COSO Enterprise Risk Management (ERM) Framework (2017)
Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Governance and Culture
The board provides oversight of strategy and carries out governance responsibilities to support management in achieving strategic and business objectives.
- Board charter
- Risk committee minutes
- Annual risk oversight report
- Director risk training records
- No documented risk oversight cadence
- Board minutes lack risk discussion evidence
The organization establishes operating structures in pursuit of strategy and business objectives.
- Org chart
- Delegation of authority matrix
- Operating model documentation
- RACI for risk roles
- Outdated org structure
- Unclear risk ownership
The organization defines desired behaviors that characterize its culture.
- Code of conduct
- Culture survey results
- Values statement
- Tone-at-the-top communications
- No culture measurement
- Values not embedded in performance reviews
The organization demonstrates a commitment to core values across all levels.
- Ethics training records
- Disciplinary action logs
- Whistleblower channel reports
- Annual ethics attestations
- No tracking of values violations
- Whistleblower channel underused
The organization is committed to building human capital aligned to strategy and business objectives.
- Talent strategy document
- Succession plans
- Competency frameworks
- Training program records
- No risk-specific competencies
- Succession gaps in risk roles
Information, Communication, and Reporting
The organization leverages information and technology to support enterprise risk management.
- GRC platform documentation
- Data quality controls
- Risk data dictionary
- System architecture
- Spreadsheet-only risk data
- Poor data quality
The organization uses communication channels to support enterprise risk management.
- Risk communication plan
- Internal newsletters
- Escalation procedures
- Stakeholder reporting cadence
- No defined escalation path
- Ad hoc communication
The organization reports on risk, culture, and performance at multiple levels and across the entity.
- Board risk reports
- Management dashboards
- Culture metrics report
- Annual risk report
- Reports not tailored to audience
- Culture metrics missing
Performance
The organization identifies risk that impacts the performance of strategy and business objectives.
- Risk register
- Risk workshop outputs
- Emerging risk log
- Risk identification methodology
- Static risk register
- Emerging risks not captured
The organization assesses the severity of risk.
- Likelihood-impact matrix
- Inherent vs residual risk ratings
- Scenario analysis
- Heatmaps
- Subjective scoring only
- No residual risk view
The organization prioritizes risks as a basis for selecting responses.
- Top risk list
- Prioritization criteria
- Velocity and persistence scoring
- Risk ranking model
- No documented prioritization rationale
- Top risks not refreshed
The organization identifies and selects risk responses.
- Risk treatment plans
- Action owner assignments
- Cost-benefit analyses
- Response options analysis
- Response chosen without analysis
- No owner or due date
The organization develops and evaluates a portfolio view of risk.
- Enterprise risk portfolio report
- Risk correlation analysis
- Aggregated exposure summary
- Siloed risk views
- No aggregation across units
Review and Revision
The organization identifies and assesses changes that may substantially affect strategy and business objectives.
- Change impact assessments
- Triggering event log
- Strategy refresh cycle docs
- No formal change-driven risk review
- Reactive only
The organization reviews entity performance and considers risk.
- Quarterly risk and performance dashboard
- KRI reports
- Performance reviews with risk overlay
- KRIs not defined
- Risk and performance reviewed separately
The organization pursues improvement of enterprise risk management.
- ERM maturity assessment
- Lessons learned log
- Improvement roadmap
- Internal audit ERM reviews
- No maturity benchmarking
- Improvements not tracked
Strategy and Objective-Setting
The organization considers potential effects of business context on risk profile.
- PESTLE analysis
- Industry trend reports
- Stakeholder analysis
- Scenario planning outputs
- No structured environment scanning
- Context analysis outdated
The organization defines risk appetite in the context of creating, preserving, and realizing value.
- Risk appetite statement
- Board approval records
- Risk tolerance thresholds
- Appetite cascade documentation
- Qualitative-only appetite
- Appetite not linked to KPIs
The organization evaluates alternative strategies and the potential impact on risk profile.
- Strategy options analysis
- Risk impact assessments per option
- Board strategy minutes
- Strategic plan
- Single strategy without alternatives evaluated
- No risk overlay on strategy
The organization considers risk while establishing business objectives at various levels that align and support strategy.
- Business plan
- Cascaded objectives
- Performance scorecards
- Objective-risk linkage matrix
- Objectives not measurable
- No risk linkage to objectives
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.