Skip to content
complianceofficer

Blog · 25 Jul 2026 · 9 min read

COSO ERM vs ISO 31000: the real differences, and which one to adopt

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The short answer: COSO ERM and ISO 31000 both tell you how to run enterprise risk management, but they are built for different readers. COSO's 2017 framework organizes 20 principles into five components and spends most of its length on governance, strategy and board oversight, which is why US public companies cite it. ISO 31000:2018 is short guidance, about 16 pages, built on eight principles plus a framework and a process, deliberately sector-agnostic and written to be adapted. Neither is certifiable for an organization. If you are a US issuer or a regulated financial institution, COSO is the safer citation. If you want something a small risk function can actually implement, ISO 31000 is the faster start. Most mature programs run the ISO process inside the COSO governance structure.

That is the decision in one paragraph. The rest of this covers where the two genuinely differ, the question people get wrong about SOX, and what your framework choice changes about the register and the tooling underneath it. All references checked July 2026.

COSO ERM vs ISO 31000 at a glance

COSO ERM (2017) ISO 31000:2018
Publisher Committee of Sponsoring Organizations of the Treadway Commission, a private-sector US initiative of five accounting and finance bodies International Organization for Standardization
Structure 5 components, 20 principles 8 principles, a framework, a process
Length A full framework document with supporting compendiums and topic supplements About 16 pages of guidance
Center of gravity Governance, strategy, board oversight, performance The risk management process and integrating it into decisions
Risk appetite Treated at length, with worked examples of appetite, tolerance and capacity Handled briefly, through the concept of risk criteria
Certification None for organizations None; ISO publishes it as guidance, not a requirements standard
Best fit US public companies, banks, large multi-division enterprises, anyone answering to a board committee Smaller or flatter organizations, non-US operations, programs without a dedicated ERM department

What is the difference between COSO and ISO 31000?

The difference is emphasis, not disagreement. COSO's framework asks who is accountable, how risk connects to strategy, and what the board sees. ISO 31000 asks how risk gets identified, analyzed, evaluated and treated, and how that work gets embedded in ordinary decisions. Read side by side, they rarely contradict each other. They allocate their pages very differently.

There is a second difference worth naming because it trips people up: COSO publishes two frameworks that both have five components, and they are not the same thing. The Internal Control: Integrated Framework, last updated in 2013, has five components and 17 principles and is about internal control over financial reporting. The Enterprise Risk Management framework, updated in 2017, has five components and 20 principles and is about enterprise risk. Teams cite "COSO, five components" and mean different documents. Check which one your auditor is asking about before you map anything.

What are the five components of the COSO ERM framework?

The 2017 framework groups its 20 principles into five components: governance and culture; strategy and objective-setting; performance; review and revision; and information, communication and reporting. The sequence is deliberate. Governance comes first because COSO's position is that risk management fails at the top, not in the register, and review and revision sits near the end because the framework treats a static program as a failed one.

Worth knowing: COSO has not stopped publishing since 2017. Its 2026 release, From Guidance to Action: Exploring Practical ERM, is aimed squarely at programs that satisfy the framework on paper and still do not influence a single decision. If your risk committee papers get read and then filed, that is the document to pick up.

How many principles are in ISO 31000?

Eight. The 2018 revision cut the principle count and reorganized the standard around three parts: the eight principles, a framework for integrating risk management into organizational governance, and a process for identifying, analyzing, evaluating, treating, monitoring and reporting risk. The principles cover integration, structured and comprehensive approach, customization, inclusiveness, dynamic response, best available information, human and cultural factors, and continual improvement. The companion documents matter too: ISO 31010 covers risk assessment techniques in far more detail than the parent standard, and it is where most practitioners actually go for method.

Is ISO 31000 certifiable?

No, and this is the most common misunderstanding in the category. ISO 31000 is published as guidelines, not as a requirements standard, and ISO states it is not intended for certification purposes. There is no such thing as an ISO 31000 certified company. Individuals can take training and hold personal certificates from training bodies, and vendors sometimes market "ISO 31000 alignment", but no accredited certification body can audit your organization against it the way one certifies you to ISO 27001 or ISO 9001. If a buyer or an insurer asks for ISO 31000 certification, the honest answer is to explain the distinction and offer evidence of alignment instead.

COSO has no organizational certification either. What both frameworks give you is a defensible answer to "against what standard did you design this program", which is exactly the question an internal auditor or an examiner asks first.

Does SOX require COSO?

Not by name. Section 404 of the Sarbanes-Oxley Act requires management to assess the effectiveness of internal control over financial reporting, and SEC rules require management's report to identify the framework used to perform that evaluation. The framework has to be suitable and recognized. The COSO Internal Control framework is the one the overwhelming majority of US issuers name, to the point that in practice it functions as the default, but the statute does not mandate it.

Two consequences follow. First, the framework SOX work rests on is COSO's internal control framework, not COSO ERM, so adopting COSO ERM does not by itself satisfy anything under 404. Second, ISO 31000 is not a substitute for a SOX framework, because it is not about internal control over financial reporting at all. If SOX is your driver, the specifics are in SOX 404 compliance requirements, and the tooling side is on our SOX compliance software page.

Can you use COSO and ISO 31000 together?

Yes, and it is the most common end state in a mature program. The two documents fit together almost cleanly: COSO supplies the governance architecture, the link to strategy and the board reporting expectations, while ISO 31000 supplies the process discipline and, through ISO 31010, the assessment methods. Practitioners often describe COSO as answering who and why, and ISO as answering how.

The practical way to do it is to declare one framework as the framework of record, usually the one your regulator, auditor or parent company expects, and treat the other as a source of method. Declare COSO if you are a US issuer or a bank. Then run ISO's process, document your risk criteria in ISO's language, and map your five components against it once so nobody has to redo the reconciliation every year. What you should not do is maintain two registers. That is how a program ends up with two answers to "what is our top risk" and credibility with neither.

Which is better, COSO or ISO 31000?

For a US public company, a bank, an insurer or any organization with a formal risk committee, COSO ERM is the better primary citation, because it was written for exactly that governance structure and because your auditors and examiners already read it. For a mid-sized private company, a non-US subsidiary, or a team where one person owns risk alongside three other jobs, ISO 31000 is better, because you can read it in an afternoon and implement something real in a quarter rather than spending two quarters mapping principles.

The wrong answer, in either direction, is choosing the framework that produces the most impressive documentation. A register of thirty carefully worded risks that nobody reviews is worth less than eight risks with named owners, honest scores and an indicator each. Framework choice matters far less than whether the register is current, which is the part that decays quietly.

What your framework choice changes about the register

Both frameworks require the same core fields, which is convenient: a risk statement, an owner, an assessment against defined criteria or appetite, a treatment decision, and evidence that a review happened on a stated cadence. Whichever you pick, the system holding your register has to represent all five or it will fail an audit of the risk program itself. That is the actual buying requirement, and it is why we built enterprise risk management software around the register rather than around dashboards.

Where the two diverge is what your review evidence has to show. COSO's review and revision component expects you to demonstrate that the program itself gets reassessed, not just individual risks, and its board standards mean director training and self-assessment records become part of the file. ISO 31000 is lighter on the paperwork and heavier on demonstrating that risk information actually reached the decision. If you are choosing tooling, ask the vendor to show you both: the audit trail on a single risk, and the audit trail on the framework review.

The treatments are where programs get real

One test tells you whether a register is a governance artifact or a working document: pick a financial risk line and read its treatment. "Monitor closely" means the line is decoration. A real treatment on a customer late-payment risk looks like a defined dunning sequence with escalation days and an owner, and in most finance teams that work is now handled by software that chases overdue invoices automatically rather than by someone remembering to send emails. Same test on a regulatory risk line: "track developments" is decoration, whereas naming the regulator, the docket and who gets alerted is a treatment.

This is the part neither framework can do for you, and it is where the difference between a compliant ERM program and a useful one lives. COSO and ISO both tell you to treat risks. Only your own operating discipline decides whether the treatment is a sentence or a mechanism.

How to decide this week

Ask three questions in order. Who is going to read our risk reporting, and what framework do they already expect? If the answer is an audit committee, a regulator or a parent company, that decides it. Second, how many hours a week does the risk function genuinely have? Under about ten, ISO 31000 is the realistic starting point regardless of what looks more impressive. Third, what is the register for, board assurance or operational decisions? COSO leans toward the first, ISO toward the second.

Then commit, in writing, in the risk policy, and stop revisiting it. Framework churn is a real cost and produces nothing a regulator values. If you want to see what the register looks like with the regulatory lines already populated for your sector, run the scan at the top of this page, or read how the underlying watch loop works on regulatory change management. If you are earlier than that and still shortlisting platforms, our best compliance software comparison and the buyer checklist cover the selection process itself.

Sources

  • COSO, Enterprise Risk Management framework (2017), five components and 20 principles; COSO, From Guidance to Action: Exploring Practical ERM (2026), coso.org.
  • COSO, Internal Control: Integrated Framework (2013), five components and 17 principles.
  • ISO 31000:2018, Risk management: Guidelines, second edition, eight principles, published as guidance rather than for certification; ISO 31010 for risk assessment techniques, iso.org.
  • Sarbanes-Oxley Act section 404 and SEC rules requiring management to identify the suitable recognized framework used in its internal control assessment.

General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.