Explainer

COSO ERM vs ISO 31000: which framework should you use?

By the Rukn ERM team · September 2026 · 9 min read

The two dominant risk frameworks are less in competition than the question implies. Here is what actually separates them — and why most organisations end up drawing on both.

If you are building an enterprise risk management programme, you will be pointed at two documents: the COSO ERM framework and ISO 31000. They cover much of the same ground, use different vocabulary for similar ideas, and are frequently presented as a choice. In practice the decision is less consequential than the time spent debating it — but the differences are real, and one of them is commonly misunderstood.

The short answer

Choose COSO ERM 2017 if your organisation is US-listed or operates in a SOX environment, if your auditors already speak COSO, or if you want prescriptive structure to build against. Choose ISO 31000:2018 if you operate internationally, already run other ISO management systems, or prefer a lighter set of principles you adapt yourself. Neither choice will be wrong, and moving between them later is not costly.

Where each came from

COSO ERM comes from the Committee of Sponsoring Organizations of the Treadway Commission — a private-sector initiative of five US accounting and finance bodies. Its centre of gravity is corporate governance, internal control and financial reporting, and it carries the fingerprints of that heritage. The current edition, Enterprise Risk Management — Integrating with Strategy and Performance, was published in 2017 and replaced the 2004 framework.

ISO 31000 is an international standard from the International Organization for Standardization, developed by a technical committee drawn from national standards bodies worldwide. The current edition, ISO 31000:2018, deliberately simplified the 2009 original. Its heritage is engineering and management-systems standardisation rather than financial reporting, and it shows in the tone — more generic, less US-specific, applicable to any organisation of any size.

How they are structured

COSO ERM 2017 organises risk management into five components supported by twenty principles: governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. We cover these in detail in COSO ERM 2017 explained.

ISO 31000:2018 is built from three parts: eight principles describing what good risk management looks like; a framework covering leadership, integration, design, implementation, evaluation and improvement; and a process — communication and consultation, defining scope and context, risk assessment (identification, analysis, evaluation), risk treatment, monitoring and review, and recording and reporting.

The practical difference: COSO tells you more about what to build. ISO tells you more about how to think, and leaves the construction to you. Teams starting from nothing often find COSO's specificity easier to act on; teams with an established programme often find ISO's flexibility less constraining.

The certification question

This is the one that trips people up, and it is worth being unambiguous: you cannot get certified against ISO 31000. Unlike ISO 9001 or ISO 27001, ISO 31000 is guidance, not a requirements standard, and it is explicitly not intended for certification purposes. Any body offering to certify your organisation against it is selling something ISO does not recognise.

COSO ERM is likewise not a certifiable standard. Neither framework produces a certificate you can show a customer. What both produce is a defensible structure — something you can point an auditor, regulator or board at and say: this is the recognised model our programme follows.

If certification is genuinely what you need, you are looking for a different standard. ISO 27001 certifies an information security management system; SOC 2 attests to controls at a service organisation. A risk framework underpins those efforts without being the thing that gets certified.

Vocabulary differences that cause confusion

Much of the apparent gap between the frameworks is terminology. A few worth knowing:

Risk appetite. Both use the term, and both mean roughly the amount of risk an organisation is willing to accept in pursuit of its objectives. ISO 31000 leans more on "risk criteria" — the terms against which significance is evaluated. See risk appetite and risk tolerance.

Risk treatment vs risk response. ISO says treatment, COSO says response. Both describe the same set of choices: avoid, reduce, share, or accept. See risk response.

Definition of risk itself. ISO 31000 defines risk as "the effect of uncertainty on objectives" — notably neutral, admitting upside as readily as downside. COSO frames risk as the possibility that events occur and affect the achievement of strategy and objectives. In day-to-day practice both admit opportunity as well as threat, but ISO's phrasing makes it more explicit.

Side by side

  COSO ERM 2017 ISO 31000:2018
OriginUS private-sector consortiumInternational standards body
Structure5 components, 20 principles8 principles, framework, process
StylePrescriptive, detailedPrinciples-based, adaptable
CertifiableNoNo — explicitly guidance only
CostPaid publicationPaid publication
Strongest fitUS-listed, SOX, audit-heavyInternational, multi-standard

Why most organisations use both

The frameworks are not mutually exclusive, and treating the choice as binary is the actual mistake. A common and entirely defensible pattern: adopt COSO ERM's five components as the structure for your programme — because it maps cleanly onto how a board thinks about oversight — while borrowing ISO 31000's risk process and its neutral definition of risk for day-to-day operational work.

What matters far more than the choice is whether the moving parts exist. A programme with a living risk register, an approved appetite statement, monitored key risk indicators, tested controls, clear ownership and reporting that reaches the board satisfies both frameworks. A programme with a policy document citing either one and nothing underneath satisfies neither.

What to do next

Pick the one your stakeholders already recognise — if your auditors talk in COSO components, use COSO; if your organisation already runs ISO management systems, use ISO. Write down which you have adopted and why. Then stop thinking about frameworks and start building the register, because that is the part that takes the time.

COSO and COSO ERM are trademarks of the Committee of Sponsoring Organizations of the Treadway Commission. ISO and ISO 31000 are trademarks of the International Organization for Standardization. Rukn ERM is an independent product aligned to the COSO ERM 2017 framework and is not affiliated with, sponsored by, or endorsed by COSO or ISO.

Build the programme, not the policy document

Register, appetite, KRIs, controls, incidents and board reporting — structured on COSO ERM 2017, in Arabic and English.

Start free trial Explore the platform