatives and processes used to achieve those objectives. Objectives are commonly framed to be specific, measurable, achievable, realistic, and timely (SMART) so progress can be tracked. This entry is educational and not legal, audit, or compliance advice; the precise definition, principles, and application of this component depend on the specific edition of the COSO ERM framework and the entity's own facts and judgment, which are beyond the scope of the evidence provided.

Why it matters

Strategy and objective-setting matters because the risks an organization faces are shaped by the direction it chooses and the goals it sets. When strategy is developed without considering risk, an organization can pursue plans that look attractive on their face but carry uncertainties that make the goals unrealistic or expose the entity to consequences it never intended to accept. By positioning strategy and objective-setting as a component of the COSO ERM framework, the framework encourages organizations to treat risk as an input to strategic decisions rather than as something considered only after the strategy is fixed.

This alignment also helps make objectives meaningful. Framing objectives to be specific, measurable, achievable, realistic, and timely (SMART) supports the ability to track progress, and connecting those objectives to the broader strategy helps ensure that day-to-day goals actually advance the organization's longer-term direction. Where objectives are set without regard to the risks that could affect them, an organization may find that its targets are unattainable or that achieving them undermines other priorities.

The practical significance of this component depends heavily on the specific edition of the COSO ERM framework in use and on the organization's own facts and judgment. COSO ERM is a voluntary framework rather than a universal legal requirement, and the way strategy and objective-setting is applied will vary by entity, sector, and jurisdiction. This entry is educational and not legal, audit, or compliance advice.

Who it's relevant to

Boards and their committees
Boards generally exercise oversight of strategy and of the risks associated with it, rather than developing strategy operationally. This component is relevant to boards and any committee with risk oversight responsibilities because it frames how risk is intended to be considered when the organization sets its direction and defines what it aims to achieve. The specific allocation of oversight duties depends on the entity, its governance structure, and applicable requirements.
Senior management and strategy functions
Management typically owns the development of strategy and the setting of objectives, translating longer-term direction into shorter-term, measurable goals and the initiatives used to achieve them. This component is relevant to those who design and execute the strategic planning process and who are responsible for framing objectives, for example using SMART criteria, so progress can be tracked.
Risk and ERM professionals
Those responsible for enterprise risk management use this component to help ensure that risk is treated as an input to strategy and objective-setting rather than an afterthought. Their focus is generally on aligning the organization's risk-taking with its chosen direction, consistent with how the COSO ERM framework positions this component, though the precise application depends on the framework edition and the entity's own judgment.
Internal auditors and assurance functions
Assurance functions may consider how well an organization's strategy and objective-setting practices align with the ERM framework it has adopted, without owning the strategy itself. Whether and how this component is evaluated depends on the assurance function's mandate, the framework in use, and the entity's facts; this entry is educational and not audit advice.

Inside Strategy and Objective-Setting

Business Context Analysis
Consideration of the internal and external environment in which the organization operates, including how conditions may affect the entity's ability to achieve its strategy. Under the COSO ERM framework, understanding context is generally treated as a precursor to setting strategy and objectives.
Risk Appetite Definition
Articulation of the types and amount of risk the organization is generally willing to accept in pursuit of value. Risk appetite is typically set at the board and senior management level and is intended to inform, rather than dictate, strategic choices.
Alignment of Strategy with Mission, Vision, and Values
The process of evaluating whether a chosen strategy is consistent with the entity's stated mission, vision, and core values. Under certain frameworks, this alignment is examined for the possibility that the selected strategy does not support, or diverges from, those foundational elements.
Evaluation of Alternative Strategies
Consideration of the risk implications of different strategic options before one is chosen. This component focuses on the risk of selecting a strategy, not solely on execution risk, and is generally management's responsibility with board oversight.
Formulation of Business Objectives
The translation of strategy into specific, measurable business objectives at various levels of the organization. Objectives generally serve as the basis against which risks to their achievement are subsequently identified and assessed.

Common questions

Answers to the questions practitioners most commonly ask about Strategy and Objective-Setting.

Is strategy and objective-setting a risk management activity owned by the risk function?
Not exactly. Strategy and objective-setting is generally a management responsibility, typically led by executive management and overseen by the board, rather than an activity owned by the risk function. Under frameworks such as COSO's Enterprise Risk Management framework, this component describes how risk considerations are integrated into strategy development and objective-setting so that strategy aligns with mission, vision, and stated risk appetite. The risk function typically supports and informs this process by providing risk insight, but it does not own the setting of strategy or objectives. Accountability for strategic decisions generally sits with management, subject to board oversight. The precise allocation of these roles varies by jurisdiction, entity type, and the organization's own governance arrangements.
Does integrating risk into strategy simply mean identifying the risks to achieving the chosen strategy?
That is only part of it. Under frameworks such as COSO ERM, integrating risk into strategy is often described as involving more than identifying risks to executing an already-selected strategy. It can also include considering the possibility that a strategy does not align with the organization's mission, vision, and values, as well as the risk implications of the strategy chosen versus alternatives that were not pursued. Focusing only on execution risk may overlook these broader dimensions. How deeply an organization addresses each dimension is a matter of management judgment and depends on the framework adopted, the entity's context, and its objectives. This description is educational and not a prescription for any particular organization.
How should the board be involved in strategy and objective-setting without taking over management's role?
In many governance arrangements, the board's role is generally one of oversight, challenge, and approval rather than day-to-day formulation. Boards commonly review and constructively challenge the strategy proposed by management, test its alignment with the organization's stated risk appetite and long-term interests, and satisfy themselves that the process considered relevant risks. Management typically retains responsibility for developing and executing the strategy. The appropriate balance depends on the entity type, the size and complexity of the organization, applicable law and listing rules, and any governance code the organization follows. This is a matter for the organization's own judgment and, where relevant, professional advice.
How does risk appetite connect to objective-setting in practice?
Risk appetite is often used as a reference point when objectives are set, so that the objectives an organization pursues are broadly consistent with the amount and type of risk it is generally willing to accept in pursuit of its mission and vision. In practice, this can mean testing proposed objectives against the stated appetite and, where an objective would require accepting risk beyond that appetite, revisiting either the objective or the appetite through the appropriate governance process. It is worth distinguishing risk appetite from risk tolerance, which typically refers to acceptable variation around specific objectives, and from risk capacity, which refers to the maximum risk an organization is able to bear. How these are defined and operationalized varies by framework and organization.
How can an organization tell whether risk has genuinely been integrated into strategy rather than treated as a separate exercise?
Indicators can include whether risk considerations appear in strategy discussions rather than only in a parallel risk report, whether alternative strategies were evaluated for their risk implications, and whether the connection between chosen objectives and the organization's risk appetite is documented and traceable. Assurance functions, such as internal audit operating independently of management, may in some organizations review the design and operation of this process. What constitutes adequate integration is a matter of professional judgment and depends on the framework adopted and the organization's context; there is no single universal test.
How often should strategy and objectives be revisited to keep risk considerations current?
There is no universally mandated frequency. Many organizations revisit strategy and objectives on a periodic cycle, such as during an annual planning process, and also on an event-driven basis when significant internal or external changes occur, for example shifts in the operating environment, regulatory developments, or changes in the risk profile. The right cadence depends on the organization's size, sector, complexity, and the pace of change it faces, as well as any requirements set by applicable law, listing rules, or an adopted governance code. This entry is educational and does not prescribe a schedule for any particular entity; organizations should apply their own judgment and seek professional advice where appropriate.

Common misconceptions

Strategy and objective-setting is purely a management activity in which the board plays no part.
While management generally formulates and executes strategy, the board typically holds an oversight role, including reviewing strategy and, in many governance models, approving or challenging the organization's risk appetite. The distinction is one of oversight versus operational responsibility, not exclusion.
Risk appetite and risk tolerance mean the same thing within strategy-setting.
Risk appetite generally refers to the broad amount and type of risk an organization is willing to pursue at a strategic level, whereas risk tolerance typically describes the acceptable level of variation relative to specific objectives. They operate at different levels and should not be treated as interchangeable.
Applying the COSO ERM framework's approach to strategy and objective-setting is a universal legal requirement.
COSO ERM is a voluntary framework, not binding law. Whether and how an organization adopts it depends on jurisdiction, sector, entity type, and management judgment. It provides guidance rather than a mandatory standard.

Best practices

Analyze the internal and external business context before finalizing strategy, so that objectives are set with an informed understanding of the environment in which the organization operates.
Define and document risk appetite at the board and senior management level, and use it to inform the evaluation of strategic options rather than as an after-the-fact justification.
Assess the possibility that a chosen strategy does not align with the organization's mission, vision, and values, treating this misalignment as a distinct risk to be considered.
Evaluate the risk implications of alternative strategies during the selection process, not only the risks associated with executing the strategy already chosen.
Translate strategy into specific, measurable business objectives that can serve as a clear basis for later risk identification and assessment.
Clarify the respective roles of the board and management in strategy and objective-setting, distinguishing oversight responsibilities from operational ones, and reflect this allocation in governance documentation.