Risk Management

COSO ERM: The 2017 Framework Explained

Standarity Editorial Team·Enterprise risk and GRC practitioners
··6 min read

COSO ERM is the enterprise risk management framework published by the Committee of Sponsoring Organizations of the Treadway Commission. The 2017 edition, titled "Enterprise Risk Management - Integrating with Strategy and Performance," organizes effective risk management into five components and 20 principles that connect risk directly to strategy and value creation.

What COSO ERM 2017 Is

The 2017 framework, developed by PwC under the direction of the COSO board, runs to more than 100 pages and reframes enterprise risk management as a strategic capability rather than a defensive compliance exercise. Its central message is that risk should be considered when an organization sets strategy and pursues performance, not treated as a separate control activity bolted on afterward. The framework positions risk information as an input to better decisions about which opportunities to pursue and how to allocate resources.

This is a meaningful shift from earlier thinking. Where older approaches asked "what could go wrong," COSO ERM 2017 asks how understanding risk helps an organization create, preserve, and realize value. The framework is principles-based, meaning the 20 principles describe outcomes to achieve rather than a rigid checklist to tick off, so organizations apply them in ways appropriate to their size, sector, and complexity.

The Five Components

COSO ERM 2017 is built on five interrelated components. Each contains a group of the 20 principles that together describe what effective enterprise risk management looks like in practice.

  • Governance and Culture - sets the tone, oversight, values, and risk-aware behaviors (principles 1 to 5)
  • Strategy and Objective-Setting - aligns risk appetite with strategy and business objectives (principles 6 to 9)
  • Performance - identifies, assesses, prioritizes, and responds to risks that affect objectives (principles 10 to 14)
  • Review and Revision - evaluates how well ERM is working and improves it over time (principles 15 to 17)
  • Information, Communication, and Reporting - captures and shares risk information across the organization (principles 18 to 20)

According to research published in The Journal of Risk and Insurance, firms that reach mature levels of enterprise risk management have shown up to a 25% market valuation premium - evidence that a well-applied framework like COSO ERM affects more than compliance.

How It Differs From the 2004 Cube

The original 2004 COSO ERM framework used a three-dimensional "cube" that many practitioners found confusing to interpret and apply. It leaned heavily toward internal control, compliance, and financial reporting, reflecting its post-Sarbanes-Oxley origins. The 2017 revision retired the cube entirely and replaced it with the five-component, 20-principle structure, placing far greater emphasis on the relationship between risk and value creation. In short, 2004 was control-centric; 2017 is strategy-centric.

COSO ERM vs ISO 31000

COSO ERM and ISO 31000 are the two leading risk frameworks, and they are complementary rather than competing. COSO ERM is extensive - over 100 pages - and focuses on corporate governance, oversight, and the auditing of risk management activities, which makes it the de facto standard among U.S. boards and audit-oriented professionals. ISO 31000:2018 is compact and standardized, structured around eight principles, a framework, and a process, and it can be applied to any organization or any type of risk. For a deeper look at that standard, see our ISO 31000 guide.

In practice, most large organizations no longer choose one over the other. A common hybrid uses COSO ERM 2017 as the governance and reporting overlay while ISO 31000 supplies the operational risk process. Board-level reporting follows COSO's 20 principles, while risk registers and treatment plans follow the ISO 31000 process steps of scope, identification, analysis, evaluation, and treatment. This combination satisfies both U.S. regulatory expectations and international standards.

How to Apply COSO ERM

Applying the framework starts with governance and culture, because the tone set by the board and executives determines whether ERM becomes embedded or ignored. From there, connect the framework to strategy: define risk appetite, examine how risk could affect the chosen strategy, and consider the risk implications of alternative strategies before they are locked in.

  • Establish board oversight and a clear risk culture before building processes
  • Define risk appetite and tie it explicitly to strategy and objectives
  • Identify and prioritize risks against the objectives they threaten
  • Select responses and integrate them into normal operations, not a separate silo
  • Build reporting that gives decision-makers timely, relevant risk information
  • Review performance regularly and revise the program as conditions change

The goal is integration. When risk information flows into strategy discussions, performance reviews, and resource decisions, COSO ERM stops being a document and becomes a way the organization thinks. Pairing the governance strength of COSO with a disciplined operational process - such as the one described in our ISO 31000 guide - gives organizations both the oversight boards expect and the practical mechanics teams need.

Frequently Asked Questions

What is COSO ERM?

COSO ERM is the enterprise risk management framework from the Committee of Sponsoring Organizations of the Treadway Commission. The 2017 edition integrates risk management with strategy and performance through five components and 20 principles.

What are the five components of COSO ERM 2017?

The five components are Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication, and Reporting. Together they contain the 20 principles that define effective ERM.

How does COSO ERM 2017 differ from the 2004 version?

The 2004 version used a three-dimensional cube focused on internal control and compliance. The 2017 revision retired the cube, adopted a five-component and 20-principle structure, and emphasized the link between risk and value creation.

What is the difference between COSO ERM and ISO 31000?

COSO ERM is an extensive governance and oversight framework favored by U.S. boards, while ISO 31000 is a compact, flexible standard focused on the risk management process. Many organizations use them together, with COSO as governance overlay and ISO 31000 as operational process.

How many principles does COSO ERM 2017 have?

COSO ERM 2017 has 20 principles distributed across its five components. They are principles-based outcomes rather than a prescriptive checklist, so organizations apply them according to their size, industry, and complexity.

Is COSO ERM mandatory?

COSO ERM is a voluntary framework, not a regulation. However, it is the de facto standard for enterprise risk management among U.S. public-company boards and is widely referenced by regulators, auditors, and rating agencies.

Explore Courses on Udemy

Intermediate

ISO 31000: Risk Management Implementation Step by Step

Intermediate

Implement Operational Risk Management Step by Step

Intermediate

CRISC Certification — IT Risk Management with AI Tools