Blog
/
Finance

Implementing COSO ERM: A Practical Guide for Finance Leaders

Lee Latter
Lee Latter
0
min
2026-08-04

Risk management in finance is only as effective as the structure behind it. The COSO ERM framework gives finance leaders a consistent, evidence-based approach to identifying, assessing, and managing risk across the business, connecting risk oversight directly to strategic performance rather than treating it as a separate compliance exercise.

Summary

  • COSO ERM (Enterprise Risk Management) is a globally recognised framework that integrates risk management with strategy and business performance, last updated in 2017.
  • It is built around five components: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication, and reporting.
  • Only 34% of organisations have a fully established ERM programme, per the Baker Tilly & Internal Audit Foundation ERM Maturity Survey 2025 (n=567) — underlining how much room for improvement remains across most sectors.
  • COSO ERM is a voluntary framework; it differs from mandatory regulations such as the FCA’s operational resilience rules or ISO 31000, which carry legal or contractual weight.
  • Finance leaders using a structured ERM approach are better positioned to inform key financial decisions with automation and connect risk data directly to capital allocation.
  • Data automation and reconciliation controls form a critical part of operationalising the framework’s performance and review components.

What is COSO ERM?

COSO stands for the Committee of Sponsoring Organizations of the Treadway Commission, a joint initiative formed in 1985 by five major professional accounting and finance bodies including the American Institute of Certified Public Accountants and the Institute of Internal Auditors. Originally established to address fraudulent financial reporting, COSO has since expanded its scope to become the cornerstone of modern enterprise risk management practice.

The COSO ERM framework (formally titled Enterprise Risk Management: Integrating with Strategy and Performance) was first published in 2004 and significantly revised in 2017. The revision reduced the framework from eight components to five and repositioned ERM as a strategic tool rather than a compliance function. The central premise is that risk management should be embedded in how an organisation sets and pursues its objectives, not bolted on as a separate process.

COSO is widely used across financial services, where banks, insurance firms, and investment managers face overlapping operational, credit, market, and compliance risks. A robust Enterprise Resource Planning (ERP) system is frequently cited as a foundational requirement for operationalising the framework, as it provides the data infrastructure needed to monitor risks consistently across entities and functions.

Key components of the COSO ERM framework

The 2017 framework organises enterprise risk management into five interrelated components, each supported by a set of principles:

  • Governance and culture: Sets the tone from the top. The board and senior management define risk appetite, establish oversight responsibilities, and embed risk awareness into the organisation’s values and behaviour.
  • Strategy and objective-setting: Integrates risk management into strategic planning. Risk appetite is articulated in the context of business objectives, and potential risks are evaluated as part of the strategy development process rather than after the fact.
  • Performance: Identifies and assesses risks that could affect the achievement of objectives. Risks are prioritised based on their likelihood and impact, and responses are selected - accept, avoid, pursue, reduce, or share - based on the organisation’s risk appetite.
  • Review and revision: Evaluates whether ERM components are functioning effectively and whether the risk environment has changed. This is an ongoing process, not an annual exercise.
  • Information, communication, and reporting: Ensures that relevant risk information flows through the organisation in a timely and usable format. Reporting covers both internal decision-making and external stakeholder communication.

Does your business need the COSO ERM framework?

COSO ERM is not a mandatory requirement for most businesses. It is a voluntary framework that organisations choose to adopt because it improves the quality of their risk oversight. The case for adoption is strongest when the business operates across multiple entities, geographies, or regulatory environments; when the board or audit committee is under pressure to demonstrate that risk management is integrated with strategy; or when the organisation is growing through acquisition and needs a common risk language across newly integrated entities.

A useful starting point is an internal audit of current risk management practice against the five COSO components. Where gaps exist, particularly in governance accountability, risk appetite documentation, or the quality of risk reporting, the framework provides a structured path to improvement. The same Baker Tilly & Internal Audit Foundation survey found that fewer than half of respondents (49%) agree that risk awareness resonates across their organisation, and only 62% say risk information is actively used for strategic planning - clear indicators that most ERM programmes are not yet delivering their full potential. Avoiding reconciliation errors with risk management is a concrete example of where operational risk controls, properly embedded, reduce both financial exposure and audit findings.

The value of a framework like COSO ERM is not in the documentation it produces — it is in the conversations it forces. When risk appetite is formally articulated and connected to objectives, the business has a common reference point for every significant decision. Without that, risk management tends to be reactive and inconsistent
Lee Latter, Head of Professional Services, Aurum Solutions

How do risk management frameworks differ from risk management regulation?

A framework like COSO ERM or ISO 31000 is guidance, it represents best practice and provides a structure that organisations voluntarily adopt to improve their risk management capability. Adoption is a choice, and the framework can be applied in full or in part depending on the organisation’s size, complexity, and maturity.

Regulation is different. The FCA’s operational resilience framework requires firms to identify important business services, set impact tolerances, and demonstrate they can remain within those tolerances during disruption, this is a legal obligation with supervisory consequences for non-compliance. The Senior Managers and Certification Regime (SMCR) places personal accountability on named individuals for specific risk and control responsibilities.

ISO 31000 occupies a middle ground. It is an international standard rather than a legal requirement, but contractual relationships or sector-specific expectations may effectively make compliance necessary for some organisations. The key difference from COSO ERM is that ISO 31000 is principles-based and applicable across all industries, while COSO ERM is more prescriptive and oriented toward financial reporting and governance contexts. In practice, finance leaders in regulated sectors typically need to satisfy both: regulatory obligations set the floor, and frameworks like COSO ERM provide the architecture for building above it.

How can Aurum help with your ERM?

Effective ERM depends on accurate, timely data and that data depends on reconciliation and control processes that work reliably at scale. The performance and review components of COSO ERM require finance teams to monitor risk indicators continuously and adjust their response as conditions change. That is only possible when the underlying financial data is clean, reconciled, and current.

The technology gap within ERM is significant. The Baker Tilly & Internal Audit Foundation survey found that 59% of ERM programmes still rely on basic tools such as spreadsheets, and fewer than 1 in 10 (6%) report AI is used frequently to assist in identifying risks. This leaves most organisations without the real-time data visibility and automated monitoring that a mature ERM programme requires.

At Aurum, we work with finance teams to automate reconciliation across bank accounts, sub-ledgers, and ERP systems, creating the audit-ready data environment that ERM frameworks require. Automated exception management means that control gaps are surfaced immediately rather than discovered during a quarterly review. Every reconciliation outcome is logged with a clear audit trail, supporting the information and reporting component of COSO ERM without additional manual effort.

Book a demo with Aurum to see how data automation and reconciliation controls can strengthen your ERM programme.

At Aurum Solutions, we are committed to upholding fiscal responsibility in all our financial endeavours. We prioritise prudent financial management, transparency, and accountability to ensure the effective allocation and utilisation of resources. Our commitment to fiscal responsibility extends to our stakeholders, fostering trust and sustainability in our financial practices.

Lee Latter
Author
Lee Latter

Head of Professional Services

Author page

Get started. Together with Aurum.
It’s time to automate your reconciliation.
Request Demo
Related resources