COSO ERM is the enterprise risk management framework published by the Committee of Sponsoring Organizations of the Treadway Commission. The 2017 edition, titled "Enterprise Risk Management - Integrating with Strategy and Performance," organizes effective risk management into five components and 20 principles that connect risk directly to strategy and value creation.
What COSO ERM 2017 Is
The 2017 framework, developed by PwC under the direction of the COSO board, runs to more than 100 pages and reframes enterprise risk management as a strategic capability rather than a defensive compliance exercise. Its central message is that risk should be considered when an organization sets strategy and pursues performance, not treated as a separate control activity bolted on afterward. The framework positions risk information as an input to better decisions about which opportunities to pursue and how to allocate resources.
This is a meaningful shift from earlier thinking. Where older approaches asked "what could go wrong," COSO ERM 2017 asks how understanding risk helps an organization create, preserve, and realize value. The framework is principles-based, meaning the 20 principles describe outcomes to achieve rather than a rigid checklist to tick off, so organizations apply them in ways appropriate to their size, sector, and complexity.
The Five Components
COSO ERM 2017 is built on five interrelated components. Each contains a group of the 20 principles that together describe what effective enterprise risk management looks like in practice.
- Governance and Culture - sets the tone, oversight, values, and risk-aware behaviors (principles 1 to 5)
- Strategy and Objective-Setting - aligns risk appetite with strategy and business objectives (principles 6 to 9)
- Performance - identifies, assesses, prioritizes, and responds to risks that affect objectives (principles 10 to 14)
- Review and Revision - evaluates how well ERM is working and improves it over time (principles 15 to 17)
- Information, Communication, and Reporting - captures and shares risk information across the organization (principles 18 to 20)
According to research published in The Journal of Risk and Insurance, firms that reach mature levels of enterprise risk management have shown up to a 25% market valuation premium - evidence that a well-applied framework like COSO ERM affects more than compliance.
How It Differs From the 2004 Cube
The original 2004 COSO ERM framework used a three-dimensional "cube" that many practitioners found confusing to interpret and apply. It leaned heavily toward internal control, compliance, and financial reporting, reflecting its post-Sarbanes-Oxley origins. The 2017 revision retired the cube entirely and replaced it with the five-component, 20-principle structure, placing far greater emphasis on the relationship between risk and value creation. In short, 2004 was control-centric; 2017 is strategy-centric.
COSO ERM vs ISO 31000
COSO ERM and ISO 31000 are the two leading risk frameworks, and they are complementary rather than competing. COSO ERM is extensive - over 100 pages - and focuses on corporate governance, oversight, and the auditing of risk management activities, which makes it the de facto standard among U.S. boards and audit-oriented professionals. ISO 31000:2018 is compact and standardized, structured around eight principles, a framework, and a process, and it can be applied to any organization or any type of risk. For a deeper look at that standard, see our ISO 31000 guide.
In practice, most large organizations no longer choose one over the other. A common hybrid uses COSO ERM 2017 as the governance and reporting overlay while ISO 31000 supplies the operational risk process. Board-level reporting follows COSO's 20 principles, while risk registers and treatment plans follow the ISO 31000 process steps of scope, identification, analysis, evaluation, and treatment. This combination satisfies both U.S. regulatory expectations and international standards.
How to Apply COSO ERM
Applying the framework starts with governance and culture, because the tone set by the board and executives determines whether ERM becomes embedded or ignored. From there, connect the framework to strategy: define risk appetite, examine how risk could affect the chosen strategy, and consider the risk implications of alternative strategies before they are locked in.
- Establish board oversight and a clear risk culture before building processes
- Define risk appetite and tie it explicitly to strategy and objectives
- Identify and prioritize risks against the objectives they threaten
- Select responses and integrate them into normal operations, not a separate silo
- Build reporting that gives decision-makers timely, relevant risk information
- Review performance regularly and revise the program as conditions change
The goal is integration. When risk information flows into strategy discussions, performance reviews, and resource decisions, COSO ERM stops being a document and becomes a way the organization thinks. Pairing the governance strength of COSO with a disciplined operational process - such as the one described in our ISO 31000 guide - gives organizations both the oversight boards expect and the practical mechanics teams need.