Back to Frameworks

COSO Enterprise Risk Management (ERM) Framework (2017)

International (COSO)
v2017
5 domains
20 controls

COSO Enterprise Risk Management framework (2017 edition, Integrating with Strategy and Performance), structured as five interrelated components (Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication, and Reporting) and 20 principles. Copyrighted by COSO/AICPA; full control text requires a licensed copy.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Governance and Culture

5 controls
Controls in the Governance and Culture domain of COSO Enterprise Risk Management (ERM) Framework (2017)5 controls
CodeTitle
GOV-1Exercises Board Risk Oversight
GOV-2Establishes Operating Structures
GOV-3Defines Desired Culture
GOV-4Demonstrates Commitment to Core Values
GOV-5Attracts, Develops, and Retains Capable Individuals

Information, Communication, and Reporting

3 controls
Controls in the Information, Communication, and Reporting domain of COSO Enterprise Risk Management (ERM) Framework (2017)3 controls
CodeTitle
INFO-18Leverages Information and Technology
INFO-19Communicates Risk Information
INFO-20Reports on Risk, Culture, and Performance

Performance

5 controls
Controls in the Performance domain of COSO Enterprise Risk Management (ERM) Framework (2017)5 controls
CodeTitle
PERF-10Identifies Risk
PERF-11Assesses Severity of Risk
PERF-12Prioritizes Risks
PERF-13Implements Risk Responses
PERF-14Develops Portfolio View

Review and Revision

3 controls
Controls in the Review and Revision domain of COSO Enterprise Risk Management (ERM) Framework (2017)3 controls
CodeTitle
REV-15Assesses Substantial Change
REV-16Reviews Risk and Performance
REV-17Pursues Improvement in ERM

Strategy and Objective-Setting

4 controls
Controls in the Strategy and Objective-Setting domain of COSO Enterprise Risk Management (ERM) Framework (2017)4 controls
CodeTitle
STR-6Analyzes Business Context
STR-7Defines Risk Appetite
STR-8Evaluates Alternative Strategies
STR-9Formulates Business Objectives

Frequently Asked Questions

What is COSO Enterprise Risk Management (ERM) Framework (2017)?

COSO Enterprise Risk Management (ERM) Framework (2017) is a compliance framework from International (COSO) with 5 domains and 20 controls. COSO Enterprise Risk Management framework (2017 edition, Integrating with Strategy and Performance), structured as five interrelated components (Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication, and Reporting) and 20 principles. Copyrighted by COSO/AICPA; full control text requires a licensed copy. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does COSO Enterprise Risk Management (ERM) Framework (2017) have?

COSO Enterprise Risk Management (ERM) Framework (2017) has 20 controls organised across 5 domains. The largest domains are Governance and Culture (5 controls), Performance (5 controls), Strategy and Objective-Setting (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does COSO Enterprise Risk Management (ERM) Framework (2017) map to?

COSO Enterprise Risk Management (ERM) Framework (2017) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with COSO Enterprise Risk Management (ERM) Framework (2017) compliance?

Start your COSO Enterprise Risk Management (ERM) Framework (2017) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about COSO Enterprise Risk Management (ERM) Framework (2017) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required