Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 31000 vs COSO ERM explained

ISO 31000 vs COSO ERM: 5 Clear Differences Explained (2026)

ISO 31000 vs COSO ERM is a comparison between the two documents most organisations cite when they say they have a risk management framework — and they are different kinds of document, written for different readers, that can be used together. ISO 31000:2018, Risk management — Guidelines, is a sixteen-page international standard: eight principles, a framework of six components built around leadership and commitment, and a seven-step process from communication and consultation to recording and reporting; it applies to any organisation and any risk, uses “should” throughout, and cannot be certified against.

COSO’s Enterprise Risk Management — Integrating with Strategy and Performance (2017) is a much longer framework from the Committee of Sponsoring Organizations of the Treadway Commission: five components and twenty principles that follow the life of a strategy, written for boards and executives of entities that already use COSO’s internal control framework, and aimed at how risk shapes strategy and performance rather than at how risk is assessed. This guide sets the two side by side on five differences, maps the components of each to the other, explains which to adopt first for four common situations, and describes how organisations run one programme that answers both.

ISO 31000 vs COSO ERM: guidelines vs enterprise framework
ISO 31000:2018 — 8 principles, framework (leadership and commitment; integration, design, implementation, evaluation, improvement), 7-step process; any organisation, any risk; not certifiable · COSO ERM 2017 — 5 components, 20 principles; governance and culture → strategy and objective-setting → performance → review and revision → information, communication and reporting; boards and executives; US-rooted.

ISO 31000 vs COSO ERM: what each one is

ISO 31000:2018 is the second edition of the standard, developed by ISO/TC 262, published in February 2018 and confirmed in 2023. Clause 4 states eight principles — integrated, structured and comprehensive, customised, inclusive, dynamic, best available information, human and cultural factors, continual improvement — around the purpose of creating and protecting value. Clause 5 describes the framework: leadership and commitment at the centre, with integration, design, implementation, evaluation and improvement around it. Clause 6 describes the process: communication and consultation; scope, context and criteria; risk assessment (identification, analysis, evaluation); risk treatment; monitoring and review; recording and reporting. Its vocabulary is ISO 31073, and its techniques are in IEC 31010:2019. Our guide to ISO 31000 covers the three components.

COSO ERM 2017 replaced the 2004 cube. Its five components — governance and culture; strategy and objective-setting; performance; review and revision; information, communication and reporting — carry twenty principles, from “exercises board risk oversight” (1) to “reports on risk, culture, and performance” (20). It is written for organisations that set strategy and manage performance against it, and it treats risk as a consideration in choosing strategy and objectives, not only in delivering them. It sits alongside COSO’s 2013 internal control framework, with its 17 principles, which is the framework SOX section 404 assessments are built on. Our guide to the COSO ERM principles lists all twenty.

ISO 31000 vs COSO ERM: the five differences

Difference ISO 31000:2018 COSO ERM 2017
1. Purpose and audience Guidelines for managing any risk in any organisation; written for anyone who manages risk, at any level A framework for how enterprise risk management integrates with strategy and performance; written for boards, executives and the functions that serve them
2. Structure Principles, framework and process — a description of what risk management is and how it is done Components and principles — a description of what an organisation with effective ERM demonstrates
3. Treatment of the risk process Explicit: a seven-step process with defined activities for identification, analysis, evaluation and treatment, and a companion standard of techniques Implicit: performance principles 10–14 (identifies risk, assesses severity, prioritises, implements responses, develops portfolio view) describe outcomes rather than method
4. Relationship to strategy Risk management integrated into decision-making and objectives; strategy is one context among others Central: strategy and objective-setting is a component; risk is considered in choosing strategy, not only in executing it
5. Origin and reach International, sector-neutral, adopted by national standards bodies worldwide; referenced by other ISO management system standards US-rooted, rooted in financial reporting and internal control; strongest in listed companies, financial services and organisations already using COSO 2013

1. Purpose and audience

ISO 31000 tells a risk manager, a project manager or a plant manager how to manage the risks in front of them. COSO ERM tells a board and an executive team how the organisation’s approach to risk should shape and be shaped by its strategy. A safety engineer can use ISO 31000 without a board; a board can use COSO ERM without a safety engineer.

2 and 3. Structure and the process

The visible ISO 31000 vs COSO ERM difference is that ISO 31000 has a process and COSO ERM has principles. Clause 6 of ISO 31000 says what to do and in what order, and IEC 31010 says how; COSO’s performance component says what an organisation with effective ERM does — identifies risk, assesses severity, prioritises, responds, takes a portfolio view — and leaves the method to the organisation. Organisations that adopt COSO ERM and need a method usually borrow ISO 31000’s process, which is why the two are so often found together.

4. Strategy

COSO’s argument is that risk belongs in the choice of strategy: an entity considers risk appetite when setting strategy, evaluates alternative strategies for their risk, and sets business objectives that reflect both. ISO 31000 agrees that risk management is part of decision-making, but its framework is organised around leadership, integration and the process rather than around the strategic planning cycle. For a board, COSO’s framing is the more natural; for the people who run the assessments, ISO 31000’s is.

5. Origin

ISO 31000 is what a regulator or a management-system auditor outside the United States expects to see referenced; COSO is what an audit committee and an external auditor in a listed company expect. Neither is certifiable; both are cited in policies far more often than they are implemented.

ISO 31000 vs COSO ERM element by element

ISO 31000:2018 element COSO ERM 2017 counterpart Note
Principles (clause 4): integrated, structured, customised, inclusive, dynamic, best information, human factors, improvement Governance and culture principles 1–5; the framework’s overall stance COSO’s culture principles (3–5) go further into values and behaviour
Framework — leadership and commitment (5.2) Principle 1 exercises board risk oversight; 2 establishes operating structures; 4 demonstrates commitment to core values Both put accountability at the top
Framework — integration (5.3) Principles 6–9: analyses business context, defines risk appetite, evaluates alternative strategies, formulates business objectives COSO’s strategy component is where ISO’s integration is most demanding
Framework — design, implementation, evaluation, improvement (5.4–5.7) Principles 15–17 review and revision: assesses substantial change, reviews risk and performance, pursues improvement ISO’s framework cycle; COSO’s review component
Process — communication and consultation (6.2) Principles 18–20: leverages information systems, communicates risk information, reports on risk, culture and performance COSO adds explicit reporting on culture
Process — scope, context and criteria (6.3) Principle 6 analyses business context; 7 defines risk appetite ISO’s risk criteria and COSO’s risk appetite overlap; our guide to risk appetite covers the terms
Process — risk assessment and treatment (6.4–6.5) Principles 10–14: identifies risk, assesses severity, prioritises risks, implements risk responses, develops portfolio view ISO supplies the method; COSO adds the portfolio view
Process — monitoring, review, recording, reporting (6.6–6.7) Principles 15–20 Both require it; COSO ties it to performance

The gaps run both ways. COSO has no equivalent of ISO’s explicit process steps or of IEC 31010’s techniques; ISO has no equivalent of COSO’s strategy component, portfolio view or culture reporting.

ISO 31000 vs COSO ERM: which to adopt first

Situation Start with Then
Building risk management from nothing, any sector ISO 31000 process and framework, with IEC 31010 techniques COSO ERM’s strategy and portfolio principles when the board asks how risk informs strategy
US-listed company with SOX 404 on COSO 2013 COSO ERM, which the audit committee and auditors already speak ISO 31000 as the method beneath the performance principles
Certified to an ISO management system (9001, 27001, 45001) ISO 31000 — the risk clauses of those standards are written in its language COSO ERM only if the board wants a strategy-level framework
Financial services under a regulator that expects enterprise risk management Both: COSO ERM for the governance and appetite architecture, ISO 31000 for the assessment process One risk taxonomy, one register, two reporting views

Running one programme that answers both

  1. Use ISO 31000’s process as the engine. Scope, context and criteria; identification, analysis and evaluation; treatment; monitoring; recording and reporting — with techniques from IEC 31010. This is the part COSO leaves open.
  2. Use COSO ERM’s components as the governance architecture. Board oversight, operating structures, culture, risk appetite tied to strategy, alternative-strategy evaluation, the portfolio view and reporting on culture and performance.
  3. Write one risk management policy that cites both. Our guide to the risk management policy covers the sections; the policy states the principles (ISO) and the components (COSO) and the process (ISO) once.
  4. Set risk criteria and risk appetite as one decision. ISO 31000 6.3 criteria and COSO principle 7 appetite are two views of the same thresholds; our guides to risk criteria and risk appetite cover the terms.
  5. Report in COSO’s shape, evidence in ISO’s. The board pack follows the five components; the register, the assessments and the treatment records follow the seven steps.

Frequently asked questions

What is the difference between ISO 31000 and COSO ERM?
ISO 31000:2018 is a sixteen-page international guideline — eight principles, a framework and a seven-step process — for managing any risk in any organisation. COSO ERM 2017 is a framework of five components and twenty principles describing how enterprise risk management integrates with strategy and performance, written for boards and executives. ISO supplies the method; COSO supplies the strategy-level architecture.

Can you be certified to either?
No. ISO 31000 is a guidelines standard using ‘should’ and cannot be certified against; COSO ERM has no certification scheme. Both are frameworks to align with, not standards to comply with.

Do they conflict?
No. Their elements map to each other closely — ISO’s leadership, integration and process to COSO’s governance, strategy, performance and reporting components — and most organisations that use COSO ERM borrow ISO 31000’s process for assessment.

Which is better for a non-US organisation?
ISO 31000 is the international reference and the language of the ISO management system standards; COSO ERM is most useful where a board or regulator expects enterprise-level strategy integration, or where COSO 2013 internal control is already in use.

Where do techniques like bow-tie and FMEA come from?
IEC 31010:2019, the companion to ISO 31000; COSO ERM does not prescribe techniques.

Where this leaves you

Settle ISO 31000 vs COSO ERM by role rather than by choice: ISO 31000 is the process and the principles every assessment runs on, COSO ERM is the architecture a board uses to tie risk to strategy, and one programme can carry both — one policy, one set of criteria and appetite, ISO’s seven steps as the engine and COSO’s five components as the reporting shape.

References

More on ISO 31000

The risk management policy and framework document, the risk criteria and appetite statement, the risk assessment procedure on the ISO 31000 process and the board reporting templates are in the ISO 31000 Risk Management Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.