This lesson examines the two dominant enterprise risk management frameworks globally—the COSO framework (widely used in the USA) and ISO 31000 (preferred in Europe). It covers their core components, differences, and the institutional factors driving their adoption. The SOA’s CFE 101 Enterprise Risk Management course emphasizes foundational ERM concepts and their application to organizations .

 

  • The COSO Framework (USA): COSO (Committee of Sponsoring Organizations of the Treadway Commission) is specifically focused on ERM as an ongoing process and is largely aimed at helping US organisations meet their requirements for reporting under the Sarbanes–Oxley Act (SOX). The approach is structured and governance-focused, with an emphasis on financial control, audit, and internal governance.

  • The ISO 31000 Framework (Europe/Global): ISO 31000 is a principles-based, adaptable standard published by the International Organization for Standardization. Unlike COSO, it is meant to be a more voluntary guidance and is a more generic and process-oriented standard focused on the importance of an overall risk management framework. The standard is based on three core components: Principles (foundation for effective risk management), Framework (structure tying risk management to leadership and strategy), and Process (a structured cycle of communication, risk identification, analysis, and treatment).

  • Regulatory Frameworks – Basel III and Beyond: The Basel III international regulatory framework establishes standards for bank capital, leverage, and liquidity. Key components include minimum capital requirements, the Liquidity Coverage Ratio (LCR), and the Net Stable Funding Ratio (NSFR). Importantly, the implementation of Basel III differs across jurisdictions: there are differing UK, US, and European perspectives in terms of specific capital requirements (e.g., the CRD IV package in Europe, Prudential Regulation Authority (PRA) in the UK, and Federal Reserve Board alignment in the US) .

  • Internal Capital Adequacy Assessment Process (ICAAP): Under Pillar 2 of the Basel framework, the ICAAP requires banks to assess their capital adequacy relative to their risk profile. This involves defining risk-bearing capacity, quantifying risk appetite, and assigning capital limits to business units. It includes technical considerations such as going concern vs. gone concern analysis and stress testing .