Global (COSO; entities of every type and size)

COSO Enterprise Risk Management (ERM) Framework (2017)

48 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

48 controls 0 frameworks share controls with it Global (COSO; entities of every type and size) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
GOV-1Exercises Board Risk Oversight0
GOV-2Establishes Operating Structures0
GOV-3Defines Desired Culture0
GOV-4Demonstrates Commitment to Core Values0
GOV-5Attracts, Develops, and Retains Capable Individuals0
INFO-18Leverages Information and Technology0
INFO-19Communicates Risk Information0
INFO-20Reports on Risk, Culture, and Performance0
PERF-10Identifies Risk0
PERF-11Assesses Severity of Risk0
PERF-12Prioritizes Risks0
PERF-13Implements Risk Responses0
PERF-14Develops Portfolio View0
REV-15Assesses Substantial Change0
REV-16Reviews Risk and Performance0
REV-17Pursues Improvement in ERM0
STR-6Analyzes Business Context0
STR-7Defines Risk Appetite0
STR-8Evaluates Alternative Strategies0
STR-9Formulates Business Objectives0
APPLICATIONSCOSO's applications of the framework: compliance risk management (2020) and ESG-related risk (2018)0
COMP-GCGovernance and Culture (Principles 1 to 5)0
COMP-ICInformation, Communication, and Reporting (Principles 18 to 20)0
COMP-PEPerformance (Principles 10 to 14)0
COMP-RRReview and Revision (Principles 15 to 17)0
COMP-SOStrategy and Objective-Setting (Principles 6 to 9)0
FRAMEWORKCOSO ERM 2017: what it is, its structure, and what is held0
P1Principle 1: Exercises Board Risk Oversight0
P10Principle 10: Identifies Risk0
P11Principle 11: Assesses Severity of Risk0
P12Principle 12: Prioritizes Risks0
P13Principle 13: Implements Risk Responses0
P14Principle 14: Develops Portfolio View0
P15Principle 15: Assesses Substantial Change0
P16Principle 16: Reviews Risk and Performance0
P17Principle 17: Pursues Improvement in Enterprise Risk Management0
P18Principle 18: Leverages Information and Technology0
P19Principle 19: Communicates Risk Information0
P2Principle 2: Establishes Operating Structures0
P20Principle 20: Reports on Risk, Culture, and Performance0
P3Principle 3: Defines Desired Culture0
P4Principle 4: Demonstrates Commitment to Core Values0
P5Principle 5: Attracts, Develops, and Retains Capable Individuals0
P6Principle 6: Analyzes Business Context0
P7Principle 7: Defines Risk Appetite0
P8Principle 8: Evaluates Alternative Strategies0
P9Principle 9: Formulates Business Objectives0
SUMMARY-FAQThe executive summary and COSO's September 2017 FAQ0

Tell me when COSO Enterprise Risk Management (ERM) Framework (2017) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • KPI definitions
  • Targets register
  • Improvement log
  • Improvement register
  • Customer feedback
  • Action records

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for COSO Enterprise Risk Management (ERM) Framework (2017), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition