Skip to content

Strategic Performance Management and Business Valuation · Corporate Risk Management Performance

Enterprise Risk Management: COSO ERM Framework Explained

Updated 11 October 2026 · Fact-checked

Enterprise risk management (ERM) is a firm-wide process, led by the board and management, that identifies, assesses and responds to risks that can affect strategy and performance. The 2017 COSO framework, Enterprise Risk Management: Integrating with Strategy and Performance, has five components and 20 principles. To answer questions, map each fact to a component.

Understand Enterprise Risk Management (COSO ERM)

Every business takes risk to earn returns. Enterprise risk management treats risk as one connected picture for the whole entity, not as separate problems handled by separate departments. Credit risk, supply risk, cyber risk and regulatory risk are looked at together, against the strategy the company has chosen.

COSO is the Committee of Sponsoring Organizations of the Treadway Commission. Its 2017 ERM framework is titled Integrating with Strategy and Performance. The title tells you the main idea: risk management is not a back-office control. It is part of setting strategy and of running the business to meet objectives.

The 2017 framework has five interrelated components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; and Information, Communication and Reporting. These are supported by 20 principles, grouped under the components. The principles are stated as things an organisation does, such as exercising board risk oversight, defining risk appetite, identifying and assessing risks, and prioritising and responding to them.

The older 2004 framework used eight components and a cube. The 2017 update replaced the cube with a helix-style picture, and put more weight on strategy, culture and performance. Do not mix the two versions in an answer.

How does ERM support performance? It helps the company choose strategy with eyes open to risk, set a risk appetite it can live with, spot threats and opportunities early, use capital where risk-adjusted returns are best, and cut surprises. Example: an Indian auto-components maker sees that one customer gives 60% of its sales. Under ERM it identifies this as a concentration risk, assesses its impact, and responds by diversifying customers. It then reports progress to the board.

COSO has a separate Internal Control framework (2013). It focuses on reasonable assurance for operations, reporting and compliance objectives through five control components. ERM is wider. It covers strategy and risk appetite, and it deals with opportunity as well as threat.

Key rules to remember

Five components of COSO ERM (2017)
Governance and Culture → Strategy and Objective-Setting → Performance → Review and Revision → Information, Communication and Reporting
Learn the order. The last component runs through all the others, and review and revision feeds back into them.
Number of principles
20 principles across the five components
State that principles are grouped under components. Learn the main themes, not necessarily each wording word for word.
Principles under Governance and Culture
Board risk oversight; operating structures; desired culture; commitment to core values; attract, develop and retain capable individuals
Five principles.
Principles under Strategy and Objective-Setting
Business context; risk appetite; alternative strategies; business objectives
Four principles. Risk appetite is set here, before strategy is chosen.
Principles under Performance
Identify risk; assess severity; prioritise risks; implement risk responses; portfolio view
Five principles. The portfolio view looks at risk across the whole entity.
Principles under Review and Revision
Assess substantial change; review risk and performance; pursue improvement in ERM
Three principles.
Principles under Information, Communication and Reporting
Leverage information and technology; communicate risk information; report on risk, culture and performance
Three principles. 5 + 4 + 5 + 3 + 3 = 20.
Risk appetite versus risk capacity
Risk appetite = amount and type of risk the entity is willing to accept in pursuit of value; capacity = maximum risk it can bear
Appetite should sit within capacity.

How to solve Enterprise Risk Management (COSO ERM) questions

Use this method for any question on COSO ERM, whether it asks for definitions, components, a case application or a comparison.

  1. 1Read the question and mark the task word: explain, list, compare, apply or evaluate.
  2. 2If it is a case, underline each fact that shows a risk activity, such as a board decision, an appetite statement, a risk register or a review.
  3. 3Map each fact to one of the five components. Name the component first, then the principle.
  4. 4Link each point to strategy and performance. Say how it helps the entity meet objectives, not only avoid loss.
  5. 5For a comparison, use fixed heads: purpose, scope, focus on strategy, components, and who owns it. Write one line for each framework per head.
  6. 6Give a short example in rupees or a business setting from the case. Keep it specific.
  7. 7Close with a clear conclusion or recommendation, such as which component is weak and what to fix first.
  8. 8Check you used the 2017 framework terms, not the 2004 ones.

Quickest way: Component-tagging method

When to use it: Use this for MCQs and for case questions where you have little time.

  1. Ask what the activity is about. Board, culture or values means Governance and Culture.
  2. Appetite, strategy options or objectives means Strategy and Objective-Setting.
  3. Identifying, scoring, ranking or responding to risks means Performance.
  4. Changes, lessons or improvements means Review and Revision.
  5. Data, reports, communication to stakeholders means Information, Communication and Reporting.
  6. If options mix 2004 and 2017 terms, pick the 2017 one.

Common mistakes in Enterprise Risk Management (COSO ERM)

  • Listing the 2004 eight components (such as internal environment and objective setting) as the current framework.

    Older books and notes still show the 2004 cube.

    Fix: Write the 2017 five components. Mention 2004 only if the question asks about the change.

  • Treating ERM and COSO Internal Control as the same framework.

    Both come from COSO and both talk about risk and control.

    Fix: Say ERM is wider: it covers strategy, risk appetite and opportunities. Internal control gives reasonable assurance on operations, reporting and compliance objectives.

  • Placing risk appetite under Performance.

    Students link appetite with risk assessment.

    Fix: Remember appetite is set in Strategy and Objective-Setting, because strategy must fit appetite.

  • Describing ERM only as avoiding losses.

    Risk is commonly seen as purely negative.

    Fix: State that ERM also helps spot opportunities and supports value creation and performance.

  • Saying risk management belongs only to the risk officer or internal audit.

    Students confuse who coordinates with who owns risk.

    Fix: Say the board oversees, management owns risks, and everyone in the entity has a role.

  • Writing a case answer in theory with no link to facts.

    Students recall the list and stop.

    Fix: Quote the case fact, name the component, then give the implication.

Worked examples

Example 1

Sundaram Textiles Ltd's board has approved a statement that the company will not accept a loss of more than 5% of annual profit from any single foreign-exchange exposure. Management then reviews export-growth options against this limit. Identify the COSO ERM (2017) component involved, and explain how it supports performance.

Show the solution
  1. The board statement of the acceptable level of loss is a risk appetite statement.
  2. Defining risk appetite and evaluating alternative strategies are principles under Strategy and Objective-Setting.
  3. Reviewing export-growth options against the limit shows strategy is chosen with risk in view.
  4. Support for performance: the company avoids strategies that could threaten results beyond what it can accept.
  5. It can also pursue growth within the limit, so risk is taken deliberately to earn returns.

Answer: The component is Strategy and Objective-Setting. Risk appetite is set and strategy options are tested against it, so the company seeks growth within limits it can bear.

Example 2

Differentiate between the COSO Internal Control framework and the COSO ERM framework on any four points, and state how ERM adds value.

Show the solution
  1. Purpose: Internal Control gives reasonable assurance that objectives are achieved. ERM manages risk to strategy and performance.
  2. Scope: Internal Control covers operations, reporting and compliance objectives. ERM covers these and strategy.
  3. Risk appetite: Internal Control does not centre on it. ERM requires an appetite to be set and linked to strategy.
  4. Structure: Internal Control has five components (the 2013 framework). ERM (2017) has five components and 20 principles.
  5. Orientation: Internal Control is mainly about controls to address risk. ERM also looks at opportunity and the portfolio of risks.
  6. Value added: ERM links risk to strategy, improves resource allocation and reduces surprises.

Answer: Internal Control is narrower and control-focused. ERM is broader, strategy-linked and appetite-driven, with five components and 20 principles. It adds value by tying risk to strategy and performance.

Exam tips

  • Learn the five components in order and attach the principle themes to each. This answers most MCQs.
  • In case questions, name the component explicitly and quote the fact that proves it.
  • Be ready for a comparison with COSO Internal Control and with ISO 31000, using fixed heads.
  • Use the 2017 wording. If a question mentions 2004, answer for that version and say so.
  • Close case answers with a recommendation, such as which component needs strengthening.

Practice questions from Corporate Risk Management Performance

Enterprise Risk Management (COSO ERM) in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Enterprise Risk Management (COSO ERM): frequently asked questions

What are the five components of COSO ERM 2017?

They are Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; and Information, Communication and Reporting. They are supported by 20 principles.

What is the difference between COSO internal control and ERM?

Internal control gives reasonable assurance on operations, reporting and compliance objectives. ERM is broader. It integrates risk with strategy and performance and uses a risk appetite.

What is enterprise risk management with an example?

It is an entity-wide process to identify, assess and respond to risks that affect strategy and performance. For example, a firm that depends on one customer for most sales spots the concentration risk, sets a limit and diversifies.

Do I need to memorise all 20 principles for CMA Final?

Learn them by component and know the main themes. Most questions test whether you can match a situation to a component and explain its effect on performance.