Explainer

The COSO ERM framework (2017), explained

By the Rukn ERM team · Updated September 2026 · 8 min read

The COSO ERM framework is one of the most widely used models for enterprise risk management. This guide explains what it is, what changed in the 2017 edition, what its five components ask of an organization, and how teams put it into practice.

The COSO ERM framework, formally Enterprise Risk Management — Integrating with Strategy and Performance, was published in 2017. It reframed risk management as something woven into strategy and performance rather than a compliance exercise bolted on afterwards. It organizes enterprise risk management into five components and twenty principles. You don't need to memorize the principles, but understanding what each component is for is genuinely useful.

What is the COSO ERM framework?

COSO is the Committee of Sponsoring Organizations of the Treadway Commission, a joint initiative of five professional bodies: the American Accounting Association, the American Institute of CPAs, Financial Executives International, The Institute of Internal Auditors and the Institute of Management Accountants. It was formed in 1985 and publishes guidance on internal control, enterprise risk management and fraud deterrence.

Its ERM framework describes how an organization should manage risk across the whole enterprise rather than department by department. In the 2017 edition, enterprise risk management is not a function or a checklist. It is the combination of culture, capabilities and practices, joined up with strategy-setting and day-to-day performance, that an organization relies on to manage risk while it creates, preserves and realizes value.

That definition matters in practice. It means ERM is judged by whether it improves decisions, not by whether a risk register exists.

From 2004 to 2017: what changed

COSO's first ERM framework, Enterprise Risk Management — Integrated Framework, appeared in 2004. It was built around eight components, from internal environment and objective setting through event identification, risk assessment and risk response to control activities, information and communication, and monitoring. It was usually drawn as a cube that crossed those components with categories of objectives and levels of the organization.

The 2017 update kept the underlying ideas but changed the emphasis in three ways:

The five components and twenty principles

The five components are interrelated rather than sequential. The twenty principles sit beneath them: five under governance and culture, four under strategy and objective-setting, five under performance, three under review and revision, and three under information, communication and reporting. The descriptions below paraphrase what each component asks for.

1. Governance & culture

This is the foundation: who is accountable for risk, and what the organization's risk culture actually is. Its principles cover board oversight of risk, operating structures that make accountability clear, the culture the organization wants, commitment to its core values, and attracting and developing capable people. A brilliant framework fails if the culture ignores it, which is why COSO puts culture first. Models such as the three lines model are commonly used to make these responsibilities concrete.

2. Strategy & objective-setting

Risk only means something relative to objectives. This component connects risk management to strategy: understanding the business context, defining risk appetite, evaluating alternative strategies in light of the risk they carry, and setting business objectives that are consistent with that appetite. It is the component most often skipped, and the one that separates real ERM from a risk register kept in isolation.

3. Performance

This is the operational heart most people picture when they think of risk management. Its principles cover identifying risks to objectives, assessing how severe they are, prioritizing them, choosing a response, and building a portfolio view of risk across the whole organization. The 2017 framework describes responses as accepting, avoiding, pursuing, reducing or sharing a risk. It is where your risk register, your assessment of likelihood and impact, and your heat map live.

4. Review & revision

Risk is not static, so a program can't be either. This component asks the organization to notice substantial change in its environment, review how risk and performance are actually tracking, and keep improving its ERM practices. In day-to-day terms, that means monitoring key risk indicators, testing control effectiveness, and revising the program as the business and its risks change. It is the discipline that keeps a register from going stale.

5. Information, communication & reporting

Finally, risk information has to flow: up to the board, across the business, and out to stakeholders. The principles here cover using information and technology to support ERM, communicating risk information, and reporting on risk, culture and performance at every level. Board-ready reporting isn't an afterthought. It is a named component of the framework.

How risk, strategy and performance fit together

The central idea of the 2017 framework is that risk and performance are two views of the same thing. COSO describes risk to strategy in three ways:

The framework also introduces the idea of a risk profile: how the amount of risk an organization carries changes as it targets higher or lower performance. The practical takeaway is that appetite should be set alongside objectives, and that a risk rising above appetite is a performance signal, not just a compliance one.

COSO ERM vs COSO Internal Control

A common point of confusion: COSO publishes two frameworks. The Internal Control — Integrated Framework, first published in 1992 and updated in 2013, is about control. Its five components are the ones many finance teams know from Sarbanes-Oxley work. The 2017 ERM framework is broader: it is about managing risk to strategy and performance across the enterprise, and it treats internal control as one part of that picture. The two are complementary, not competing.

A separate question is how COSO ERM compares with ISO 31000, the other widely used risk management standard. We cover that in COSO ERM vs ISO 31000: which framework should you use?

A framework, not a procedure

COSO ERM describes what good enterprise risk management achieves. It does not prescribe forms, scoring scales or software. Two consequences follow:

Where everyday risk practices fit

Most of what a risk team already does maps onto the five components. Seeing the mapping makes gaps obvious:

PracticeMain componentWhat it contributes
Risk committee, roles and risk ownersGovernance & cultureAccountability for each risk and for the program
Risk appetite and toleranceStrategy & objective-settingThe boundary objectives and risks are judged against
Risk identification and the risk registerPerformanceA single record of risks to objectives
Risk assessment: likelihood, impact, inherent and residual riskPerformanceConsistent severity and prioritization
Controls and treatment actionsPerformanceThe response to each prioritized risk
Key risk indicators and control testingReview & revisionEvidence that risks and responses are behaving as expected
Dashboards and board reportingInformation, communication & reportingRisk information reaching the people who decide

For the mechanics of the performance component, see how to build a risk register and inherent vs residual risk. For monitoring, see how to choose KRIs that actually work.

Applying the principles: a practical sequence

You don't adopt COSO ERM by writing a policy that cites it. You adopt it by building the moving parts, roughly in this order:

  1. Set up governance. Agree who oversees risk, name a risk owner for each area, and decide how often the program is reviewed.
  2. Anchor risk to objectives. List the objectives that matter most and draft an appetite statement for each risk category.
  3. Build the register. Identify risks to those objectives, describe each one clearly, and assess it on a consistent scale.
  4. Record controls and responses. Link existing controls to the risks they address, judge how effective they are, and assign actions where residual risk is above appetite.
  5. Monitor. Choose a small set of key risk indicators with thresholds, and test key controls on a schedule.
  6. Report and revise. Report risk against appetite to the people who decide, and revisit the register when the business changes.

None of these steps requires a particular tool. A small program can run in spreadsheets, and our free risk register template follows this structure.

Putting the principles into practice

As a program grows, keeping those moving parts connected becomes the hard part: a control re-test should change residual risk, a breached indicator should reach its owner, and a board report should reflect this week's register rather than last quarter's spreadsheet. Many organizations use risk management platforms to structure their risk registers, assessments, controls, KRIs and monitoring in a way that is aligned with their chosen framework.

Rukn ERM is one such platform: enterprise risk management software aligned with the COSO Enterprise Risk Management framework (2017). Its modules correspond to the activities in the table above. There is a risk register, risk assessment with control-driven residual scoring, key risk indicators with threshold alerts, appetite per risk category, committee and policy records, and board reporting, in English and Arabic.

Related reading

COSO and COSO ERM are trademarks of the Committee of Sponsoring Organizations of the Treadway Commission. Rukn ERM is an independent product aligned with the COSO Enterprise Risk Management framework (2017) and is not affiliated with, sponsored by, or endorsed by COSO.