While the COSO Internal Control Framework focuses primarily on internal control design, the updated COSO Enterprise Risk Management (ERM) Framework—Aligning Risk with Strategy and Performance—looks broader to integrate risk management principles into strategic planning, corporate governance, and operational execution.
Strategy Selection ---> Objective Mapping ---> Performance Analysis ---> Portfolio View Evaluation

The ERM framework is structured around five core governance components:
  • Governance and Culture: Establishes board oversight responsibilities, defines desired corporate behaviors, and aligns risk management priorities with organizational strategy.
  • Strategy and Objective-Setting: Integrates risk considerations directly into strategic planning cycles. It requires establishing an explicit risk appetite baseline and assessing how alternative strategic decisions could change the organization’s risk profile.
  • Performance: Focuses on identifying and assessing risks that could impact the execution of planned business strategies, prioritizing exposures based on severity, and managing the total portfolio of risks within the organization’s overall appetite.
  • Review and Revision: Evaluates how corporate performance holds up during operational stress events, allowing the firm to adjust its strategy and control structures based on changing economic conditions.
  • Information, Communication, and Reporting: Utilizes automated data collection pathways to compile and present risk data to senior executives and board members, helping to support informed operational decisions.

Â