What are the four main objectives of COSO ERM?

What are the four main objectives of COSO ERM?
When initiating the project to update its ERM framework, COSO saw opportunities to achieve clarity on several fronts.  The updated framework recognizes the increasing importance of the interconnection of risk, strategy and enterprise performance – particularly in conjunction with making important decisions.  It begins with an underlying premise that every entity exists to provide value to its stakeholders and faces uncertainty in the pursuit of that value.  Therefore, the framework itself focuses on preserving and creating enterprise value, with an emphasis on managing risk within the entity’s risk appetite.  The term “uncertainty” is defined as not knowing how or if potential events may manifest themselves in the context of achieving future strategies and business objectives. “Risk” is considered the effect of such uncertainty in the formulation and execution of the business strategy and the achievement of business objectives.

The challenge for management and the board of directors is to evaluate how much uncertainty – as well as how much risk – they are prepared and able to accept when executing the strategy and pursuing the organization’s performance goals.  Therefore, ERM is all about balancing risks and reward in creating value.  Achieving that balance leads to an emphasis on protecting enterprise value as well as enhancing it.

The framework is principles-based, meaning it introduces five interrelated components and outlines 20 relevant principles arrayed among those components.  The framework is a significant improvement over its 2004 counterpart, as its structure offers a benchmarking option for companies seeking to enhance their ERM approach.  The framework focuses on integrating ERM with the core processes that matter. Its subtitle says it all – “Integrating with Strategy and Performance.” Its concept of integration is embodied within its definition of ERM: “The culture, capabilities and practices, integrated with strategy-setting and performance, that organizations rely on to manage risk creating, preserving and realizing value.”

If a company implements a stand-alone process, it may be worthwhile and useful, but not an ERM, as COSO defines it.  There are four themes that are vital to effective ERM integration:

  1. Implementing strategy
  2. Integrating performance
  3. Laying a strong foundation with risk governance and culture
  4. Tying risk considerations into decision-making processes

Learn more about ERM and COSO by exploring these related publications on KnowledgeLeader:

Enterprise Risk Management Summary Approach Guide

Enterprise Risk Management Project Plan Guide

ERM Audit Questionnaire

COSO ERM: What It Means to the Board

Overview of the COSO Internal Control - Integrated Framework (KLplus CPE Course)

Updated COSO ERM Framework: What's New?

*This post has been updated to include Enterprise Risk Management - Integrated Framework updates.

03 May 2021

What are the four main objectives of COSO ERM?

The COSO ERM framework explained

If you are a risk, compliance or audit professional then it is likely you will have heard of the COSO ERM framework and its role in supporting effective risk management and internal control systems. Though if you are not overly familiar with how the framework is applied in practice, we summarise the key components and how it could benefit your organisation in achieving its long-term objectives.

The need for more effective risk management

In answer to a call for principles-based guidance to help businesses implement an enterprise-wide approach to risk management, COSO (the Committee of Sponsoring Organisations) launched its ERM Integrated Framework in 2004.

This original framework, whilst particularly well suited for enterprises where risk is driven by the internal audit function, came under some criticism for its lack of focus on identifying threats and opportunities - which is arguably where the true value of ERM lies.

To address this and the growing complexity of the risk environment, COSO later published an updated standard in 2017 which builds on the characteristics of the 2004 version, with a greater emphasis on strategy-setting and driving performance.

Today, the COSO risk management framework is used by thousands of enterprises worldwide to enhance their internal controls, providing a more extensive and robust focus on the area of ERM. Not only does it concentrate on broader strategic objectives but also company culture and concepts such as risk appetite. Plus, with stakeholders engaged with risk more than ever before and with less margin for error, the new standard helps organisations to meet the demands of heightened transparency and accountability when managing the impact of risk.

What are the five components of the COSO framework?

COSO believes that for ERM to be effective, it must be embedded throughout an organisation, since risk influences and aligns strategy and performance at all levels.

Comprising 20 principles that are grouped into five interrelated components, COSO’s latest framework acknowledges risk management as an iterative process, as shown in the model below.

What are the four main objectives of COSO ERM?
What are the four main objectives of COSO ERM?

  1. Governance and culture – Providing a foundation for the other four components, governance refers to the ‘tone from the top’ and the oversight responsibilities for ERM, whilst culture looks at risk awareness, desired behaviours, and instilling the right ethical values.
  2. Strategy and objective-setting – With a core focus on strategic planning, understanding the long-term impact of risk and the contributing factors, this section offers guidance on establishing the risk appetite, formulating key objectives, and defining the processes for adequately identifying, assessing and responding to risk.
  3. Performance – Once the strategy has been developed, the next step is to assess the risks that could hinder a business as it strives towards its goals. This component assists organisations in prioritising risks based on their severity, as well as effectively responding to these risks. The results of which are then shared with the key risk stakeholders.
  4. Review and revision – Now that risks have been prioritised along with their associated course of action, organisations can reflect on their ERM process to examine how well it's functioning and, if the risk landscape has evolved, determine where improvements can be made.
  5. Information communication and reporting – The final component of the framework helps to ensure ERM is embedded as a continual practice, where information is shared from both internal and external sources across the organisation in the areas of risk, culture and performance.

Why implement the COSO enterprise risk management framework?

The ability to achieve your organisational objectives is largely accomplished through your reputation, which in turn is dependent on your commitment and focus on good governance and accountability.

As the risk landscape becomes ever more volatile and complex, the COSO ERM framework not only helps to provide assurance to key stakeholders but also offers an effective lens through which businesses can evaluate their ability to align strategy, risk and performance. 

Since it also enforces greater transparency and culture around risk, organisations are better able to improve their resilience capabilities as well as identify risks before they pose a major threat in the evolving business environment.

Another key benefit of the COSO framework is that it accommodates modern-day risk management technology and the generation of data and analytics to support decision-making – a sure way to mitigate any unwanted surprises and harness opportunities for future organisational success.

Knowing where to start

Applying the COSO framework to your risk management operations may seem like a monumental endeavour, which is why it is recommended to approach its implementation in stages, prioritising one component at a time.

In order to do this, first assess where your business stands in relation to the five key principles of the framework. By answering the following questions, you can gain better clarity on where to concentrate your efforts:

  • What is your organisation’s culture around risk and is this being exemplified from the top?
  • How are decisions made when it comes to risk?
  • How do you know if you are moving towards your business objectives or if there is an obstacle in the way?
  • What is helping to drive organisational improvement?
  • Does your business lack key insights and effective communication around risk?
  • What are your businesses top pain points and could an ERM framework help to solve them?

With the right focus and a burgeoning ERM strategy, your business can be confident in tackling the uncertainty of not just today’s risk climate but also that of the future.

Now that you have had a whistle-stop tour of the COSO ERM framework, we explore a topic that has seen some debate over the years: Who owns enterprise risk? Download your free white paper to get our recommendations for auditors and risk managers.

What are the four main objectives of COSO ERM?

Alexandria Claypole

As Content Marketing Executive at Ideagen, Alex delivers insightful and actionable content to help organisations worldwide better understand the intricacies of the auditing, risk and compliance world. With strong roots in the technology sector, Alex is committed to advocating software solutions that support businesses in both achieving and exceeding their objectives.

What are the four objectives of COSO?

COSO can be divided into three key objectives: Operations, reporting, and compliance. These objectives fully support the goal of the internal control framework.

What are the four objective categories in the ERM framework?

At present, the CAS ERM framework covers four types of risk: financial, strategic, operational, and hazard. And the process of applying the framework itself involves seven process steps: Establish Context.

What are the objectives and components of the COSO ERM framework?

Here are the five components of the COSO framework:.
Control environment. The control environment seeks to make sure that all business processes are based on the use of industry-standard practices. ... .
Risk assessment and management. ... .
Control activities. ... .
Information and communications. ... .
Monitoring..

What is COSO in ERM?

COSO, which is short for the Committee of Sponsoring Organizations of the Treadway Commission, was initially established by five major accounting associations and institutes in the U.S. in the mid-1980s as part of the National Commission on Fraudulent Financial Reporting.