COSO ERM

Also known as: Enterprise Risk Management

framework · governance and compliance · regulatory-standard

Enterprise-level extension of COSO internal control framework integrating strategy and performance with risk.

COSO Enterprise Risk Management is the Committee of Sponsoring Organizations' framework for enterprise-level risk management, integrating strategy and performance with risk consideration. The 2017 revision (Enterprise Risk Management — Integrating with Strategy and Performance) substantially restructured the earlier 2004 framework around five interrelated components and twenty principles, emphasizing risk's role in strategy formulation rather than treating it as compliance overlay. COSO ERM is widely adopted by US public companies and is referenced in audit and regulatory expectations even where not formally required.

Originators

Committee of Sponsoring Organizations of the Treadway Commission (COSO) high

Year / Decade

2004 (original); 2017 (substantial revision) high

Primary sources

COSO (2004). Enterprise Risk Management — Integrated Framework, COSO (2017). Enterprise Risk Management — Integrating with Strategy and Performance high

Core components

Primary use case

Enterprise risk management programs at large organizations; reference framework for risk committees and audit functions; basis for regulatory expectations around risk management.

Common criticisms

Lineage

Child of
COSO Internal Control-Integrated Framework
Siblings
COSO Internal Control-Integrated Framework, ISO 31000, Three Lines Model, FAIR
Derived from
COSO Internal Control-Integrated Framework