3.1 Enterprise Risk Management Frameworks
Key Takeaways
- COSO ERM (2017) organizes enterprise risk governance across 5 interrelated components supported by 20 core principles, embedding risk analysis directly into strategic planning and performance execution.
- ISO 31000:2018 is a non-certifiable guidance standard structured around an open triad: 8 foundational principles (centered on value creation and protection), an organizational framework, and a systematic risk management process.
- NIST CSF 2.0 elevated enterprise risk governance by establishing the GOVERN (GV) function alongside Identify, Protect, Detect, Respond, and Recover, providing actionable operational controls for board-level risk oversight.
- Effective risk governance demands integrating IT risk into Enterprise Risk Management (ERM) to eliminate operational silos, ensure cross-functional aggregation, and prevent blind spots in digital supply chains.
- Framework selection must reflect organizational complexity and regulatory mandates: COSO ERM excels in corporate governance and board reporting, ISO 31000 provides flexible process guidance, and NIST CSF delivers technical and operational cybersecurity rigor.
3.1 Enterprise Risk Management Frameworks
Modern enterprises operate in an interconnected, volatile threat environment where information technology (IT) and cybersecurity risks can instantaneously destabilize strategic objectives, erode shareholder value, and trigger severe regulatory penalties. Historically, organizations managed risks in operational silos: financial risk resided in the treasury department, legal risk in general counsel, operational risk in facilities or business units, and IT risk within the server room. This fragmented approach created catastrophic blind spots, as senior executives and boards of directors lacked an aggregate, holistic view of enterprise exposure.
Enterprise Risk Management (ERM) resolves this fragmentation by establishing a structured, consistent, and continuous governance process to identify, analyze, respond to, and monitor all categories of risk across the entire organization. For the ISACA CRISC professional, understanding how IT risk integrates into overarching ERM frameworks—primarily COSO ERM, ISO 31000:2018, and NIST CSF 2.0—is fundamental to establishing effective risk governance.
+-----------------------------------------------------------------------------+
| THE EVOLUTION FROM SILOED RISK TO ERM |
| |
| SILOED / FRAGMENTED RISK MANAGEMENT ENTERPRISE RISK MANAGEMENT (ERM)|
| ----------------------------------- --------------------------------|
| - IT risks treated as technical bugs - IT risks quantified as |
| - Disjointed risk registers per unit strategic business exposures |
| - Inconsistent risk evaluation criteria - Unified risk taxonomy & scales|
| - Reactive firefighting after incidents - Aggregated portfolio view |
| - Risk ignored in strategic planning - Proactive, strategy-aligned |
+-----------------------------------------------------------------------------+
1. The COSO ERM Framework (2017)
In 2017, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) published an updated edition of its landmark framework: Enterprise Risk Management—Integrating with Strategy and Performance. This edition modernized enterprise risk governance by directly linking risk identification and assessment with strategy formulation, business objective setting, and performance execution.
[!NOTE] COSO Internal Control vs. COSO ERM: CRISC candidates must distinguish between COSO's two distinct frameworks:
- COSO Internal Control - Integrated Framework (2013): Focuses on internal financial controls, compliance, operational control reliability, and reporting (organized around 5 internal control components and 17 principles).
- COSO ERM (2017): Focuses on broad strategic risk governance, value creation, strategy formulation, and enterprise performance (organized around 5 ERM components and 20 principles).
+-----------------------------------------------------------------------------+
| COSO ERM (2017) 5-COMPONENT HELIX |
| |
| 1. GOVERNANCE & CULTURE |
| Sets tone at the top, establishes oversight, enforces ethics. |
| | |
| v |
| 2. STRATEGY & OBJECTIVE-SETTING |
| Defines risk appetite, evaluates alternative business strategies. |
| | |
| v |
| 3. PERFORMANCE |
| Identifies, assesses, prioritizes, and responds to risk exposures. |
| | |
| v |
| 4. REVIEW & REVISION |
| Assesses framework changes, evaluates performance, seeks improvements. |
| | |
| v |
| 5. INFORMATION, COMMUNICATION & REPORTING |
| Leverages IT/data systems, reports risk, culture, and performance. |
+-----------------------------------------------------------------------------+
The 5 Components and 20 Supporting Principles
COSO ERM defines 20 actionable principles distributed across its five interrelated components:
Component 1: Governance and Culture (5 Principles)
Governance sets the organization's tone, reinforcing the importance of ERM and establishing oversight responsibilities. Culture pertains to ethical values, desired behaviors, and understanding of risk in the entity.
- Exercises Board Risk Oversight: The board of directors provides governance and oversight of the ERM strategy.
- Establishes Operating Structures: Management designs operating models and reporting lines to achieve business objectives within risk boundaries.
- Defines Desired Culture: The entity defines core behavioral expectations and acceptable risk-taking culture.
- Demonstrates Commitment to Core Values: The organization articulates commitment to integrity and ethical decision-making.
- Attracts, Develops, and Retains Capable Individuals: The enterprise builds human capital and aligns competencies with risk management responsibilities.
Component 2: Strategy and Objective-Setting (4 Principles)
ERM, strategy, and objective-setting work together in the strategic planning process. Risk appetite is established and aligned with strategy; business objectives put strategy into practice. 6. Analyzes Business Context: Considers external and internal environmental factors influencing enterprise risk profiles. 7. Defines Risk Appetite: Formulates and clearly articulates risk appetite in the context of creating, preserving, and realizing value. 8. Evaluates Alternative Strategies: Assesses alternative strategic pathways and their associated risk profiles. 9. Formulates Business Objectives: Establishes measurable operational objectives aligned with strategy and risk appetite.
Component 3: Performance (5 Principles)
Risks that may impact the achievement of strategy and business objectives need to be identified and assessed. Risk is prioritized by severity in the context of risk appetite. 10. Identifies Risk: Identifies new, emerging, and changing risk exposures across operations and technologies. 11. Assesses Severity of Risk: Evaluates likelihood and impact of identified risks at multiple levels of the entity. 12. Prioritizes Risks: Ranks risks as a basis for selecting appropriate risk responses. 13. Implements Risk Responses: Selects and executes risk responses (mitigation, transfer, avoidance, acceptance). 14. Develops Portfolio View: Synthesizes an aggregate enterprise-wide portfolio view of risk across business units.
Component 4: Review and Revision (3 Principles)
By reviewing entity performance, an organization can consider how well the ERM components are functioning over time and in light of substantial changes. 15. Assesses Substantial Change: Identifies internal and external shifts (e.g., mergers, regulatory changes, disruptive tech) that alter risk profiles. 16. Reviews Risk and Performance: Evaluates whether target performance metrics were achieved within acceptable risk boundaries. 17. Pursues Improvement in ERM: Continuously enhances risk governance capabilities, data analytics, and control systems.
Component 5: Information, Communication, and Reporting (3 Principles)
ERM requires a continual process of obtaining and sharing necessary information, from both internal and external sources, flowing up, down, and across the organization. 18. Leverages Information Systems: Harnesses technology, data governance, and analytics to support robust ERM execution. 19. Communicates Risk Information: Shares actionable risk data across stakeholders through open reporting channels. 20. Reports on Risk, Culture, and Performance: Generates executive and board reports detailing risk metrics, KRI trends, and control posture.
2. ISO 31000:2018 (Risk Management — Guidelines)
The International Organization for Standardization (ISO) developed ISO 31000:2018 to provide an open, globally recognized standard applicable to any public, private, or community enterprise. Unlike management system standards such as ISO/IEC 27001 (Information Security) or ISO 9001 (Quality Management), ISO 31000 is a guidance document and cannot be certified against.
ISO 31000:2018 is architected as an interconnected triad: Principles, Framework, and Process.
+-----------------------------------------------------------------------------+
| ISO 31000:2018 ARCHITECTURAL TRIAD |
| |
| [8 PRINCIPLES] [FRAMEWORK] [PROCESS] |
| - Value Creation & - Leadership & - Scope, Context,|
| Protection (Core) Commitment (Core) Criteria |
| - Integrated - Integration - Risk Assessment|
| - Structured/Comprehensive - Design * Identification|
| - Customized - Implementation * Analysis |
| - Inclusive - Evaluation * Evaluation |
| - Dynamic - Improvement - Risk Treatment |
| - Best Available Info - Monitoring/Rev |
| - Human & Cultural - Recording/Rep |
| - Continual Improvement - Comm/Consult |
+-----------------------------------------------------------------------------+
The ISO 31000 Triad Detailed:
A. The 8 Principles
The core purpose of risk management is value creation and protection. This core purpose is sustained by eight operational principles:
- Integrated: Embedded as an integral part of all organizational activities and governance.
- Structured and Comprehensive: A systematic approach yields consistent, comparable results.
- Customized: Tailored to the organization's external and internal context and operating profile.
- Inclusive: Involves appropriate stakeholder engagement to ensure perspectives and knowledge are considered.
- Dynamic: Anticipates, detects, acknowledges, and responds to organizational change in real time.
- Best Available Information: Accounts for historical data, forward-looking models, and data limitations.
- Human and Cultural Factors: Recognizes human capabilities, perceptions, and cultural behaviors at all levels.
- Continual Improvement: Iteratively enhanced through learning, audit feedback, and experience.
B. The Framework
The framework assists management in integrating risk management into significant activities and functions. Leadership and Commitment forms the non-negotiable core, driving the continuous cycle of:
- Integration: Embedding risk processes into organizational structures.
- Design: Designing the risk architecture, resource allocation, and communication mechanisms.
- Implementation: Executing the risk framework across business operations.
- Evaluation: Measuring framework performance against governance expectations.
- Improvement: Adapting the framework to address internal and external changes.
C. The Process
The risk management process involves the systematic application of policies, procedures, and practices to the activities of communicating, consulting, establishing the context, and assessing, treating, monitoring, reviewing, recording, and reporting risk.
+-----------------------------------------------------------------------------+
| ISO 31000:2018 RISK MANAGEMENT PROCESS |
| |
| +---------------------------------------------------------------------+ |
| | COMMUNICATION & CONSULTATION | |
| +----------------------------------+----------------------------------+ |
| | |
| v |
| +---------------------------------------------------------------------+ |
| | SCOPE, CONTEXT & RISK CRITERIA | |
| +----------------------------------+----------------------------------+ |
| | |
| v |
| +---------------------------------------------------------------------+ |
| | RISK ASSESSMENT | |
| | +-------------------+ +-------------------+ +---------------+ | |
| | | IDENTIFICATION |->| ANALYSIS |->| EVALUATION | | |
| | +-------------------+ +-------------------+ +---------------+ | |
| +----------------------------------+----------------------------------+ |
| | |
| v |
| +---------------------------------------------------------------------+ |
| | RISK TREATMENT | |
| +----------------------------------+----------------------------------+ |
| | |
| v |
| +---------------------------------------------------------------------+ |
| | RECORDING & REPORTING | |
| +----------------------------------+----------------------------------+ |
| | |
| v |
| +---------------------------------------------------------------------+ |
| | MONITORING & REVIEW | |
| +---------------------------------------------------------------------+ |
+-----------------------------------------------------------------------------+
3. NIST Cybersecurity Framework (CSF) 2.0 Governance Integration
In February 2024, the National Institute of Standards and Technology (NIST) released NIST CSF 2.0, expanding the framework's scope from critical infrastructure protection to all organizations regardless of size or sector. The most pivotal architectural update was the introduction of the GOVERN (GV) function.
+-----------------------------------------------------------------------------+
| NIST CSF 2.0 SIX-FUNCTION ARCHITECTURE |
| |
| [GOVERN] |
| (Organizational Context, |
| Strategy, Policy, Oversight, |
| Supply Chain Risk Governance) |
| | |
| +-------------------------+-------------------------+ |
| | | | |
| v v v |
| [IDENTIFY] [PROTECT] [DETECT] |
| (Asset Mgmt, Risk (IAM, Data Sec, (Continuous Mon., |
| Assessment, Imp/Vuln) Awareness, Platform) Anomaly Detection) |
| | | | |
| +-------------------------+-------------------------+ |
| | |
| +-------------+-------------+ |
| | | |
| v v |
| [RESPOND] [RECOVER] |
| (Incident Mgmt, (Restoration, BCP, |
| Analysis, Mitigation) Post-Incident Review) |
+-----------------------------------------------------------------------------+
The GOVERN Function (GV) Categories:
- Organizational Context (GV.OC): Understanding enterprise mission, stakeholder expectations, and legal/regulatory requirements.
- Risk Management Strategy (GV.RM): Establishing organizational risk appetite, tolerance, and operational risk management priorities.
- Roles, Responsibilities, and Authorities (GV.RR): Defining accountable leadership, resource allocation, and RACI governance.
- Policy (GV.PO): Establishing, updating, and communicating organizational cybersecurity policies and standards.
- Oversight (GV.OV): Monitoring enterprise cybersecurity posture and evaluating the effectiveness of risk governance.
- Cybersecurity Supply Chain Risk Management (GV.SC): Managing third-party, vendor, and supply chain cyber risk exposures.
[!IMPORTANT] Strategic Role of the GOVERN Function: In NIST CSF 1.1, governance concepts were scattered across Identify and Protect categories. NIST CSF 2.0 establishes GOVERN as the overarching umbrella that informs and directs how an enterprise executes the other five technical and operational functions (Identify, Protect, Detect, Respond, Recover).
4. Comprehensive Framework Comparison Matrix
| Framework Feature | COSO ERM (2017) | ISO 31000:2018 | NIST CSF 2.0 | ISACA COBIT 2019 / Risk IT |
|---|---|---|---|---|
| Primary Issuing Body | COSO (Treadway Commission) | International Organization for Standardization (ISO) | National Institute of Standards & Technology (NIST) | ISACA |
| Core Focus | Enterprise strategy, governance, and business performance integration | Holistic risk management guidelines across all risk types | Cybersecurity and digital asset risk governance and operations | Enterprise Governance of Information & Technology (EGIT) |
| Structural Model | 5 Components, 20 Principles | Triad: 8 Principles, Framework, Process | 6 Functions (GV, ID, PR, DE, RS, RC), Categories, Subcategories | 40 Governance and Management Objectives across 5 Domains |
| Target Audience | Board of Directors, CROs, CFOs, Executive Leadership | Risk Managers, GRC Professionals, Operations Leaders | CISOs, Security Engineers, IT Risk Assessors, Regulators | CIOs, CISOs, IT Audit Leaders, IT Governance Committees |
| Certification Status | Non-certifiable guidance | Non-certifiable guideline standard | Non-certifiable framework | Non-certifiable governance framework |
| Key Strength | Directly links risk appetite to corporate strategy and value creation | Universally adaptable, concise, open-standard terminology | Deep operational cybersecurity controls linked directly to governance | Seamlessly connects IT-specific processes to enterprise business goals |
5. CRISC Exam Traps & Practical Decision Rules
+-----------------------------------------------------------------------------+
| CRISC FRAMEWORK DECISION RULES |
| |
| 1. THE "CERTIFYING TO ISO 31000" TRAP |
| Trap: "Our enterprise received ISO 31000 certification." |
| Reality: ISO 31000 is a guideline, not a management system standard. |
| Organizations certify to ISO/IEC 27001, not ISO 31000. |
| |
| 2. THE "COSO CUBE VS. COSO HELIX" TRAP |
| Trap: Confusing COSO Internal Control (Cube) with COSO ERM (Helix).|
| Reality: COSO Internal Control (2013) has 17 principles for controls; |
| COSO ERM (2017) has 20 principles for strategic risk. |
| |
| 3. THE "ONE SIZE FITS ALL" TRAP |
| Trap: Selecting a single framework to solve all governance needs. |
| Reality: Mature enterprises synthesize frameworks: COSO ERM at the |
| board level, COBIT for IT governance, and NIST CSF for cyber.|
+-----------------------------------------------------------------------------+
An enterprise is revising its governance structure to better align risk management with strategic planning and executive performance. The Board of Directors requests a framework that embeds risk identification directly into strategy formulation. Which framework and structural model should the IT risk practitioner recommend?
A multinational corporation seeks to standardize its risk management terminology and processes across global subsidiaries without pursuing formal compliance certification. Which standard provides guidance organized around principles, framework, and process?
The newly released NIST Cybersecurity Framework (CSF) 2.0 introduced a significant structural addition to establish direct synergy between operational cybersecurity activities and executive risk governance. Which function was added?
A Chief Information Security Officer (CISO) is presenting a multi-year security roadmap to the board Audit Committee. The committee asks why the enterprise cannot rely solely on the technical controls in NIST CSF and instead requires an overarching ERM framework. What is the PRIMARY rationale?