Â
This lesson introduces the leading frameworks for establishing and implementing an Enterprise Risk Management (ERM) program, providing the structure and process for managing risk systematically.
3.1 The COSO Framework
The COSO (Committee of Sponsoring Organizations of the Treadway Commission) Internal Control-Integrated Framework is widely used for internal control and is a foundational document for enterprise risk management . The COSO framework for enterprise risk management integrates risk management with strategy and performance, emphasizing how risk is managed across an organization. Its five components are Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; and Information, Communication, and Reporting . Understanding the COSO framework, including its components and twenty principles, is a key learning outcome in professional risk management programs .
3.2 ISO 31000: Principles and Guidelines
The ISO 31000 standard provides principles and generic guidelines on risk management. It is designed to help organizations create a risk management framework that is integrated into their overall governance and management systems . ISO 31000 outlines principles such as being “integrated,” “structured,” and “inclusive,” and provides guidance on establishing the context, assessing risk, treating risk, and monitoring and reviewing . Programs often cover the COSO framework and ISO 31000 standard for enterprise risk management in a systematic manner, providing a comprehensive understanding of these key standards.
3.3 Applying Risk Management Frameworks
Both COSO and ISO 31000 provide a structured approach to risk management, but they are principles-based and require adaptation to the specific context of an organization. The frameworks emphasize that risk management is not a one-time project but a continuous process integrated into the organization’s culture, governance, and decision-making .