COSO Enterprise Risk Management Framework: Benefits and Critiques
This paper examines the COSO Enterprise Risk Management Integrated Framework, developed by the Committee of Sponsoring Organizations of the Treadway Commission. It traces COSO's origins in the savings and loan crisis of the 1980s and its subsequent update following the Sarbanes-Oxley Act. The paper outlines COSO's core objectives—aligning risk appetite, reducing losses, and fostering an ethical organizational culture—before turning to substantive criticisms. Critics argue the framework is excessively vague, overly complex, and poorly suited to guiding Section 404 compliance. The paper also examines COBIT as an alternative and concludes that more targeted risk management research is needed.
- Introduction to COSO and Its Origins: COSO's creation, purpose, and historical context
- Core Objectives of Enterprise Risk Management: COSO's six core ERM goals defined
- COSO's Holistic, Principles-Based Approach: Portfolio-wide risk culture and ethics emphasis
- Criticism: Vagueness and the Rules vs. Principles Debate: Critics challenge COSO's lack of concrete standards
- Complexity and Section 404 Compliance Challenges: COSO's complexity hinders SOX Section 404 compliance
- Limited Adoption and the Search for Alternatives: Low COSO adoption and COBIT as alternative
- Conclusion: Framework gaps and need for further research
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- Balances explanation of the COSO framework with sustained critical analysis, presenting both advocates' and critics' perspectives fairly.
- Uses concrete analogies—such as comparing COSO to a "lifestyle guide for a healthy heart"—to make abstract regulatory concepts accessible.
- Grounds the critique in real-world evidence, including survey data on adoption rates and a reference to the 2008 financial crisis as a stress test of the framework.
Key academic technique demonstrated
The paper models argumentative balance by introducing the framework charitably before systematically dismantling its weaknesses. This move-then-counter structure—common in policy and regulatory analysis—prevents the essay from reading as one-sided advocacy, lending credibility to its ultimate conclusion that COSO is insufficient on its own.
Structure breakdown
The paper opens with COSO's historical context and definitional scope, then explains its holistic, principles-based philosophy. The middle sections present the two dominant criticisms—vagueness and complexity—followed by adoption statistics and a comparison with the alternative COBIT framework. The conclusion synthesizes these threads and calls for further research, following a classic problem-analysis-recommendation arc.
Introduction to COSO and Its Origins
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) created its internal control integrated framework to help enhance organizations' enterprise risk management systems while ensuring compliance with existing standards of ethics. At the time of its construction, a series of business scandals had raised "heightened concern and focus on risk management, and it became increasingly clear that a need exists for a robust framework to effectively identify, assess, and manage risk" (Flaherty & Mackey v). COSO was first instituted in the wake of the savings and loan debacle of the 1980s, when calls arose for greater and more transparent record-keeping on the part of organizations to protect both investors and shareholders (Shaw 1). Since its implementation, however, the wave of accounting-related scandals has failed to abate. COSO was updated and reformed in the 21st century following the passage of the Sarbanes-Oxley Act (SOX), but whether it has the necessary specificity to offer meaningful guidelines to organizations—guidelines sufficient to reduce risk, enhance growth, and ensure compliance with existing standards—remains debatable.
Core Objectives of Enterprise Risk Management
COSO defines enterprise risk management as responding to several core needs. The first is "aligning risk appetite and strategy," given that risk will vary from entity to entity (Flaherty & Mackey 1). ERM also means being more responsive to risk, ensuring that decisions are made to select the best possible response. In addition to reducing losses, risk management according to COSO entails proactively identifying surprises and being better able to identify risks across enterprises. It also means seizing opportunities to capitalize upon and more effectively deploying organizational capital (Flaherty & Mackey 1). Ideally, implementing COSO creates a more proactive and responsive organization that is agile enough to adapt to changes in the environment. Its lack of specificity regarding what constitutes risk is seen as a way to ensure that the framework remains applicable as the economy changes and can be equally appropriate to a wide variety of organizations.
COSO's Holistic, Principles-Based Approach
COSO views risk management as holistic in nature and as encompassing a unified strategy throughout the organization. "The framework emphasizes the importance of identifying and managing risks across the enterprise from a portfolio perspective. Many organizations perform risk management within each subdivision, but part of the overall vision of ERM is that the risks that occur in the subunits and sublevels of the entity are aggregated and viewed from the top as an overall portfolio of risk" (Chapman 3). It is a process-based theory and does not view internal controls as an end in and of themselves. Education of all employees is prioritized as a method of control, as all organizational participants must work to improve operations, reporting, and compliance.
There is a strong emphasis on creating a culture that takes an appropriate view of risk and embraces ethics in a positive fashion, rather than treating ethics as a threat to productivity. "Many frauds occur in companies that have excellent internal control systems because the corporate culture allows managers and employees to 'look the other way' and simply ignore that controls are being overridden" (Baggett 10). COSO's open-ended framework is guided by the concept that "attitudes are as important as systems" and that management must construct a belief system founded upon ethics (Baggett 10).
Conclusion
The lack of widespread use of COSO indicates that organizations have not found it satisfactory to fully address their needs, and find it both complicated and insufficiently well-defined. The concepts behind COSO—organizational education and broad-based principles to guide risk management—seem sound in theory. But even though principles-based accounting has become increasingly accepted, there remains a great deal of questioning of COSO's effectiveness, evidenced by the active search for alternative industry models. There is also no evidence that organizations that did implement COSO were any better at avoiding the pitfalls of the 2008 financial crisis (Leech 11). More research is needed to ensure that an effective risk management model is developed—one that is more protective of both organizations and investors.
References
Baggett, W. "Creating a Culture of Security." Internal Auditor. Jun 2003. Web. 17 Oct 2015.
Berkowitz, A. & Rampell, R. "The Accounting Debate: Principles Versus Rules." The Wall Street Journal. 2 Dec 2002.
Chapman, C. "Bringing ERM into Focus." Internal Auditor. Jun 2003. Web. 17 Oct 2015.
COSO & COBIT Center. SOX Online. Web. 17 Oct 2015.
Flaherty, J. & Maki, T. Enterprise Risk Management Integrated Framework. COSO. 2004. Web. 17 Oct 2015.
Leech, T. "The High Cost of ERM Herd Mentality." Risk Oversight White Paper. Mar 2011. Web. 17 Oct 2015.
Sarbanes-Oxley Act Section 404. A Guide to Sarbanes-Oxley. 2002. Web. 17 Oct 2015.
Shaw, H. "The Trouble with COSO." CFO. 2006. Web. 17 Oct 2015.
Create your account
Always verify citation format against your institution’s current style guide requirements.