COSO ERM Framework
The COSO ERM Framework is a voluntary, non-binding framework developed by COSO to help organizations identify, assess, manage, and monitor risk across the enterprise. It is designed to connect risk management with an organization's strategy and performance rather than treating risk as a standalone activity. It is a widely referenced best-practice resource, not a law or regulation, and organizations adopt and adapt it based on their own circumstances.
The COSO ERM Framework, titled Enterprise Risk Management, Integrating with Strategy and Performance, is a principles-based framework issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Its 2017 iteration is organized around five interrelated components, Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; and Information, Communication, and Reporting, intended to embed risk considerations into strategy-setting and performance management. Supplementary guidance extends its application to specific domains, including a November 2020 publication addressing the application of the framework to compliance risk management. The framework is a voluntary standard rather than a legal requirement; its adoption, scope, and integration with related frameworks (such as ISO 31000) depend on the entity, sector, and jurisdiction, and it does not by itself allocate specific accountability among the board, management, or assurance functions.
Why it matters
Risk management has historically been treated as a siloed, backward-looking exercise disconnected from the decisions that actually shape an organization's future. The COSO ERM Framework matters because it reframes risk as something inseparable from strategy-setting and performance management, encouraging organizations to consider risk when objectives are being formed rather than after commitments have already been made. For boards and senior management, this integration is significant: it positions risk information as an input to strategic choices rather than a compliance afterthought.
Because the framework is voluntary and principles-based, its value lies in offering a common structure and vocabulary that organizations can adapt to their own circumstances, sector, and jurisdiction. It is widely referenced as a best-practice resource, which can help management demonstrate a considered, structured approach to enterprise risk. However, adopting the framework does not by itself satisfy any legal or regulatory obligation, and organizations should be careful not to treat reference to COSO ERM as evidence that specific accountabilities have been discharged.
The framework's reach has expanded through supplementary guidance, including a November 2020 publication applying the framework to compliance risk management. This illustrates how a general enterprise risk structure can be extended to specific domains, but it also underscores that ERM and compliance risk management remain distinct disciplines with different owners; the framework provides structure rather than dictating how accountability is allocated among the board, management, or assurance functions.
Who it's relevant to
Inside COSO ERM
Common questions
Answers to the questions practitioners most commonly ask about COSO ERM.