The Committee of Sponsoring Organizations of the Treadway Commission developed the COSO Enterprise Risk Management – Integrating with Strategy and Performance framework. While ISO 31000 provides general guidelines, COSO focuses on aligning risk management directly with corporate governance, financial reporting, and strategic planning. [1, 2, 3]
The Five Interrelated Components of COSO ERM
The COSO framework organizes its risk management principles into five core operational components: [1, 2]
[Governance & Culture] ---> [Strategy & Objective-Setting] ---> [Performance]
|
v
[Review & Revision] <--- [Information, Comms, & Reporting] <----------+
- Governance and Culture: Establishes board oversight responsibilities, defines desired corporate behaviors, and reinforces ethical, risk-aware values across the enterprise. [1]
- Strategy and Objective-Setting: Evaluates risk appetite alongside strategic planning, ensuring business growth targets are realistic and balanced against potential threats. [1]
- Performance: Identifies, assesses, and prioritizes risks that could disrupt strategic execution, then selects appropriate risk responses. [1]
- Review and Revision: Evaluates organizational performance after major operational changes to see how well the ERM framework adapted to the new environment. [1]
- Information, Communication, and Reporting: Shares necessary risk data across all levels of the organization to support timely decision-making. [1]
Â