Strategic Business Leader · Managing, monitoring and mitigating risk
Risk Management Frameworks and Standards: COSO ERM and ISO 31000
Updated 11 October 2026 · Fact-checked
A risk management framework is a structured set of principles and components that an organisation uses to identify, assess, respond to and monitor risk. COSO ERM and ISO 31000 are the two main ones. To answer a question, name the framework, match its parts to the scenario, and recommend specific improvements.
Understand Frameworks and Standards for Risk Management
A risk management framework is a blueprint. It tells a board what a good risk system looks like, so risk is handled in a consistent way across the whole organisation rather than in scattered, ad hoc pockets. In SBL you are rarely asked to recite a framework. You are asked to judge whether a company's risk system is sound and to advise the board.
COSO ERM is the enterprise risk management framework from the Committee of Sponsoring Organizations of the Treadway Commission. The 2017 version is titled Enterprise Risk Management: Integrating with Strategy and Performance. It links risk to strategy and performance. It is organised into five components: governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. Each component has supporting principles. The key idea is that risk is considered when strategy is chosen, not only when it is delivered.
ISO 31000 is an international standard giving guidelines on risk management. It is built around three linked elements: principles (why risk management exists and what makes it effective), a framework (leadership, integration, design, implementation, evaluation and improvement) and a process (communication and consultation, scope, context and criteria; risk assessment covering identification, analysis and evaluation; risk treatment; monitoring and review; recording and reporting). ISO 31000 is a set of guidelines, not a certification standard. It is designed to fit any organisation, of any size or sector.
The two are more alike than different. Both are principles-based, both need board-level leadership, both stress culture, integration with decision-making and continuous improvement. The usual contrasts: COSO ERM is tied closely to strategy, performance and governance and grew from the internal control tradition, while ISO 31000 is a generic, process-focused standard that is not tied to one sector. Do not claim one is always better. The right choice depends on the organisation.
The third source in your syllabus is UK Corporate Governance Code guidance on risk. The Code requires the board to be responsible for determining the nature and extent of the principal risks it is willing to take, and to maintain sound risk management and internal control systems. The board should review their effectiveness at least annually and report on it. The related guidance on risk management, internal control and related financial and business reporting supports this. It is not a framework like COSO or ISO. It sets out the board's duties, and COSO or ISO can be used to meet them.
Key rules to remember
- COSO ERM (2017) components
- Governance and culture → Strategy and objective-setting → Performance → Review and revision → Information, communication and reporting
- Five components. Use them as a checklist to assess a company's risk system.
- ISO 31000 structure
- Principles + Framework + Process
- The process runs: communication and consultation; scope, context and criteria; risk assessment (identify, analyse, evaluate); risk treatment; monitoring and review; recording and reporting.
- UK Corporate Governance Code board duty on risk
- Board determines the nature and extent of principal risks it will take, maintains sound risk and control systems, and reviews their effectiveness at least annually
- State this as a board responsibility. It is a duty, not a framework.
- Core contrast
- COSO ERM = strategy and performance focus; ISO 31000 = generic principles, framework and process
- Both are principles-based and flexible. Neither is a legal requirement by itself.
How to solve Frameworks and Standards for Risk Management questions
Use this method for any SBL question on risk frameworks, whether you must explain one, compare two, or assess a company's risk system.
- 1Read the requirement. Decide if you must describe, compare, evaluate or recommend. The verb sets the depth.
- 2Pick the framework that fits. Use COSO ERM when the case stresses strategy, governance and culture. Use ISO 31000 when it stresses a clear risk process. Name the Code if the company is listed or under a governance regime.
- 3List the relevant parts of the framework in a few words each. Do not describe everything, only what the scenario touches.
- 4Apply each part to the case facts. Say what the company does, and where it falls short, using names, numbers and events from the scenario.
- 5Link gaps to consequences. Explain how the weakness could harm strategy, reputation, compliance or shareholder value.
- 6Recommend specific actions. Examples: a board risk committee, a risk register, named risk owners, regular reporting, a defined risk appetite.
- 7Add a balanced point on limits. Frameworks cost time and money, can become box-ticking, and do not remove risk.
- 8Close with a clear conclusion that answers the requirement and shows commercial awareness.
Quickest way: Framework, gap, fix in three passes
When to use it: When time is short and you need a structured answer in a few minutes.
- Name the framework and give its structure in one line, for example the five COSO components.
- Scan the scenario and tag each fact to a component or process stage. Mark each as present, weak or missing.
- Write one sentence per gap: what is missing, why it matters here, what to do.
- Finish with one line on board responsibility and monitoring.
Common mistakes in Frameworks and Standards for Risk Management
Reciting the framework from memory without linking it to the case.
Students feel safe writing learned content and run out of time to apply it.
Fix: Spend at least half of the answer on scenario facts. Every framework point should be followed by a case reference.
Mixing up COSO ERM with the COSO internal control framework.
Both come from COSO and appear in the same chapter.
Fix: Remember COSO ERM covers enterprise-wide risk linked to strategy. The internal control framework covers controls. Say which one you mean.
Treating the UK Corporate Governance Code as a risk framework like ISO 31000.
It appears in the same list of sources.
Fix: Describe it as a statement of board duties on risk and control. Say that a company can use COSO or ISO to meet those duties.
Claiming one framework is better and ignoring context.
Students want a firm answer.
Fix: Compare on fit: size, sector, listing status, strategy focus. Then give a justified recommendation.
Listing generic recommendations such as 'improve risk management'.
Students run out of ideas under time pressure.
Fix: Give precise actions: who does what, how often, and how it is reported to the board.
Presenting the framework as a guarantee against loss.
Students overstate benefits.
Fix: State that frameworks give reasonable assurance only, and that judgement, culture and cost still matter.
Worked examples
Example 1
Zenith Foods, a listed food manufacturer, has no board-level discussion of risk. Each department keeps its own risk list and nothing is reported upwards. A product recall has damaged its reputation. The chair asks you to explain how COSO ERM would help. Write a short answer.
Show the solution
- Identify the framework: COSO ERM (2017) has five components. Name them briefly.
- Governance and culture: there is no board oversight and no shared risk culture. The board should set risk responsibilities and tone.
- Strategy and objective-setting: risk is not linked to strategy. Zenith should define its risk appetite and consider risk when choosing products and suppliers.
- Performance: departmental lists are not combined. Zenith needs one enterprise-wide register that ranks risks by likelihood and impact, and responses such as stricter supplier checks.
- Review and revision: the recall shows no learning. A post-incident review should update the register.
- Information, communication and reporting: nothing goes to the board. Regular risk reports should reach the board and audit or risk committee.
- Balance: the framework takes time and cost to embed and can become box-ticking, so management should keep it proportionate.
Answer: COSO ERM would give Zenith a structure to replace its fragmented approach: board oversight and culture, risk-aware strategy with a stated appetite, an enterprise-wide ranked register, learning from incidents like the recall, and regular reporting to the board. It supports reasonable assurance, not a guarantee, and should be applied proportionately.
Example 2
Harbor Logistics, a mid-sized private company, is choosing between COSO ERM and ISO 31000. Its finance director says they are 'basically the same'. Advise the board on the similarities and differences and make a recommendation.
Show the solution
- Similarities: both are principles-based and flexible, need leadership from the top, stress risk culture, integration into decisions and continuous improvement, and neither is mandatory by itself.
- Difference in focus: COSO ERM links risk explicitly to strategy and performance and is organised into five components. ISO 31000 is a generic standard built on principles, a framework and a defined process.
- Difference in origin and use: COSO ERM grew from the internal control and governance tradition. ISO 31000 is designed to suit any organisation of any size or sector.
- Apply to Harbor: it is a private mid-sized company with no stated process for assessing risk. A clear step-by-step process helps it start. Strategy-risk linkage matters too as it expands.
- Recommendation: adopt ISO 31000 for its clear process and flexibility, and borrow COSO's emphasis on linking risk to strategy when setting objectives. Keep the effort proportionate to its size.
- Caveat: either framework fails if the board does not own it or if it becomes a compliance exercise.
Answer: The finance director is partly right: both are principles-based and need board leadership. They differ in emphasis. COSO ERM ties risk to strategy and performance through five components, while ISO 31000 provides a generic principles, framework and process structure. For Harbor, ISO 31000 is a sensible starting point because of its clear process and flexibility, supplemented by COSO's strategy focus, applied proportionately.
Exam tips
- Always tie the framework to the scenario. A pure description of COSO or ISO earns few marks and no professional skills credit.
- Know the five COSO ERM components and the ISO 31000 structure of principles, framework and process well enough to list them in seconds.
- When the company is listed, mention the board's duty to determine the nature and extent of principal risks and to review controls at least annually.
- Use the commercial awareness skill: weigh cost and benefit and say what is proportionate for the company's size.
- If asked to compare, organise by headings such as focus, structure and fit. Then give a clear recommendation.
Practice questions from Managing, monitoring and mitigating risk
- Brindle Foods, a mid-sized manufacturer, has listed a risk that a key supplier may fail. The risk committee rates the likelihood as low but …
- Marlowe Retail is deciding how to respond to a risk of supplier failure. It signs a contract with a second supplier so that supply continues…
- Orchid Bank has a business continuity plan that includes an alternative data centre. Management states that the plan has been approved by th…
- Tarnwell Energy's board reviews risk only once a year through a report prepared by the finance director. Following a major safety incident t…
- Zephyr Logistics Ltd has a board that wants a risk management approach in which the board sets risk appetite, management owns risks day to d…
Frameworks and Standards for Risk Management in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Frameworks and Standards for Risk Management: frequently asked questions
What is the difference between COSO ERM and ISO 31000?
Both are principles-based and flexible. COSO ERM is organised into five components and links risk closely to strategy and performance. ISO 31000 is a generic standard made up of principles, a framework and a risk management process, and is designed for any organisation.
Do I need to memorise the COSO ERM principles for SBL?
You should know the five components well and be able to describe what each means in practice. Learning every individual principle is less useful than applying the components to a case. Marks come from application, not recall.
Is ISO 31000 a certification standard?
No. It provides guidelines for risk management and is not a standard against which an organisation is certified. Organisations use it to design and improve their own risk systems.
How does the UK Corporate Governance Code relate to these frameworks?
The Code sets out the board's responsibilities for risk and control, including determining the nature and extent of principal risks and reviewing the systems at least annually. COSO ERM or ISO 31000 can be used as the practical framework to meet those duties.