COSO Enterprise Risk Management
An enterprise-wide framework for integrating risk management with strategy-setting and performance, owned at the top of the organisation.
Why it matters in CRISC
COSO ERM is the reference model for how risk connects to strategy and governance — appetite set at the top, risk considered when objectives are chosen, not bolted on after. A risk practitioner is expected to know that ERM is a governance discipline, not a control checklist.
Key elements
| Element | What it is |
|---|---|
| Governance & Culture | Establishes oversight responsibilities and the risk culture — board oversight, operating structures, and the desired behaviours that set the tone for everything else. |
| Strategy & Objective-Setting | Integrates ERM into strategic planning: defining risk appetite and evaluating alternative strategies against it before objectives are locked in. |
| Performance | Identifies, assesses and prioritises risks that affect the achievement of objectives, then selects risk responses across the portfolio. |
| Review & Revision | Reviews how the entity is performing and whether the ERM components are still working as intended, revising them as circumstances change. |
| Information, Communication & Reporting | Uses relevant information from internal and external sources to support ERM, and reports on risk, culture and performance to stakeholders. |
💡 How it shows in the exam
Expect stems that test the sequence appetite → strategy → objectives (COSO's core insight that risk appetite shapes strategy selection), and questions distinguishing enterprise-level ERM governance from operational control activities.