COSO Enterprise Risk Management (ERM) framework
COSO ERM ties board level risk appetite decisions to strategy setting, requires KRI dashboards that form an auditable Evidence record, and mandates a review and revision component that closes the loop as ongoing Learning.
Committee of Sponsoring Organizations of the Treadway Commission (COSO), 2004
The origin of the framework, as the directory records it. The mark grades the origin, not this page.
Umbrex, COSO Enterprise Risk Management (ERM) framework
The directory entry this score was read from. Umbrex is a consultancy network; its summary is the reference, not a primary source.
Scored against the twelve cells, it loads four: Authority, Strategy, Evidence, and Learning. The other eight it leaves to you. Of Composition, Evidence, and Mastery, the three cells that go blank first when an agent enters a workflow, it loads Evidence.
Original framework published 2004; current version, Enterprise Risk Management Integrating with Strategy and Performance, published 2017.
This is not a summary of the framework. Umbrex has one; the link under Sources goes there.
Which decisions may an agent make alone, and who is able to stop it?
Where on the evolution curve does each capability sit, and does that dictate build, buy, or let go?
What would you show an auditor, and can the system produce it without being asked?
How does tacit judgment become reusable, and who owns the loop that has to close?
