Strategic Performance Management and Business Valuation · Risk Management
Risk Management Frameworks: COSO ERM and ISO 31000
Updated 11 October 2026 · Fact-checked
A risk management framework is a structured system for identifying, assessing, responding to and monitoring risk across an organisation. COSO ERM (2017) links risk to strategy and performance through five components and 20 principles. ISO 31000 gives principles, a framework and a process. To answer, name the parts, then apply them to the case.
Understand Risk Management Frameworks (COSO ERM and ISO 31000)
Enterprise risk management (ERM) treats risk as something to manage across the whole organisation, not department by department. A framework gives the board and management a common structure and language, so risks are handled consistently and tied to objectives.
Two frameworks matter for your exam. COSO ERM is the 2017 framework, titled "Enterprise Risk Management: Integrating with Strategy and Performance". ISO 31000 is an international standard on risk management guidelines. Both aim at the same outcome: better decisions under uncertainty.
The 2017 COSO ERM framework has five interrelated components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication and Reporting. These are supported by 20 principles. The older 2004 COSO model was a cube with eight components (internal environment, objective setting, event identification, risk assessment, risk response, control activities, information and communication, monitoring). Do not mix the two versions.
ISO 31000 has three linked parts: principles (the values that make risk management effective, such as being integrated, structured, customised, inclusive, dynamic, based on best available information, considering human and cultural factors, and continually improving), a framework (leadership and commitment, integration, design, implementation, evaluation, improvement) and a process (communication and consultation, scope, context and criteria, risk assessment, risk treatment, monitoring and review, recording and reporting). Risk assessment itself covers identification, analysis and evaluation.
In governance, the board oversees risk and sets risk appetite, management owns and runs risk processes, and a risk officer coordinates and reports. Internal audit gives independent assurance. Frameworks are voluntary guidance, not a legal checklist, so you adapt them to the entity's size and nature.
Key rules to remember
- COSO ERM 2017 components
- Governance and Culture → Strategy and Objective-Setting → Performance → Review and Revision → Information, Communication and Reporting
- Five components, 20 principles. Remember the first three as the core cycle of setting up, choosing strategy and executing.
- ISO 31000 structure
- Principles + Framework + Process
- The process runs: communication and consultation; scope, context, criteria; risk assessment (identify, analyse, evaluate); risk treatment; monitoring and review; recording and reporting.
- Risk exposure (simple)
- Expected loss = Probability × Impact
- Used to rank risks in assessment. Probability is a fraction between 0 and 1; impact is in rupees.
- Residual risk
- Residual risk = Inherent risk − Effect of controls and responses
- Conceptual relationship. Compare residual risk with risk appetite to decide if further treatment is needed.
How to solve Risk Management Frameworks (COSO ERM and ISO 31000) questions
Use this method for any question on frameworks, whether it asks you to describe, compare or apply them.
- 1Read the question and identify the framework asked: COSO ERM, ISO 31000 or both.
- 2List the structure first: five components for COSO ERM (2017), or principles, framework and process for ISO 31000.
- 3Define each part in one line, using your own words.
- 4Link each part to the facts in the case, such as a named company, a loss event or a weak board.
- 5For comparison questions, use fixed headings: origin, structure, focus, certification or use, and scope.
- 6Point out gaps in the case and say which component or step would fix them.
- 7Close with a short recommendation, such as board-level risk appetite and regular review.
Quickest way: Structure-first recall
When to use it: Use this for 2-mark MCQs and for opening a long answer when time is short.
- Write the skeleton on rough paper: COSO has 5 components and 20 principles; ISO has principles, framework and process.
- Match the keyword in the question: culture, board, appetite means Governance and Culture; strategy options means Strategy and Objective-Setting; assess, respond means Performance.
- If the question mentions improving or changing practices, think Review and Revision.
- If it mentions data, reports or stakeholders, think Information, Communication and Reporting.
- Eliminate options that mix the 2004 eight components with the 2017 five.
Common mistakes in Risk Management Frameworks (COSO ERM and ISO 31000)
Mixing the 2004 eight-component COSO model with the 2017 five-component model.
Old textbooks and notes still show the cube with eight components.
Fix: Write the 2017 five components as your default. Mention 2004 only if the question asks about it.
Saying ISO 31000 is a certifiable standard.
Students assume all ISO standards give certificates.
Fix: Say ISO 31000 provides guidelines. It is not meant for certification, unlike some other ISO standards.
Listing components without applying them to the case.
Students learn lists by rote and stop there.
Fix: After each component, add one sentence tying it to the facts in the question.
Treating risk appetite and risk tolerance as the same thing.
Both words sound similar.
Fix: Appetite is the broad amount and type of risk the entity is willing to pursue. Tolerance is the acceptable variation around a specific objective.
Presenting ERM as only a risk-avoidance exercise.
Risk is seen as purely negative.
Fix: State that the frameworks treat risk as both threat and opportunity, and link it to value creation.
Writing a difference answer with no clear basis of comparison.
Students write two separate paragraphs.
Fix: Use a point-by-point comparison with at least four bases, such as issuer, structure, focus and use.
Worked examples
Example 1
Sundaram Textiles Ltd has no board-level discussion of risk. Each plant manager handles risks on his own, and losses from a cotton price spike were not reported upward. Using COSO ERM (2017), identify the weak components and suggest improvements.
Show the solution
- Governance and Culture is weak: the board does not oversee risk and there is no common risk culture or defined appetite.
- Information, Communication and Reporting is weak: the cotton price loss did not reach management or the board.
- Performance is weak: risks were not identified, assessed and prioritised on a company-wide basis, and no response such as hedging or supplier contracts was chosen.
- Improvement: set up a board risk committee, define risk appetite, and appoint a chief risk officer to coordinate.
- Improvement: create a risk register for all plants and a regular reporting line to management and the board.
- Improvement: review the process periodically under Review and Revision and adjust the responses.
Answer: The gaps lie mainly in Governance and Culture, Performance, and Information, Communication and Reporting. A board risk committee, a stated risk appetite, a company-wide risk register, regular reporting and periodic review would fix them.
Example 2
A risk has a 20% probability of occurring and an impact of ₹50,00,000. Controls are expected to cut the impact to ₹30,00,000 with the same probability. The company's risk appetite for this risk is an expected loss of ₹5,00,000. Compute the expected loss before and after controls and state whether further treatment is needed, in the ISO 31000 risk evaluation step.
Show the solution
- Expected loss before controls = 0.20 × ₹50,00,000 = ₹10,00,000.
- Expected loss after controls = 0.20 × ₹30,00,000 = ₹6,00,000.
- Compare with appetite: ₹6,00,000 is more than ₹5,00,000, so the residual risk is above appetite.
- Under risk evaluation, this means further treatment is needed, such as insurance transfer or stronger controls.
- Under monitoring and review, track the risk after treatment.
Answer: Expected loss falls from ₹10,00,000 to ₹6,00,000, which is ₹1,00,000 above the appetite of ₹5,00,000. Further risk treatment is needed.
Exam tips
- For comparison questions, learn a four-point table in your head: issuer, structure, focus and use. Then write it as point-wise lines.
- In case-based MCQs, match the symptom in the case to the COSO component or ISO step. Read the facts, not just the options.
- Always state the version: COSO ERM 2017 has five components and 20 principles.
- Do the small numerical step (probability × impact) neatly with rupee units, since examiners reward clear workings.
- End application answers with one practical recommendation, such as setting appetite or forming a risk committee.
Practice questions from Risk Management
- A firm's cash flow from a project has a 0.2 probability of a Rs 50 lakh loss, 0.5 probability of a Rs 20 lakh gain and 0.3 probability of a …
- Which risk is best described as the possibility of loss arising from inadequate or failed internal processes, people, systems or external ev…
- Aarav Textiles estimates that a fire could damage its warehouse stock. Probability of a fire in a year is 2%, and the loss if it occurs is R…
- Under the risk-management approach of treating risks by response, Sundaram Textiles decides to stop exporting to a politically unstable coun…
- A bank uses a one-day 99% Value at Risk (VaR) of Rs 4 crore for its trading book, assuming returns are independent and normally distributed.…
Risk Management Frameworks (COSO ERM and ISO 31000) in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Management Frameworks (COSO ERM and ISO 31000): frequently asked questions
What are the five components of COSO ERM 2017?
They are Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; and Information, Communication and Reporting. They are supported by 20 principles.
What are the principles of ISO 31000?
They state that risk management should be integrated, structured and comprehensive, customised, inclusive, dynamic, based on best available information, mindful of human and cultural factors, and continually improving. Their purpose is value creation and protection.
What is the main difference between COSO ERM and ISO 31000?
COSO ERM is a framework from the Committee of Sponsoring Organizations, built around five components that tie risk to strategy and performance. ISO 31000 is an international standard with principles, a framework and a process, and it is generic and not for certification.
Is ERM mandatory under law in India?
The frameworks themselves are voluntary guidance. Indian company law and listing rules do place risk-related duties on boards, but you should not cite a specific section unless you are sure of it.