COSO ERM: What It Is and How to Apply It in Practice
Anyone who digs into enterprise risk management quickly runs into two big names: COSO ERM and ISO 31000. COSO ERM comes up especially often in organizations with a dedicated ERM function, a board of directors, or compliance obligations such as CSRD and NIS2. But what exactly does this framework involve? And more importantly, how do you make sure it becomes more than a thick document gathering dust on a shelf?
In this blog, we explain what COSO ERM is, how the framework is structured, how it relates to ISO 31000, and how to translate its principles into a risk management practice that genuinely comes alive in your organization.
What Is COSO ERM?
COSO ERM is a framework for enterprise risk management developed by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). This U.S. organization was founded in 1985 and is best known for its internal control framework, which is used worldwide for purposes such as Sarbanes-Oxley compliance.
COSO published its first ERM framework in 2004. In 2017, a thoroughly revised version appeared under the title "Enterprise Risk Management: Integrating with Strategy and Performance." That subtitle says it all: COSO ERM is not about checking off risks, but about connecting risk management to strategy and performance.
The core idea: risks are not a standalone compliance topic, but belong in every strategic decision an organization makes, from setting direction to day-to-day execution.
How the COSO ERM Framework Is Structured
The 2017 COSO ERM framework consists of five components with a total of twenty underlying principles. The five components are:
1. Governance and Culture
Governance sets the tone at the top: who is responsible for risk management, and how is oversight organized? Culture is about behavior, ethics, and the degree to which employees feel free to raise risks openly.
2. Strategy and Objective-Setting
Risk management starts with strategy. In this component, you define the organization's risk appetite and test whether the chosen strategy aligns with it. Objectives at every level then become the starting point for identifying risks.
3. Performance
This is the heart of the operational risk process: identifying risks, assessing their severity, prioritizing them, and then selecting responses. The result is a portfolio view of risks that helps management steer performance.
4. Review and Revision
Organizations and their environment change constantly. This component focuses on periodically reviewing the risk profile and adjusting the approach when needed.
5. Information, Communication, and Reporting
Risk management stands or falls on good information. This component describes how you gather, share, and report risk information to management, the board, and regulators.
COSO ERM Versus ISO 31000: What Is the Difference?
Alongside COSO ERM, ISO 31000 is the other major international framework for risk management. The two are not mutually exclusive, but they do have a different character:
In practice, we see that many organizations, such as engineering firms, construction companies, and public-sector bodies, work on the basis of ISO 31000, while larger corporates with a formal ERM function more often turn to COSO ERM. A growing number of organizations combine the two: COSO ERM as the governance backbone, and ISO 31000 as the practical guide for the risk process.
Worth knowing: RiskChallenger works with ISO 31000 certified advisors, and the principles of both frameworks combine very well. The building blocks (context, identification, analysis, evaluation, treatment, monitoring, and communication) largely overlap.
The COSO ERM Pitfall: Paper Versus Practice
Here is the honest truth: implementing a framework is not the same as making risk management work. Many organizations that adopt COSO ERM recognize this pattern:
- There is a beautifully written risk policy, based on the twenty principles
- The risk register gets filled in during an annual session
- Reporting to the board consists of a list of scores and colors
- And after that... little happens until the next cycle
The framework itself warns against this too. It is no coincidence that "culture" is part of the very first component and that the fifth component has "communication" right in its name. COSO ERM recognizes that risk management only adds value when it becomes part of the daily dialogue within the organization.
And that is exactly where things often go wrong in practice. Risk management becomes the job of a single risk manager, who maintains a register in Excel or a complex GRC system that the rest of the organization barely looks at. The number in the risk matrix becomes more important than the conversation behind it.
Bringing COSO ERM to Life With Communicative Risk Management
The philosophy of communicative risk management aligns perfectly with what COSO ERM sets out to do: risk management as an organization-wide dialogue rather than an administrative exercise. Here is how you translate the five components into practice:
Culture is built in sessions, not in documents. Risk awareness grows when people participate. Interactive risk sessions in which the whole team thinks along, for example through a brainstorm where participants join via a QR code without needing an account, make risk management inclusive and accessible.
Link risks to what you want to protect. COSO ERM connects risks to strategy and objectives. The same idea sits at the core of the 1-2-3 approach of RiskChallenger Resilience: first determine which interests you want to protect, then look at which risks threaten those interests, and finally choose preventive and mitigating measures.
Assess risks collectively. One person estimating likelihood and impact produces an opinion. A team quantifying together produces a conversation, and that conversation is where the real insights emerge. The broader and more varied the group, the better your risk picture.
Make review continuous rather than annual. Automated deadline tracking and reminders for control measures keep the risk file up to date, without the risk manager having to chase everyone down.
Report visually and at every level. Dashboards that show strategic, tactical, and operational insights make the reporting component of COSO ERM considerably lighter. The board and regulators can see at a glance how the organization is doing.
Who Is COSO ERM Relevant For?
COSO ERM is especially interesting for:
- Corporates and larger organizations that report to a board of directors or a board risk committee
- Organizations with compliance obligations such as Sarbanes-Oxley, CSRD, or NIS2
- Organizations that want to integrate strategic and operational risk management rather than work in separate systems
- CFOs, CROs, and compliance officers looking for a recognized, widely accepted framework to structure their ERM function
Do you work mainly on a project basis, for example in construction, infrastructure, or the public sector? Then ISO 31000 often offers a more practical starting point. But even then, the COSO ERM principles, especially those around governance, culture, and communication, are valuable for testing your approach.
Conclusion: The Framework Is the Beginning, the Dialogue Is the Goal
COSO ERM offers a thoughtful and complete framework for connecting risk management to strategy and performance. But putting the twenty principles on paper is not enough. The framework only works when risks are discussed throughout the organization: from the boardroom to the project teams.
Risk management is about the substantive dialogue, not about the number on the page. Organizations that combine COSO ERM with a communicative, interactive approach get the most out of the framework: not just compliance, but real insight into what threatens the organization and what makes it stronger.
Curious how to bring your ERM framework to life with communicative risk management? Schedule a personal demo or start a free 30-day trial today at www.riskchallenger.nl.
Do you have any questions about this article?
Feel free to contact us via live chat or via
support@riskchallenger.nl






