COSO Enterprise Risk Management Framework 2017
The COSO Enterprise Risk Management Framework 2017 is a globally recognized model for integrated risk management that helps organizations identify, analyze, and manage risks in relation to strategic objectives. The framework comprises five components (governance and culture, strategy, performance, review, reporting) and twenty principles, emphasizing that effective risk management is a strategic, performance-oriented discipline rather than a compliance exercise.
Source: COSO ERM 2017
COSO ERM 2017, formally the COSO Enterprise Risk Management Framework 2017, is a globally recognized model for integrated risk management that helps organizations identify, analyze, and manage risks in direct relation to their strategic objectives. The framework comprises five components (governance and culture, strategy and objective-setting, performance, review and revision, and information, communication, and reporting) and twenty underlying principles. Its core message is that effective risk management is a strategic, performance-oriented discipline rather than a standalone compliance exercise.
For the board, the supervisory board, and the audit committee, COSO ERM 2017 matters because it explicitly links risk to strategy and value creation. The framework offers a common language with which the board can substantiate which risks are deliberately taken and which are controlled. This supports the oversight role of the supervisory board and the audit committee, who want to see that risk management aligns with the chosen course rather than being addressed only after the fact.
In practice, COSO ERM 2017 is applied by translating the twenty principles into the organization's own governance, processes, and steering information. It starts with governance and culture (the foundation for risk behavior), proceeds through linking risk to strategy and performance, and concludes with review and structured reporting. Unlike the older COSO cube model from 2004, the 2017 version places stronger emphasis on decision-making, performance, and the role of culture. Many organizations use it alongside the COSO Internal Control framework for financial control.
At ONE Risk Advisory, we use COSO ERM 2017 when designing and assessing control frameworks that fit the organization. It is the most widely used framework for enterprise risk management (ERM) and explicitly links risk management to strategy and value creation. We help organizations not only to control risks but also to weigh them when setting their course.
Last updated:
Related service Governance & Control Design
Frequently asked questions
What is the difference between COSO ERM 2017 and COSO Internal Control?
COSO ERM 2017 focuses on enterprise risk management in relation to strategy and value creation; COSO Internal Control focuses on controlling processes, reporting, and compliance. Many organizations use both together, with ERM covering the strategic level and Internal Control covering process control.
Is COSO ERM 2017 a certifiable standard?
No. COSO ERM 2017 is a framework, not a certifiable standard like an ISO norm. Organizations tailor it to their own context and cannot obtain a formal certificate for it; its value lies in the structured approach and the common language.
Why is the 2017 version different from the old COSO cube?
The 2017 version shifts emphasis from a control cube to the link between risk, strategy, and performance. Culture and decision-making take a more prominent place, so that risk management is meant to protect and create value rather than merely tick off risks.