Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

COSO ERM vs ISO 31000 comparison infographic

COSO ERM vs ISO 31000: The Essential 2026 Guide to Choosing a Risk Framework

COSO ERM vs ISO 31000 is the framework choice that risk managers face when the board asks for an enterprise risk program and someone must decide what to build it on. Both are respected, both are widely used and both can work. They differ in origin, structure and the audience they serve, and those differences decide which one fits.

This guide compares the two side by side: what each contains, how they handle strategy, risk appetite and process, who tends to prefer which, and how to combine them without duplicating work. It is written for risk, finance and compliance leaders. Neither framework is a certification scheme in the way some standards are, so the question is about design, not audit passing. Always read the current official documents before you cite specific language.

Free gap assessment

Is risk management actually changing decisions?

A maturity assessment against all eight principles, the framework and the process, free. Nobody can certify you to ISO 31000, so this scores distance from good practice instead.

Run the free ISO 31000 maturity assessment →  or  View premium report sample

What COSO ERM is

COSO published Enterprise Risk Management: Integrating with Strategy and Performance in 2017, updating its earlier 2004 framework. It organizes ERM around five components: governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. Within those components sit 20 principles, from exercising board oversight to developing a portfolio view of risk.

The defining idea is that risk management is part of setting and delivering strategy, not a separate compliance activity. Our overview of the COSO framework and the detailed page on COSO ERM principles walk through each component.

What ISO 31000 is

ISO 31000 is an international standard that provides guidelines on managing risk. The 2018 edition is short and deliberately generic. It is built on three elements: principles that describe the characteristics of effective risk management, a framework that describes how to integrate it into governance and operations, and a process covering scope and context, assessment, treatment, monitoring, communication and recording.

ISO 31000 provides guidance, so you cannot be certified to it. Organizations use it as the model for their own risk policy and procedures and often reference it in other standards. It applies equally to a hospital, a bank or a municipality, which is part of its appeal.

Structure: COSO ERM vs ISO 31000 side by side

COSO is organized around components and principles and puts a great deal of emphasis on governance, culture, strategy and performance. ISO 31000 is organized around the operational logic of managing risk: set context, assess, treat, monitor. You can see the difference in where each starts. COSO starts with governance and culture, asking who oversees risk and what behaviors the organization rewards. ISO 31000 starts with principles and integration, then describes a repeatable process.

Neither is better in the abstract. COSO gives a richer picture of how risk sits in strategy; ISO 31000 gives a cleaner process you can write procedures around. Many organizations take the structure from one and the process from the other.

AspectCOSO ERM (2017)ISO 31000 (2018)
PublisherCommittee of Sponsoring Organizations of the Treadway CommissionInternational Organization for Standardization
StructureFive components and 20 principlesPrinciples, framework and process
FocusIntegrating risk with strategy and performanceGuidelines for managing risk in any organization
NatureFramework with principlesGuidance standard, not certifiable
AudienceBoards, finance, internal audit, US-listed companiesRisk managers across sectors and countries
Risk appetiteExplicitly embedded in strategy settingAddressed through criteria and framework integration
CompanionInternal Control framework for ICFRSupporting standards in the ISO risk family

How each treats strategy, appetite and performance

COSO links risk directly to strategy. It asks organizations to evaluate alternative strategies, consider risk appetite when choosing one and monitor performance against objectives. See our guide to COSO risk appetite for how appetite is expressed and used.

Free enterprise risk assessment

Which of your business risks sit above your appetite?

Set your criteria and appetite, pick from 36 strategic, financial, operational and compliance scenarios, rate them and decide how to treat each. Built to ISO 31000, and free.

Run the free enterprise risk assessment →  or  View premium report sample

ISO 31000 also expects risk management to be integrated into decision-making and to create and protect value, but it does not prescribe a specific approach to strategy or appetite. It asks you to define risk criteria, which is where appetite and tolerance typically appear. If your board wants explicit appetite statements tied to strategy, COSO gives more ready-made structure.

Which one fits which organization

COSO ERM tends to fit publicly listed companies, financial reporting environments and organizations whose boards and auditors already use COSO for internal control. The same committee published the Internal Control framework used for ICFR; see SOX compliance and entity-level controls for the link.

ISO 31000 tends to fit organizations that want a standard, language-neutral approach, operate across jurisdictions or use other ISO management systems. If your quality, security or continuity standards already reference ISO risk language, ISO 31000 fits naturally.

A third group, which is large, uses both: COSO for board-level ERM and ICFR, and ISO 31000 as the day-to-day process inside departments.

Combining COSO ERM and ISO 31000

Combining them works best when you assign each a clear job. Use COSO components to structure governance, culture, strategy integration and reporting to the board. Use the ISO 31000 process to define how a risk is identified, analyzed, evaluated, treated and reviewed in practice. Map your risk register fields and your procedures to both so nothing is duplicated.

Keep one risk taxonomy and one risk register. Two parallel registers create conflicting numbers and confuse the board. Link the register to objectives, and to controls where they exist. For the control side, see management review controls and fraud risk assessment, which use the same risk thinking applied to reporting and fraud.

Implementation steps for your enterprise risk management framework

A practical rollout looks like this, adapted to your size and starting point:

  • Confirm the board mandate and executive sponsor
  • Choose your reference framework or hybrid and write the risk policy
  • Define risk categories, criteria and appetite statements
  • Build the risk register and assign risk owners
  • Set the assessment and treatment process, with review cadence
  • Design reporting for management and the board
  • Test and improve through periodic review and internal audit

Templates for your risk program

Policies, registers, appetite statements, assessment forms and reporting packs are the working documents of either framework. The COSO ERM and Internal Control Toolkit includes editable templates for enterprise risk management and internal control, so you can adapt a structure instead of inventing one.

For official framework guidance, see the COSO enterprise risk management guidance. Whichever you choose, record your decision and the reasons in the risk policy so successors understand why the program looks the way it does. For the deficiency side of internal control, see material weakness and sustainability reporting controls.

A worked comparison: one risk through both lenses

Take a risk that a manufacturer might record: dependence on a single supplier for a critical component. Through the COSO lens, the discussion starts with strategy and objectives. Does the company intend to grow volume in a market that depends on that component? What risk appetite has the board set for supply disruption? Who has oversight, and how is the risk reported in the portfolio view? The focus is on how the risk affects the achievement of strategic objectives and performance targets.

Through the ISO 31000 lens, the discussion starts with the process. The team establishes the scope and context, identifies the risk, analyzes likelihood and consequence, evaluates it against the criteria, chooses treatment such as a second source or safety stock, and sets a monitoring and review cycle. Used together, the first lens decides how much the risk matters and to whom; the second decides what the team does about it and how it is tracked. The example is illustrative, and every organization will phrase it differently.

Costs and effort in COSO ERM vs ISO 31000 programs

Neither framework carries license or certification fees for the approach itself, apart from buying the documents. The real cost is internal: workshops, risk owner time, tools and reporting. Organizations that adopt COSO often invest more in governance and strategy integration at the start, which can mean board sessions and leadership training. Organizations that adopt ISO 31000 often invest more in procedure writing and register design. Plan for a first cycle of several months, a second cycle to refine and a steady state in which the program runs on a quarterly rhythm. These durations are typical, not guaranteed, and depend on size and starting maturity.

Making the final COSO ERM vs ISO 31000 call

Decide with three questions. Who is the main audience for your risk reporting: the board and external auditors, or operating managers across many sites? Do other management systems you run already use ISO risk language? And does the board want explicit links between risk appetite and strategy? If you answer board, no and yes, lean on COSO. If you answer managers, yes and no, lean on ISO 31000. If the answers are mixed, use the hybrid described above. Whatever you choose, document the decision, review it after the first annual cycle and be willing to adjust. A good COSO ERM vs ISO 31000 decision is one your organization can sustain for years, not the one that looks most impressive on paper.

Why COSO ERM vs ISO 31000 is rarely either-or

Auditors, regulators and boards rarely care which label is on the binder; they care whether risks are identified, owned, treated and reported. That is why the COSO ERM vs ISO 31000 choice matters less than consistency, evidence and follow-through.

Common mistakes in COSO ERM vs ISO 31000 decisions

Organizations sometimes pick a framework for its brand and ignore fit. They write a policy that copies the framework language and never changes behavior. They maintain separate registers for ERM, compliance and operations. They treat ISO 31000 as a certificate to win, or COSO as an accounting exercise owned only by finance. The remedy is to start from the decisions the board needs to make and build the program backward from there.

COSO ERM vs ISO 31000 FAQ

Is ISO 31000 certifiable?

No. ISO 31000 provides guidelines, not requirements, so organizations cannot be certified to it.

Is COSO ERM mandatory?

No. It is a voluntary framework. US-listed companies often use the COSO internal control framework for financial reporting controls, which is a separate document.

Which is easier to implement?

ISO 31000 is shorter and easier to read; COSO is more detailed on governance and strategy. Ease depends on your existing practices.

Can I use both?

Yes. Many organizations use COSO for board-level ERM and ISO 31000 for the process, with one risk register and taxonomy.

How many principles does COSO ERM have?

The 2017 framework has five components and 20 principles.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.