Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

COSO ERM principles explained

COSO ERM Principles: All 20 Explained in 5 Components (2026)

The COSO ERM principles are the twenty statements that make up Enterprise Risk Management — Integrating with Strategy and Performance, the 2017 framework that replaced COSO’s 2004 cube, and they are organised into five components that follow the life of a strategy rather than the structure of a control system: governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. That ordering is the framework’s argument.

Risk is not a function that sits beside strategy and reports on it; it is considered when the strategy is chosen, embedded in the objectives that put it into practice, managed in the performance that delivers it, and reviewed as the entity and its environment change. This guide sets out the five components and the twenty COSO ERM principles as COSO writes them, explains what each principle asks an organisation to be able to show, how the framework relates to the 2013 internal control framework and its 17 principles, and how to run a gap assessment against the twenty without turning a strategy framework into a compliance checklist.

COSO ERM principles: five components, twenty principles
Governance & Culture (1–5) · Strategy & Objective-Setting (6–9) · Performance (10–14) · Review & Revision (15–17) · Information, Communication & Reporting (18–20).

The five components of COSO ERM

Component COSO’s description (Executive Summary, June 2017) Principles
Governance and Culture Governance sets the organization’s tone, reinforcing the importance of, and establishing oversight responsibilities for, enterprise risk management. Culture pertains to ethical values, desired behaviors, and understanding of risk in the entity 1–5
Strategy and Objective-Setting Enterprise risk management, strategy, and objective-setting work together in the strategic-planning process. A risk appetite is established and aligned with strategy; business objectives put strategy into practice while serving as a basis for identifying, assessing, and responding to risk 6–9
Performance Risks that may impact the achievement of strategy and business objectives need to be identified and assessed. Risks are prioritized by severity in the context of risk appetite. The organization then selects risk responses and takes a portfolio view of the amount of risk it has assumed 10–14
Review and Revision By reviewing entity performance, an organization can consider how well the enterprise risk management components are functioning over time and in light of substantial changes, and what revisions are needed 15–17
Information, Communication, and Reporting Enterprise risk management requires a continual process of obtaining and sharing necessary information, from both internal and external sources, which flows up, down, and across the organization 18–20

The twenty COSO ERM principles

# Principle What it asks you to be able to show
1 Exercises board risk oversight A board (or equivalent) with the skills, independence and information to oversee strategy and the risk it carries
2 Establishes operating structures Structures, reporting lines and authorities through which risk is managed — not a risk function alone
3 Defines desired culture An articulated position on risk-taking behaviour, from risk-averse to risk-aggressive, and the behaviours expected
4 Demonstrates commitment to core values Tone from the top consistent with the stated values; consequences when behaviour departs from them
5 Attracts, develops, and retains capable individuals Competence for the strategy, including risk competence, and succession
6 Analyzes business context The internal and external environment — and how it is changing — understood before strategy is set
7 Defines risk appetite A risk appetite statement, set with strategy, that the organisation can actually use to accept or decline risk
8 Evaluates alternative strategies The strategic options considered with their risk profiles, and the implications for the entity’s risk profile of the one chosen
9 Formulates business objectives Objectives that put the strategy into practice, with the tolerance for variation in performance around each
10 Identifies risk Risks to strategy and objectives identified — new, emerging and changing — at every level
11 Assesses severity of risk Severity assessed (likelihood, impact, and the framework’s other dimensions) at the level of the objective the risk affects
12 Prioritizes risks Risks prioritised for response using agreed criteria, in the context of appetite
13 Implements risk responses Responses — accept, avoid, pursue, reduce, share — selected and implemented
14 Develops portfolio view The aggregate risk the entity has assumed, seen as a whole against appetite
15 Assesses substantial change Internal and external changes that could substantially affect strategy and objectives identified and assessed
16 Reviews risk and performance Performance results reviewed against risk taken, and the risk practices reviewed for effectiveness
17 Pursues improvement in enterprise risk management Improvements to the risk practices themselves pursued and implemented
18 Leverages information and technology Information systems that support risk management, at the level the strategy needs
19 Communicates risk information Risk information communicated up, down and across, and with external stakeholders
20 Reports on risk, culture, and performance Reporting on all three to the board and stakeholders, at the level needed to make decisions

COSO ERM principles and the 17 internal control principles

COSO maintains two frameworks. The Internal Control — Integrated Framework (2013) has five components and 17 principles and is the suitable framework almost every US public company uses for its SOX 404 assessment of internal control over financial reporting. The ERM framework has five different components and 20 principles and is not a control framework at all: it starts with strategy and asks how risk shapes it.

The 2017 revision made the boundary explicit — ERM does not replace internal control, and where the two overlap (control environment and culture, risk assessment, information and communication, monitoring) the ERM framework points to the internal control framework rather than repeating it. In practice the internal control principles are assessed for effectiveness by auditors; the ERM principles are assessed by the board and management for how well strategy and risk are integrated. Our guide to the COSO 17 principles covers the control side; the COSO framework guide covers how the two fit.

Internal Control — Integrated Framework (2013) ERM — Integrating with Strategy and Performance (2017)
Question Is there reasonable assurance that objectives — operations, reporting, compliance — will be achieved? How does risk inform strategy, objectives and performance?
Components Control environment; risk assessment; control activities; information and communication; monitoring activities Governance and culture; strategy and objective-setting; performance; review and revision; information, communication and reporting
Principles 17 20
Points of focus Yes — characteristics of each principle No — the framework uses discussion and the separate Compendium of Examples
Who assesses Management and external auditors (SOX 404, PCAOB AS 2201) Board and management; no external attestation regime
Effectiveness test All 17 principles present and functioning, components operating together Judgement about integration with strategy; no pass/fail

Assessing your organisation against the COSO ERM principles

  1. Start at principles 6 to 9, not 10. Most gap assessments begin with the risk register (principle 10) and never reach the strategy. If the business context, appetite, strategic alternatives and objectives were not analysed with risk in mind, the register is managing risks to a strategy chosen without it.
  2. Write the risk appetite before rating anything. Principle 7 is the reference point for 11, 12 and 14; severity and priority mean nothing without it. Our guide to risk appetite covers how to write one that operates.
  3. Assess severity at the level of the objective. The framework’s point is that the same risk has a different severity for different objectives; a single enterprise-wide rating hides that.
  4. Build the portfolio view once a year. Principle 14 is the one most organisations never produce: the aggregate of what has been accepted, avoided, reduced and shared, compared with appetite.
  5. Treat 15 to 17 as the audit of ERM itself. Substantial change assessed, performance reviewed against risk taken, improvements to the practices pursued — with evidence.
  6. Report on culture, not only on risk. Principle 20 names three things; boards that receive only a heat map are not receiving what the framework asks for.

Our guide to ISO 31000 covers the other risk framework organisations map to; the two are compatible, with ISO 31000 supplying process and COSO ERM supplying the strategy linkage and the board’s role.

Frequently asked questions

How many COSO ERM principles are there?
Twenty, organised into five components: governance and culture (5), strategy and objective-setting (4), performance (5), review and revision (3), and information, communication and reporting (3). They are set out in COSO’s 2017 framework, Enterprise Risk Management — Integrating with Strategy and Performance.

What is the difference between the COSO ERM principles and the 17 principles?
The 17 principles belong to the 2013 Internal Control — Integrated Framework, used for SOX 404 assessments of internal control over financial reporting. The 20 ERM principles belong to the 2017 ERM framework, which addresses how risk is considered in setting strategy, objectives and performance. They are separate frameworks that overlap in culture, risk assessment, information and monitoring.

Did the 2017 framework replace the 2004 COSO ERM cube?
Yes. The 2004 Enterprise Risk Management — Integrated Framework, with its eight-component cube, was superseded by the 2017 framework, which reorganised ERM around five components and twenty principles and emphasised integration with strategy and performance.

Is COSO ERM certifiable or audited?
No. There is no attestation regime for the ERM framework; boards and management assess how well the principles are integrated. COSO offers an ERM certificate programme for individuals, not for organisations.

Which principle do organisations most often miss?
Principle 14, the portfolio view — the aggregate of risk assumed across the entity compared with appetite — followed by principle 7, a risk appetite that is actually used to make decisions rather than a statement in the annual report.

Where this leaves you

Use the twenty COSO ERM principles in their own order: governance and culture first, then the strategy and objectives the risk is being managed for, then identification, severity, priority, response and the portfolio view, then the review of the practices themselves and the reporting on risk, culture and performance. A register that starts at principle 10 is a control tool; the framework is asking for something that starts at the board table.

References

More on COSO

The ERM policy and framework document, the risk appetite statement template, the risk register and portfolio view workbook, the board risk reporting pack and the 20-principle gap assessment are in the COSO ERM & Internal Control Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.