Comparing COSO and the ISO 31000
Risks are a normal part of doing business. But if you ignore them, they can undermine the sustainability of your accounting firm. For instance, the risk of a cyber-attack can increase the chances that your firm will lose valuable data and clients, as well as have to settle expensive lawsuits.
Luckily, there are a variety of standardized risk management frameworks that can give you control over your firm's risk landscapes. Ideally, the ISO 31000 and the COSO ERM guidelines are the best ERM frameworks. Here is a comparison of the two guidelines, as well as how your business can leverage them in improving your daily operations.
What is COSO?
COSO was invented by five professional associations: The American Accounting Organization, The Institute of Management Accountants, American Institute of Certified Public Accountants, Financial Executives International, and the Institute of Internal Auditors.
As an ERM framework, COSO is meant to provide guidelines for enterprise risk management implementation.
What is the ISO?
The ISO (International Organization for Standardization) is a global organization that looks to set operational standards for different industries. While it was formed by 25 countries in February 1947, it aims at standardizing issues that cut across industries. Ideally, the ISO 31000 tends to be among the many guidelines that the ISO has made over the years.
The COSO ERM framework in a nutshell
The COSO ERM (Enterprise Risk Management-integrated Framework), which was updated in 2016, acts as a standardized ERM framework that defines the intricacies of various internal control and corporate risk management concepts.
Some of the framework's main objectives include defining essential ERM components, establishing a common language, and providing participating bodies with an ERM guiding document.
The framework has five components:
Strategic and objective setting: requires firms to set measurable goals as they draft their risk tolerance strategies.
Information, communication, and reporting: requires internal and external stakeholders to maintain high levels of effective communication.
Performance: it requires participating bodies to implement effective risk prioritization and reporting.
Governance and culture: requires ERM-related oversight to be done on a day to day basis within participating entities.
Review and revision: It outlines how firms can measure the effectiveness of their internal controls through auditing, evaluation, and monitoring. It also showcases how to improve these aspects.

:format(avif))

:format(jpeg))
:format(jpeg))
:format(jpeg))
:format(jpeg))