COSO ERM
Also known as: Enterprise Risk Management
Enterprise-level extension of COSO internal control framework integrating strategy and performance with risk.
COSO Enterprise Risk Management is the Committee of Sponsoring Organizations' framework for enterprise-level risk management, integrating strategy and performance with risk consideration. The 2017 revision (Enterprise Risk Management — Integrating with Strategy and Performance) substantially restructured the earlier 2004 framework around five interrelated components and twenty principles, emphasizing risk's role in strategy formulation rather than treating it as compliance overlay. COSO ERM is widely adopted by US public companies and is referenced in audit and regulatory expectations even where not formally required.
Core components
- Five components: Governance & Culture
- Strategy & Objective-Setting
- Performance
- Review & Revision
- Information, Communication & Reporting
- Twenty principles supporting the components
Primary use case
Enterprise risk management programs at large organizations; reference framework for risk committees and audit functions; basis for regulatory expectations around risk management.
Common criticisms
- Volume and complexity create implementation burden
- principles can be applied superficially as documentation exercises
- integration with strategy can be aspirational rather than operational
- substantial overlap with COSO Internal Control framework creates confusion about which to apply when.
Lineage
- Child of
- COSO Internal Control-Integrated Framework
- Siblings
- COSO Internal Control-Integrated Framework, ISO 31000, Three Lines Model, FAIR
- Derived from
- COSO Internal Control-Integrated Framework