Skip to main content
Category: Enterprise Risk Management

COSO ERM Framework

Also known as: COSO ERM, Enterprise Risk Management—Integrating with Strategy and Performance, COSO Enterprise Risk Management Framework
Simply put

The COSO ERM Framework is a voluntary, non-binding framework developed by COSO to help organizations identify, assess, manage, and monitor risk across the enterprise. It is designed to connect risk management with an organization's strategy and performance rather than treating risk as a standalone activity. It is a widely referenced best-practice resource, not a law or regulation, and organizations adopt and adapt it based on their own circumstances.

Formal definition

The COSO ERM Framework, titled Enterprise Risk Management, Integrating with Strategy and Performance, is a principles-based framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Its 2017 iteration is organized around five interrelated components, Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; and Information, Communication, and Reporting, intended to embed risk considerations into strategy-setting and performance management. Supplementary guidance extends its application to specific domains, including a November 2020 publication addressing the application of the framework to compliance risk management. The framework is a voluntary standard rather than a legal requirement; its adoption, scope, and integration with related frameworks (such as ISO 31000) depend on the entity, sector, and jurisdiction, and it does not by itself allocate specific accountability among the board, management, or assurance functions.

Why it matters

Risk management has historically been treated as a siloed, backward-looking exercise disconnected from the decisions that actually shape an organization's future. The COSO ERM Framework matters because it reframes risk as something inseparable from strategy-setting and performance management, encouraging organizations to consider risk when objectives are being formed rather than after commitments have already been made. For boards and senior management, this integration is significant: it positions risk information as an input to strategic choices rather than a compliance afterthought.

Because the framework is voluntary and principles-based, its value lies in offering a common structure and vocabulary that organizations can adapt to their own circumstances, sector, and jurisdiction. It is widely referenced as a best-practice resource, which can help management demonstrate a considered, structured approach to enterprise risk. However, adopting the framework does not by itself satisfy any legal or regulatory obligation, and organizations should be careful not to treat reference to COSO ERM as evidence that specific accountabilities have been discharged.

The framework's reach has expanded through supplementary guidance, including a November 2020 publication applying the framework to compliance risk management. This illustrates how a general enterprise risk structure can be extended to specific domains, but it also underscores that ERM and compliance risk management remain distinct disciplines with different owners; the framework provides structure rather than dictating how accountability is allocated among the board, management, or assurance functions.

Who it's relevant to

Boards and Risk Committees
Directors exercising risk oversight may find the framework's Governance and Culture and Strategy and Objective-Setting components useful for structuring how risk information informs strategic discussions. The framework offers a reference point for oversight but does not itself define the board's duties, which generally derive from law, listing rules, and the organization's own governance arrangements.
Chief Risk Officers and Risk Management Functions
Those responsible for designing and operating enterprise risk management processes may use the framework's five components as a common structure and vocabulary. Because it is principles-based and voluntary, they typically adapt it to the organization's circumstances rather than applying it as a prescriptive checklist.
Chief Compliance Officers
Compliance leaders may find the November 2020 supplementary guidance on applying the COSO ERM Framework to compliance risk management relevant, as it extends the general framework to the compliance domain. Compliance risk management remains a distinct discipline, and the guidance provides structure rather than assigning specific accountabilities.
Senior Management and Strategy Leaders
Executives setting and executing strategy are a central audience, given the framework's emphasis on integrating risk with strategy and performance. The framework encourages consideration of risk during objective-setting, though how it is implemented depends on management's own judgment and the organization's context.
Internal Auditors and Assurance Functions
Assurance professionals may reference the framework when evaluating how an organization has structured its enterprise risk management. Because the framework does not itself allocate accountability, auditors should assess how responsibilities have actually been assigned within the specific entity.

Inside COSO ERM

Governance and Culture
The component addressing board risk oversight, operating structures, desired organizational culture, commitment to core values, and attraction and retention of capable people. It positions enterprise risk management as connected to the tone set at the top rather than as a standalone technical exercise.
Strategy and Objective-Setting
The component linking enterprise risk management to strategy and business objectives, including analysis of the business context, definition of risk appetite, and evaluation of alternative strategies. It reflects the framework's emphasis on considering risk when setting direction, not only when responding to events.
Performance
The component covering identification, assessment, and prioritization of risks that may affect achievement of objectives, along with selection of risk responses and development of a portfolio view of risk. This is where activities such as assessing likelihood and impact typically sit.
Review and Revision
The component focused on reviewing entity performance, considering substantial change, and pursuing improvement in enterprise risk management. It supports the framework's intent that risk management be evaluated and adjusted over time rather than treated as static.
Information, Communication, and Reporting
The component addressing the use of relevant information from internal and external sources and the communication and reporting of risk information across the organization and to stakeholders. It underpins the flow of risk data that informs decision-making at management and board levels.
Nature and Status
The COSO ERM framework is a voluntary, principles-based framework intended to help organizations integrate enterprise risk management with strategy and performance. It is not a law or regulation and is not universally mandatory; its adoption and depth of application generally depend on the entity, sector, and jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about COSO ERM.

Is the COSO ERM Framework a legal requirement that organizations must adopt?
No. The COSO ERM Framework (Enterprise Risk Management, Integrating with Strategy and Performance) is a voluntary, principles-based framework, not binding law. It is not mandated by statute or listing rules in the way specific legal obligations are. Some organizations adopt it because regulators, boards, or stakeholders view it as a recognized reference point, and in certain sectors supervisory expectations may effectively encourage a structured ERM approach. However, the framework itself is guidance rather than a legal requirement, and whether and how to apply it depends on the entity's jurisdiction, sector, size, and its own judgment.
Is the COSO ERM Framework the same as the COSO Internal Control, Integrated Framework?
No, though the two are related and share a common publisher. The COSO ERM Framework addresses enterprise risk management in connection with strategy and performance across the organization, while the COSO Internal Control, Integrated Framework addresses the design and operation of internal control, and is the framework many issuers reference for internal control over financial reporting. They serve different but complementary purposes and should not be treated as interchangeable. Selecting or referencing one does not automatically mean an organization has adopted the other.
Who within an organization is typically responsible for applying the COSO ERM Framework?
Accountability is generally distributed across roles. Management typically owns the operational task of identifying, assessing, and responding to risk and embedding ERM practices into day-to-day activities and strategy-setting. The board, often through a designated committee, generally holds an oversight role, reviewing whether management's risk management approach is functioning and consistent with the organization's risk appetite, rather than performing the operational work itself. Assurance functions such as internal audit may provide independent evaluation. The framework does not reassign these roles; organizations map its concepts onto their existing governance structure and their own definitions of authority.
How does the COSO ERM Framework relate to risk appetite and risk tolerance?
The framework treats risk appetite as a concept connecting strategy, objectives, and the amount of risk an organization is generally willing to accept in pursuit of value, and this is intended to inform decision-making rather than sit in isolation. In practice, organizations distinguish risk appetite from risk tolerance (the acceptable variation around specific objectives) and from risk capacity (the maximum risk an entity could bear). The framework provides structure for articulating these, but the specific thresholds, definitions, and how they are operationalized remain a matter for the organization's own judgment and calibration.
Can the COSO ERM Framework be scaled for a smaller or less complex organization?
The framework is principles-based, which generally allows organizations to apply its concepts proportionately to their size, complexity, sector, and risk profile. A smaller entity may implement the underlying principles through simpler processes and lighter documentation than a large, complex organization, provided the substance, connecting risk considerations to strategy and objectives, is addressed. How proportionality is applied is a matter of professional judgment and should reflect the organization's own circumstances and any applicable sector expectations; the framework does not prescribe a single implementation model.
How does adopting the COSO ERM Framework interact with other frameworks an organization may use, such as ISO 31000?
Organizations may reference more than one framework, and the COSO ERM Framework can coexist with standards such as ISO 31000, which also addresses risk management using a principles-based approach. The two differ in structure, terminology, and emphasis, so organizations typically decide how to align or map concepts to avoid duplication and inconsistent language. Neither is universally mandatory, and the choice, or combination, depends on the entity's needs, jurisdiction, sector, and stakeholder expectations. This entry is educational and not legal, audit, or compliance advice; framework selection and application should reflect professional judgment and relevant requirements.

Common misconceptions

Adopting the COSO ERM framework is a legal requirement for organizations.
The framework is a voluntary, principles-based reference rather than binding law. While some regulators, listing rules, or contractual arrangements may reference recognized risk frameworks, the COSO ERM framework itself is not universally mandatory, and requirements vary by jurisdiction, sector, and entity type. Entries here are educational and not legal, audit, or compliance advice.
The COSO ERM framework and the COSO internal control framework are the same thing.
They are distinct COSO publications with different scope. The ERM framework focuses on integrating risk management with strategy and performance across the enterprise, whereas the internal control framework addresses controls over areas such as operations, reporting, and compliance. Practitioners should be explicit about which framework they are referencing rather than treating them as interchangeable.
Implementing the framework makes enterprise risk management the responsibility of a single risk function or of the board alone.
The framework distributes activities across roles: the board typically exercises risk oversight, management generally owns the design and operation of risk responses and day-to-day risk activities, and assurance functions provide independent evaluation. Accountability for oversight versus operational risk management should not be conflated.

Best practices

Clarify role boundaries before applying the framework, documenting where board risk oversight ends and management's operational ownership of risk responses begins, so accountability is explicit rather than assumed.
Connect risk appetite to strategy and objective-setting deliberately, and keep risk appetite distinct from risk tolerance and risk capacity when translating framework concepts into your own policies.
Treat the framework as a voluntary reference to be tailored to your entity, sector, and jurisdiction, rather than adopting all components uniformly, and reconcile its use with any binding legal or listing requirements that apply.
Build a portfolio view of risk under the Performance component that aggregates individual risk assessments, distinguishing likelihood from impact and inherent from residual risk in your assessment methodology.
Use the Review and Revision component to schedule periodic evaluation of whether risk management remains effective after substantial change, rather than treating implementation as a one-time project.
Coordinate the Information, Communication, and Reporting component with your assurance functions so that independent evaluation of risk activities is distinguished from management's own reporting, avoiding overlap or gaps in accountability.