Standards
COSO ERM 2017COSO

Enterprise Risk Management — Integrating with Strategy and Performance

The enterprise risk reference framework, built on five components and twenty principles. Its major contribution is anchoring risk in strategy rather than internal control, making it the natural governance complement to ISO 31000.

Official text

Who it applies to

  • Audit committees
  • Executive leadership
  • ERM functions

Structuring points

  • The risk profile is compared against the expected performance profile
  • Risk appetite is a board decision, not an average of matrices
  • Combines well with ISO 31000: COSO for governance, ISO for process

Governance, strategy, performance, review and risk communication.