← Standards
COSO ERM 2017COSO
Enterprise Risk Management — Integrating with Strategy and Performance
The enterprise risk reference framework, built on five components and twenty principles. Its major contribution is anchoring risk in strategy rather than internal control, making it the natural governance complement to ISO 31000.
Official textWho it applies to
- Audit committees
- Executive leadership
- ERM functions
Structuring points
- The risk profile is compared against the expected performance profile
- Risk appetite is a board decision, not an average of matrices
- Combines well with ISO 31000: COSO for governance, ISO for process
Governance, strategy, performance, review and risk communication.