COSO internal control vs. COSO ERM: What’s the difference?
Organizations may use both the COSO internal control framework and the COSO ERM framework, but they serve different purposes. Internal control focuses on establishing and evaluating controls that support organizational objectives. ERM connects risk with strategy and performance.
Understanding the difference between COSO internal control vs COSO ERM helps you decide where each framework fits and when it makes sense to use both.
COSO internal control vs. COSO ERM at a glance
| COSO internal control | COSO ERM | |
| Main focus | Internal controls | Enterprise risk management |
| Objectives | Operations, reporting, and compliance | Strategy, business objectives, and performance |
| Components | 5 | 5 |
| Principles | 17 | 20 |
| Primary use | Design and evaluate internal controls | Integrate risk with strategy and performance |
COSO originally issued its internal control integrated framework in 1992 and refreshed it in 2013. The ERM framework was first published in 2004 and updated in 2017 to emphasize the connection between risk, strategy, and performance.
COSO internal control vs. COSO ERM: Key differences
Here’s how COSO internal control and COSO ERM differ.
1. Purpose and focus
The main difference is what each framework is designed to help you manage. COSO internal control provides a structure for designing, implementing, and evaluating internal controls. It focuses on whether controls support objectives related to operations, reporting, and compliance.
COSO ERM takes a risk-focused view. It treats risk as part of strategy-setting and performance, not a separate activity.
For example, a company launching a new product might use ERM to assess how different risks could affect the strategy. It could then use internal controls to address specific risks within the resulting processes.
2. Objectives
The two frameworks also approach objectives differently. The COSO internal control framework groups objectives into three categories:
- Operations: Effectiveness and efficiency of operations.
- Reporting: Reliable internal and external reporting.
- Compliance: Adherence to applicable laws and regulations.
The ERM framework connects risk management with strategy and business objectives. It considers how risks may affect the organization’s ability to achieve those objectives and create, preserve, and realize value.
This distinction matters when defining the scope of a GRC program. A control review may ask whether a reporting process has the right approvals and checks. An ERM process may ask how a major risk could affect a strategic objective and what response is appropriate.
3. Approach to risk
Both frameworks address risk, but at different points. Under internal control, risk assessment helps identify and analyze risks that could prevent objectives from being achieved. Control activities then help management mitigate those risks.
ERM considers risk across strategy and performance. It can inform decisions about strategic objectives, risk responses, and changes in the organization’s risk profile. COSO describes ERM as a way to integrate risk management with strategy-setting and performance.
A simple way to see the difference is:
ERM: What risks could affect our strategy and objectives, and how should we respond?
Internal control: What controls help us manage risks and support our objectives?
4. Components
Each framework uses five components, but they address different activities.
| COSO internal control | COSO ERM |
| Control environment | Governance and culture |
| Risk assessment | Strategy and objective-setting |
| Control activities | Performance |
| Information and communication | Review and revision |
| Monitoring activities | Information, communication, and reporting |
The internal control framework has 17 principles across its five components. The ERM framework has 20 principles across its five components.
5. Assessment and monitoring
Internal control places specific emphasis on determining whether its five components are present and functioning. Monitoring can involve ongoing evaluations, separate evaluations, or both.
COSO ERM takes a broader view of change and performance. Its review and revision component considers how the organization reviews risk and performance and responds when substantial changes affect its strategy or risk profile.
So an internal control review might examine whether a control is operating as intended. An ERM review might examine whether a significant change has altered the risks associated with a strategic objective.
How COSO internal control and COSO ERM work together
You do not necessarily have to choose between the two frameworks. They can address different parts of the same risk and control process. Consider a company expanding into a new country.
ERM can help the organization:
- Identify risks associated with the expansion.
- Assess how those risks could affect strategic objectives.
- Consider possible risk responses.
- Monitor changes that could affect performance.
Internal control can then help establish controls around areas such as:
- Regulatory compliance.
- Financial reporting.
- Access to systems and information.
- Approvals and segregation of duties.
- Operational processes.
The two frameworks therefore have different roles without being separate from each other. ERM can help determine which risks require attention, while internal controls can help address specific risks within business processes.
When to use COSO internal control vs. COSO ERM
The right framework depends on what you are trying to achieve.
| Your main need | Relevant framework |
| Evaluate the effectiveness of internal controls | COSO internal control |
| Strengthen controls around reporting | COSO internal control |
| Integrate risk with performance | COSO ERM |
| Address operational and compliance objectives | COSO internal control |
| Connect risk with business strategy | COSO ERM |
| Assess strategic risks | COSO ERM |
| Manage enterprise risks while strengthening specific controls | Both |
How CyberArrow can support COSO risk and control management
Managing risks, controls, evidence, and assessments across separate spreadsheets and systems can make it harder to maintain a consistent view of your GRC program.
CyberArrow can help centralize these activities through automated risk assessments, continuous internal control monitoring, and evidence collection. It also supports enterprise risk management methodologies and comes with pre-mapped risks and mitigations across multiple GRC frameworks and standards.
With CyberArrow, you can:
- Monitor internal controls and control performance.
- Automate risk assessments and track mitigation.
- Collect evidence across connected systems.
- Monitor control thresholds and receive alerts.
- Use dashboards and reports to track GRC activities.
FAQs
What is the difference between COSO internal control and COSO ERM?
COSO internal control focuses on designing and evaluating internal controls that support operations, reporting, and compliance objectives. COSO ERM focuses on integrating risk with strategy and performance.
Is COSO ERM the same as internal control?
No. They are related but serve different purposes. ERM considers risk in relation to strategy and performance, while the Internal Control Framework provides a structure for designing and evaluating internal controls.
Can COSO internal control and COSO ERM be used together?
Yes. An organization can use ERM to consider risks in relation to strategy and performance and use internal controls to address specific risks within business processes.
Which COSO framework should an organization use?
It depends on the objective. Internal control is relevant when the focus is on controls supporting operations, reporting, and compliance. ERM is relevant when the focus is on integrating risk with strategy and performance. Organizations may use both when they need to address enterprise risk and specific controls.