Established model
COSO Enterprise Risk Management
Committee of Sponsoring Organizations of the Treadway Commission · 2004
Also known as COSO ERM
Risk treated as part of setting and carrying out strategy, overseen by the board, rather than as a list kept by a specialist.
Its place in the frameworkBusiness Core›Governance
What it does
The first version extended internal control to risk across the whole enterprise; the 2017 revision went further and tied risk explicitly to strategy and performance, with governance and culture as its starting point. Its useful claim is that the largest risk is often the strategy itself — the chance that the chosen direction does not fit the organisation’s purpose or its appetite for risk.
- Reach for it when
- When the board receives a risk register every quarter and nothing in it has ever changed a decision.
- Where it stops
- It is broad and demanding, and easily reduced to a heat map that satisfies the auditors. It offers structure, not judgement about which risks are worth taking.
Committee of Sponsoring Organizations of the Treadway Commission, Enterprise Risk Management — Integrated Framework, 2004; Enterprise Risk Management — Integrating with Strategy and Performance, 2017. COSO is named here only to refer to its published work.
Why it sits at Governance
Who ultimately owns the business, who oversees it on their behalf, and how the risk carried by the whole organisation is held. The layer above management that management answers to.
A model is only useful when you reach for it at the right moment. This one answers a question that arises here — so it is filed here, and nowhere else. These are the working areas it serves:
- OwnershipBerle & Means, The Modern Corporation and Private Property (1932), on the separation of ownership and control; Jensen & Meckling, “Theory of the Firm: Managerial Behavior, Agency Costs and Ownership Structure” (1976).
- The boardCadbury Committee, Report on the Financial Aspects of Corporate Governance (1992); G20/OECD Principles of Corporate Governance (1999, revised 2023); Financial Reporting Council, UK Corporate Governance Code (2024).
- Enterprise riskCOSO, Enterprise Risk Management — Integrating with Strategy and Performance (2017); ISO 31000:2018, Risk management — Guidelines; Institute of Internal Auditors, The IIA’s Three Lines Model (2020).
- Succession and exitGersick, Davis, McCollom Hampton & Lansberg, Generation to Generation: Life Cycles of the Family Business (1997); Tagiuri & Davis, “Bivalent Attributes of the Family Firm” (1982, published 1996).
What it touches elsewhere
Nothing in a business is decided on its own. A conclusion reached with this model at Governance lands in these other cores, whether or not anyone follows it there.
- ComplianceRegulatory mapping, controls, monitoring and incident response sit in Compliance. Enterprise risk receives compliance risk as one input and weighs it against the rest; it neither designs nor tests the controls.
- PartnersPartners has its own Governance module, for the joint decisions inside one partnership. This object governs the organisation itself: a partnership’s steering group answers to management, and management answers here.
- OrganisationStructure and decision rights below the board belong to Organisation. The board delegates authority to the chief executive here; how that authority is then divided is settled there.
- StakeholdersOwners are one stakeholder group among several. Identifying and engaging stakeholders, and reporting to them, belongs in Stakeholders; this object holds only the owners’ formal rights and their mandate to the board.
- Contingency PlanningSlippage, buffers and fallback plans for the schedule are handled in Contingency Planning. A delay becomes an enterprise risk only where it threatens something the owners have set an appetite for.
- Data GovernanceOwnership, quality and permitted use of data are governed in Data Governance. The board sees data risk as an entry in the enterprise risk register, not as a separate regime.
- Goal CoreThe board approves the strategic goals, and the risk appetite sets how much may be staked on reaching them.
Filed at the same place
These answer questions that arise at Governance too. Where they disagree with this one, the disagreement is the useful part.
- The three lines modelWho owns a risk, who oversees it, and who independently checks both — kept as three distinct roles.
- ISO 31000 risk managementA common set of principles and a process for identifying, assessing, treating and monitoring risk.
- Agency theoryThose who run a company and those who own it want different things, and governance exists largely to manage the gap.
Elsewhere in Business Core
- Tuckman’s stages of group development
- Belbin Team Roles
- Herzberg’s two-factor theory
- Jobs to be done
- The Kano model
- The value proposition canvas
- The business model canvas
- The Van Westendorp price sensitivity meter
- Value-based pricing
- Core competence
- VRIO
- The resource-based view
- The theory of constraints
- Lean thinking
- Co-opetition and the value net
- Transaction cost economics
- Stakeholder theory
- The power–interest grid
- DuPont analysis
- Break-even and cost–volume–profit analysis
- Unit economics
- The Kraljic Matrix
- The bullwhip effect
- The SCOR Model
- On-time in-full
- Overall equipment effectiveness
- Value stream mapping
- Maslow’s hierarchy of needs
- Kotter’s eight-step change model
- Situational leadership
- The Lean Startup
- Design thinking
- Porter’s value chain
- The McKinsey 7S framework
- Six Sigma and DMAIC
- Stage-gate
- Beyond budgeting
- Dynamic capabilities
- Intangible assets
- The four S’s of intangible investment
- Net present value and discounted cash flow
- The Modigliani–Miller theorem
- The pecking order theory
- COSO Internal Control — Integrated Framework
- ISO 37301 compliance management systems
- Mintzberg’s organisational configurations
- The Star Model
- Lewin’s change model
- The ADKAR model
- Effectuation
- Open innovation
- The technology acceptance model
- The NIST Cybersecurity Framework
- The TOGAF Standard
- Wardley mapping
- Failure mode and effects analysis
These are other people’s models, named here so you can go to the source and use them properly. The Omnigoal is not affiliated with their authors and is not endorsed by them; nothing of theirs is reproduced here — no canvas, no diagram, no wording. Each is described in our own words, with the originator credited, because the framework is a place to put thinking, not a replacement for the people who did it. Model names and trademarks belong to their respective owners and are used here only to refer to the work itself.
All 166 models