Skip to content

Evidence request lists

COSO Enterprise Risk Management (ERM) Framework (2017)

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Governance and Culture

GOV-1
Exercises Board Risk Oversight

The board provides oversight of strategy and carries out governance responsibilities to support management in achieving strategic and business objectives.

Artefacts an auditor will ask for
  • Board charter
  • Risk committee minutes
  • Annual risk oversight report
  • Director risk training records
Where this commonly fails
  • No documented risk oversight cadence
  • Board minutes lack risk discussion evidence
GOV-2
Establishes Operating Structures

The organization establishes operating structures in pursuit of strategy and business objectives.

Artefacts an auditor will ask for
  • Org chart
  • Delegation of authority matrix
  • Operating model documentation
  • RACI for risk roles
Where this commonly fails
  • Outdated org structure
  • Unclear risk ownership
GOV-3
Defines Desired Culture

The organization defines desired behaviors that characterize its culture.

Artefacts an auditor will ask for
  • Code of conduct
  • Culture survey results
  • Values statement
  • Tone-at-the-top communications
Where this commonly fails
  • No culture measurement
  • Values not embedded in performance reviews
GOV-4
Demonstrates Commitment to Core Values

The organization demonstrates a commitment to core values across all levels.

Artefacts an auditor will ask for
  • Ethics training records
  • Disciplinary action logs
  • Whistleblower channel reports
  • Annual ethics attestations
Where this commonly fails
  • No tracking of values violations
  • Whistleblower channel underused
GOV-5
Attracts, Develops, and Retains Capable Individuals

The organization is committed to building human capital aligned to strategy and business objectives.

Artefacts an auditor will ask for
  • Talent strategy document
  • Succession plans
  • Competency frameworks
  • Training program records
Where this commonly fails
  • No risk-specific competencies
  • Succession gaps in risk roles

Information, Communication, and Reporting

INFO-18
Leverages Information and Technology

The organization leverages information and technology to support enterprise risk management.

Artefacts an auditor will ask for
  • GRC platform documentation
  • Data quality controls
  • Risk data dictionary
  • System architecture
Where this commonly fails
  • Spreadsheet-only risk data
  • Poor data quality
INFO-19
Communicates Risk Information

The organization uses communication channels to support enterprise risk management.

Artefacts an auditor will ask for
  • Risk communication plan
  • Internal newsletters
  • Escalation procedures
  • Stakeholder reporting cadence
Where this commonly fails
  • No defined escalation path
  • Ad hoc communication
INFO-20
Reports on Risk, Culture, and Performance

The organization reports on risk, culture, and performance at multiple levels and across the entity.

Artefacts an auditor will ask for
  • Board risk reports
  • Management dashboards
  • Culture metrics report
  • Annual risk report
Where this commonly fails
  • Reports not tailored to audience
  • Culture metrics missing

Performance

PERF-10
Identifies Risk

The organization identifies risk that impacts the performance of strategy and business objectives.

Artefacts an auditor will ask for
  • Risk register
  • Risk workshop outputs
  • Emerging risk log
  • Risk identification methodology
Where this commonly fails
  • Static risk register
  • Emerging risks not captured
PERF-11
Assesses Severity of Risk

The organization assesses the severity of risk.

Artefacts an auditor will ask for
  • Likelihood-impact matrix
  • Inherent vs residual risk ratings
  • Scenario analysis
  • Heatmaps
Where this commonly fails
  • Subjective scoring only
  • No residual risk view
PERF-12
Prioritizes Risks

The organization prioritizes risks as a basis for selecting responses.

Artefacts an auditor will ask for
  • Top risk list
  • Prioritization criteria
  • Velocity and persistence scoring
  • Risk ranking model
Where this commonly fails
  • No documented prioritization rationale
  • Top risks not refreshed
PERF-13
Implements Risk Responses

The organization identifies and selects risk responses.

Artefacts an auditor will ask for
  • Risk treatment plans
  • Action owner assignments
  • Cost-benefit analyses
  • Response options analysis
Where this commonly fails
  • Response chosen without analysis
  • No owner or due date
PERF-14
Develops Portfolio View

The organization develops and evaluates a portfolio view of risk.

Artefacts an auditor will ask for
  • Enterprise risk portfolio report
  • Risk correlation analysis
  • Aggregated exposure summary
Where this commonly fails
  • Siloed risk views
  • No aggregation across units

Review and Revision

REV-15
Assesses Substantial Change

The organization identifies and assesses changes that may substantially affect strategy and business objectives.

Artefacts an auditor will ask for
  • Change impact assessments
  • Triggering event log
  • Strategy refresh cycle docs
Where this commonly fails
  • No formal change-driven risk review
  • Reactive only
REV-16
Reviews Risk and Performance

The organization reviews entity performance and considers risk.

Artefacts an auditor will ask for
  • Quarterly risk and performance dashboard
  • KRI reports
  • Performance reviews with risk overlay
Where this commonly fails
  • KRIs not defined
  • Risk and performance reviewed separately
REV-17
Pursues Improvement in ERM

The organization pursues improvement of enterprise risk management.

Artefacts an auditor will ask for
  • ERM maturity assessment
  • Lessons learned log
  • Improvement roadmap
  • Internal audit ERM reviews
Where this commonly fails
  • No maturity benchmarking
  • Improvements not tracked

Strategy and Objective-Setting

STR-6
Analyzes Business Context

The organization considers potential effects of business context on risk profile.

Artefacts an auditor will ask for
  • PESTLE analysis
  • Industry trend reports
  • Stakeholder analysis
  • Scenario planning outputs
Where this commonly fails
  • No structured environment scanning
  • Context analysis outdated
STR-7
Defines Risk Appetite

The organization defines risk appetite in the context of creating, preserving, and realizing value.

Artefacts an auditor will ask for
  • Risk appetite statement
  • Board approval records
  • Risk tolerance thresholds
  • Appetite cascade documentation
Where this commonly fails
  • Qualitative-only appetite
  • Appetite not linked to KPIs
STR-8
Evaluates Alternative Strategies

The organization evaluates alternative strategies and the potential impact on risk profile.

Artefacts an auditor will ask for
  • Strategy options analysis
  • Risk impact assessments per option
  • Board strategy minutes
  • Strategic plan
Where this commonly fails
  • Single strategy without alternatives evaluated
  • No risk overlay on strategy
STR-9
Formulates Business Objectives

The organization considers risk while establishing business objectives at various levels that align and support strategy.

Artefacts an auditor will ask for
  • Business plan
  • Cascaded objectives
  • Performance scorecards
  • Objective-risk linkage matrix
Where this commonly fails
  • Objectives not measurable
  • No risk linkage to objectives
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.