Risk Frameworks and Standards (COSO ERM, ISO 31000)
In the CGEIT domain of Risk Optimization, risk frameworks and standards give governance professionals a structured, repeatable way to make sure IT-related risk is identified, assessed, and managed within the enterprise's risk appetite. The two most widely referenced are COSO ERM and ISO 31000. COS… In the CGEIT domain of Risk Optimization, risk frameworks and standards give governance professionals a structured, repeatable way to make sure IT-related risk is identified, assessed, and managed within the enterprise's risk appetite. The two most widely referenced are COSO ERM and ISO 31000. COSO ERM (2017), titled Enterprise Risk Management: Integrating with Strategy and Performance, was issued by the Committee of Sponsoring Organizations of the Treadway Commission. It presents risk management as part of strategy setting and performance management rather than a separate compliance activity. It has five interrelated components supported by 20 principles: 1. Governance and Culture: board risk oversight, operating structures, and ethical values. 2. Strategy and Objective-Setting: business context, risk appetite, and alignment of objectives. 3. Performance: identifying, assessing, prioritizing, and responding to risks. 4. Review and Revision: monitoring significant changes and improving ERM. 5. Information, Communication, and Reporting: using information and technology to report on risk, culture, and performance. COSO is especially influential in organizations subject to regulatory and financial-reporting expectations, such as SOX. ISO 31000:2018 is an international, non-certifiable standard that provides generic guidelines applicable to any organization. It has three parts: 1. Principles: risk management should be integrated, structured and comprehensive, customized, inclusive, dynamic, based on the best available information, attentive to human and cultural factors, and continually improved. Its core purpose is creating and protecting value. 2. Framework: leadership and commitment, integration, design, implementation, evaluation, and improvement. 3. Process: communication and consultation; scope, context, and criteria; risk assessment (identification, analysis, evaluation); risk treatment; monitoring and review; and recording and reporting. For CGEIT candidates, the key point is that these frameworks complement IT governance frameworks such as COBIT and ISACA's Risk IT. Together they help connect IT risk to enterprise objectives, define risk appetite and tolerance, assign accountability, and give the board consistent risk reporting. A governance professional should select and tailor these frameworks to the organization's context. They should not be applied mechanically. The goal is to optimize risk, balancing value creation against acceptable risk levels.
Risk Frameworks and Standards (COSO ERM, ISO 31000) for CGEIT: A Complete Guide to Risk Optimization
Introduction
Risk Optimization is one of the core domains of the ISACA CGEIT (Certified in the Governance of Enterprise IT) certification. In this domain, candidates must show that they can make sure IT-related risk is identified, assessed, managed and reported in line with the enterprise's risk appetite. Two internationally recognized references underpin this work: COSO Enterprise Risk Management (ERM) and ISO 31000. CGEIT does not test them as memorization exercises. It tests whether you understand how they help governance bodies embed risk management into strategy, decision-making and value creation.
Why Risk Frameworks and Standards Are Important
From a governance perspective, risk frameworks matter for several reasons:
1. Common language and consistency: A recognized framework gives the board, executives, business units and IT one shared vocabulary for risk. Terms such as risk appetite, risk tolerance, inherent risk and residual risk mean the same thing to everyone. This prevents IT risk from being treated as a purely technical, isolated problem.
2. Alignment with strategy: Modern frameworks, especially COSO ERM 2017, stress that risk is linked to strategy and performance. Governance of enterprise IT seeks benefits realization at an acceptable level of risk, so frameworks help ensure IT investments and operations support enterprise objectives without exposing the organization to unacceptable risk.
3. Board accountability and oversight: Boards are responsible for overseeing risk. Frameworks set out roles, responsibilities and reporting structures so that directors can fulfil their fiduciary duties and demonstrate due care.
4. Integration of IT risk into enterprise risk: CGEIT strongly emphasizes that IT risk is a business risk. Frameworks such as COSO ERM and ISO 31000 provide the enterprise-wide umbrella. IT-specific frameworks such as COBIT and ISACA's Risk IT (now integrated into COBIT 2019 guidance) plug into that umbrella.
5. Regulatory and stakeholder expectations: Regulators, auditors, investors and rating agencies increasingly expect a structured, documented approach to risk. Adopting recognized standards demonstrates maturity and builds stakeholder confidence.
6. Better decision-making: A structured process leads to informed, risk-aware decisions. Organizations can take on more of the right risks to create value and avoid the wrong ones.
What They Are
1. COSO ERM (Enterprise Risk Management: Integrating with Strategy and Performance, 2017)
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) first issued its ERM Integrated Framework in 2004. The 2004 version was shown as a cube with eight components:
Internal environment, objective setting, event identification, risk assessment, risk response, control activities, information and communication, and monitoring.
Its four objective categories were:
Strategic, operations, reporting, and compliance.
The 2017 update reframed ERM as the culture, capabilities and practices, integrated with strategy-setting and its execution, that organizations rely on to manage risk in creating, preserving and realizing value.
It is organized into five interrelated components supported by 20 principles:
a. Governance and Culture: board risk oversight, operating structures, desired culture, commitment to core values, and attracting, developing and retaining capable people.
b. Strategy and Objective-Setting: analyzing business context, defining risk appetite, evaluating alternative strategies, and formulating business objectives.
c. Performance: identifying risk, assessing severity, prioritizing risks, implementing risk responses, and developing a portfolio view.
d. Review and Revision: assessing substantial change, reviewing risk and performance, and pursuing improvement in ERM.
e. Information, Communication and Reporting: leveraging information and technology, communicating risk information, and reporting on risk, culture and performance.
Key ideas in COSO ERM 2017:
- Risk is considered in strategy selection, not only in strategy execution.
- Risk appetite is central and must be set and approved by the board and senior management.
- A portfolio view of risk lets the enterprise see aggregate exposure.
- Both the possibility of strategy not aligning with mission and the implications of the chosen strategy are considered.
- Culture and governance form the foundation.
2. ISO 31000 (Risk Management Guidelines, 2009, revised 2018)
ISO 31000 is an international standard of generic guidelines for managing risk. It applies to any organization, sector or type of risk. It is not certifiable: it is guidance, not a set of requirements for certification. It defines risk as the effect of uncertainty on objectives, and that effect can be positive or negative.
ISO 31000:2018 has three main elements:
a. Principles (8 principles; the purpose is the creation and protection of value):
- Integrated
- Structured and comprehensive
- Customized
- Inclusive
- Dynamic
- Best available information
- Human and cultural factors
- Continual improvement
b. Framework (based on a Plan-Do-Check-Act style cycle with Leadership and Commitment at the center):
- Leadership and commitment
- Integration
- Design
- Implementation
- Evaluation
- Improvement
c. Process:
- Communication and consultation (continuous)
- Scope, context and criteria
- Risk assessment, made up of risk identification, risk analysis and risk evaluation
- Risk treatment
- Monitoring and review (continuous)
- Recording and reporting
Related standards include ISO 31010 (risk assessment techniques), ISO Guide 73 (risk management vocabulary) and ISO/IEC 27005 (information security risk management, aligned with ISO 31000).
3. How They Relate to IT-Specific Frameworks
- COBIT 2019: The governance objective EDM03 Ensured Risk Optimization and the management objective APO12 Managed Risk deal directly with IT risk. COBIT is designed to align with enterprise frameworks such as COSO ERM and ISO 31000.
- Risk IT (ISACA): Its domains are Risk Governance, Risk Evaluation and Risk Response. It bridges enterprise risk management and IT risk management.
- NIST frameworks (e.g., NIST SP 800-30, 800-37, CSF): These are more technical and IT-focused.
How It Works in Practice
A typical governance-driven risk management lifecycle combining these frameworks looks like this:
1. Establish governance and culture: The board sets the tone at the top. It defines oversight structures such as a risk committee, assigns accountability (for example, a CRO and risk owners) and promotes a risk-aware culture.
2. Define context and risk appetite: The enterprise analyzes its internal and external context, including stakeholders, regulation, technology and competitors. The board approves a risk appetite statement, which is the amount and type of risk the organization is willing to pursue or retain. Management then translates it into risk tolerances, the acceptable variation around objectives.
3. Integrate with strategy and objectives: Strategic options, including major IT initiatives such as cloud migration, AI adoption or ERP replacement, are evaluated against risk appetite before approval.
4. Identify risks: Risk scenarios, workshops, interviews, checklists and analysis of loss events are used to identify risks to objectives. In IT, risk scenarios are a key tool in Risk IT/COBIT.
5. Analyze and evaluate: Likelihood and impact (severity) are assessed using qualitative, semi-quantitative or quantitative methods. Inherent risk (before controls) and residual risk (after controls) are determined, and risks are compared to the risk criteria and appetite.
6. Respond and treat: The standard response options are:
- Avoid: stop the activity.
- Mitigate/Reduce: implement controls.
- Transfer/Share: use insurance or outsourcing, though accountability remains with the organization.
- Accept: retain the risk within appetite, with formal sign-off.
ISO 31000 also notes that a risk may be pursued, taking or increasing risk to pursue an opportunity. COSO 2017 uses the terms accept, avoid, pursue, reduce and share.
7. Portfolio view and aggregation: Risks are aggregated across the enterprise. Interdependencies and concentrations are identified so the board sees the total risk profile.
8. Monitor, review and report: Key Risk Indicators (KRIs), risk registers, dashboards and heat maps support ongoing oversight. Reports go to the board and the risk committee. Changes in context, such as new regulations or technology shifts, trigger reassessment.
9. Continual improvement: The framework itself is evaluated and improved periodically, for example through maturity assessments and lessons learned from incidents.
Key Terminology to Master
- Risk appetite: the broad level of risk the enterprise is willing to accept in pursuit of value. It is set by the board.
- Risk tolerance: the acceptable deviation from the level set by risk appetite. It is more granular and operational.
- Risk capacity: the maximum risk the enterprise can absorb without threatening its existence.
- Inherent risk: risk before controls.
- Residual risk: risk remaining after treatment.
- Risk owner: the person accountable for managing a specific risk. This is usually a business owner, not IT.
- Risk profile: the overall picture of risks the enterprise faces.
- Risk register: the documented record of identified risks, assessments, owners and responses.
- KRI: a metric that provides early warning of increasing risk exposure.
COSO ERM vs. ISO 31000: Key Differences
- Origin: COSO is US-based and has historically been linked to internal control and financial reporting (Sarbanes-Oxley context). ISO 31000 is international and generic.
- Structure: COSO has 5 components and 20 principles. ISO 31000 has principles, a framework and a process.
- Emphasis: COSO 2017 emphasizes integration with strategy and performance. ISO 31000 emphasizes a flexible, adaptable process applicable to any organization.
- Certification: Neither is certifiable in the formal sense. ISO 31000 is explicitly guidance.
- Definition of risk: COSO 2017 defines risk as the possibility that events will occur and affect the achievement of strategy and business objectives. ISO defines it as the effect of uncertainty on objectives.
- Commonality: Both treat risk as having both upside and downside. Both stress leadership, integration, culture, continuous monitoring and value creation.
Exam Tips: Answering Questions on Risk Frameworks and Standards (COSO ERM, ISO 31000)
1. Think like a board member, not a technician.
CGEIT is a governance exam. When a question asks what should be done first or what is most important, the best answer usually involves governance-level actions. Examples include defining risk appetite, aligning with enterprise objectives, assigning accountability or securing executive sponsorship. Implementing a specific technical control is rarely the best answer.
2. Risk appetite comes from the board.
Questions often test who sets risk appetite. The answer is the board of directors, or senior management with board approval. IT management, the CIO or the CISO do not set enterprise risk appetite. They operate within it.
3. IT risk is a business risk.
Prefer answers that integrate IT risk into the enterprise risk management program over answers that build a separate, standalone IT risk process. If an option says integrate IT risk management with the enterprise ERM framework, it is very likely correct.
4. Business owns the risk.
Risk ownership typically sits with business process owners or executives accountable for the affected objectives. IT is often the custodian or implementer of controls, not the risk owner.
5. Know the sequence.
Many questions test order. Context or objective-setting comes before identification. Identification comes before analysis, analysis before evaluation and evaluation before treatment. Monitoring, communication and consultation are continuous throughout. If asked what comes first when implementing a framework, look for leadership commitment, a mandate, or understanding the context and objectives.
6. Transfer does not transfer accountability.
When risk is shared through insurance or outsourcing, the enterprise remains accountable. Expect distractor answers suggesting otherwise.
7. Accepting risk requires formal approval within appetite.
Risk acceptance must be documented and approved by someone with the appropriate authority. If residual risk exceeds appetite, it must be escalated or treated further.
8. Look for value and strategy alignment.
COSO 2017 and ISO 31000 both link risk to value creation and objectives. When choosing between answers, favour the one that connects risk management to the achievement of enterprise objectives and value.
9. Distinguish appetite, tolerance and capacity.
Appetite is a strategic and broad statement. Tolerance is the acceptable variance and is more specific. Capacity is the absolute maximum the organization can absorb. Exam distractors often swap these terms.
10. Selecting a framework: customize, don't copy.
ISO 31000 emphasizes that risk management should be customized. If a question asks about adopting a framework, the best answer usually involves tailoring it to the enterprise's context, size, culture and objectives rather than implementing it verbatim.
11. Culture and tone at the top.
If a question describes an organization where risk processes exist but are ignored, the root cause is often culture, leadership commitment or accountability. The fix is rarely more documentation or more tools.
12. Portfolio view and aggregation.
When asked how the board can best understand overall exposure, look for answers about an aggregated, enterprise-wide risk profile or portfolio view. Individual project-level risk registers alone are not the answer.
13. Reporting should be meaningful to the audience.
Board reporting should be concise, business-oriented and focused on key risks versus appetite, trends and KRIs. Detailed technical vulnerability lists are not appropriate for the board.
14. Recognize key words in questions.
Words such as MOST, BEST, FIRST, PRIMARY and GREATEST signal that several answers may be partially correct. Choose the one with the broadest governance impact and strongest alignment to enterprise objectives.
15. Map frameworks to the COBIT governance model.
Remember that EDM03 (Ensured Risk Optimization) is the governance objective, covering evaluate, direct and monitor by the board. APO12 (Managed Risk) is the management objective. Governance sets direction and appetite. Management executes within it.
Sample Question Walkthrough
Question: An enterprise is implementing an ERM program based on COSO ERM. Which of the following should be done FIRST to ensure IT risk is managed effectively?
A. Deploy a GRC tool to track IT risks
B. Define the enterprise risk appetite and integrate IT risk into it
C. Conduct a vulnerability assessment of critical systems
D. Purchase cyber insurance
Answer: B. Risk appetite is foundational under COSO ERM's Strategy and Objective-Setting component. Without it, there are no criteria for evaluating or responding to risk. The other options are tactical activities that depend on appetite having been defined first.
Summary
COSO ERM and ISO 31000 give enterprises structured, recognized approaches to managing risk in support of strategy and value creation. For CGEIT, the key is to view these frameworks through a governance lens:
- The board sets risk appetite and provides oversight.
- IT risk is integrated into enterprise risk.
- The business owns its risks.
- Risk management is continuous, customized and embedded in decision-making.
If you master the components, principles, process steps and terminology, and consistently choose answers that reflect strategic alignment, accountability and value, you will be well prepared to answer risk framework questions on the CGEIT exam.
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!