Enterprise Risk Management (ERM) is a structured, consistent, and continuous process used across the entire organization to identify, assess, decide on responses to, and report on opportunities and threats that affect the achievement of objectives.
COSO ERM Framework (2017 Update: “Enterprise Risk Management—Integrating with Strategy and Performance”)
The Committee of Sponsoring Organizations (COSO) framework focuses on the importance of considering risk in both the strategy-setting process and in driving performance. It is structured around five interrelated components:
  • Governance and Culture: Governance sets the organization’s tone, reinforcing the importance of ERM and establishing oversight responsibilities. Culture relates to ethical values, desired behaviors, and understanding of risk in the entity.
  • Strategy and Objective-Setting: ERM, strategy, and objective-setting work together in the strategic-planning process. Risk appetite is established and aligned with strategy; business objectives put strategy into practice while serving as a basis for identifying, assessing, and responding to risk.]
  • Performance: Risks that may impact the achievement of strategy and business objectives need to be identified and assessed. Risks are prioritized by severity in the context of risk appetite. The organization then selects risk responses and takes a portfolio view of the amount of risk it has assumed. 
  • Review and Revision: By reviewing entity performance, an organization can consider how well the ERM components are functioning over time and in light of substantial changes, and what revisions are needed.
  • Information, Communication, and Reporting: ERM requires a continual process of obtaining and sharing necessary information, from both internal and external sources, which flows up, down, and across the organization. 
+---------------------------------------------------------------------------------------+

|                                      COSO ERM                                         |
+---------------------+-----------------------+---------------+------------+------------+

| Governance & Culture| Strategy & Objectives |  Performance  |  Review &  | Info, Comms|
|     (The Tone)      |      (The Plan)       | (Execution)   |  Revision  | & Reporting|
+---------------------+-----------------------+---------------+------------+------------+

ISO 31000:2018 Risk Management Guidelines
ISO 31000 provides principles, a framework, and a process for managing risk. Unlike COSO, it is not specific to internal controls over financial reporting and can be customized to any sector. 
  • Principles: The foundation of risk management. The core purpose is the creation and protection of value. Other principles include being integrated, structured, customized, inclusive, dynamic, utilizing the best available information, and considering human and cultural factors. 
  • Framework: Ensures risk management is integrated into all significant activities. Leadership commitment is the center, surrounded by integration, design, implementation, evaluation, and improvement.
  • Process: The systematic application of management policies, procedures, and practices to the activities of communicating, consulting, establishing the context, and assessing, treating, monitoring, reviewing, recording, and reporting risk.
Â