Enterprise risk management represents one of the most significant evolutions in how organizations think about uncertainty, moving from siloed approaches where different departments manage their own risks in isolation toward integrated frameworks that recognize how risks interact, compound, and create both threats and opportunities across an entire organization. For Canadian organizations operating in an increasingly complex environment characterized by supply chain disruptions, cybersecurity threats, regulatory changes, and climate-related uncertainties, understanding the major frameworks that guide enterprise risk management has become essential rather than optional. Two frameworks dominate professional practice globally and within Canada: the Committee of Sponsoring Organizations of the Treadway Commission framework, commonly known as COSO, and the International Organization for Standardization's ISO 31000 standard. While these frameworks share fundamental principles, they differ in structure, emphasis, and practical application in ways that matter significantly for Canadian small and medium businesses, non-profits, and professional service firms attempting to build coherent risk management practices.
The COSO framework emerged from concerns about financial reporting and internal controls following corporate scandals in the United States during the early 2000s. Originally focused on internal control, COSO expanded in 2004 to address enterprise risk management comprehensively, and its most recent major update, released in 2017 under the title Enterprise Risk Management—Integrating with Strategy and Performance, reflects a contemporary understanding that risk management cannot be separated from strategic planning and operational execution. COSO conceptualizes enterprise risk management as comprising five interrelated components: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication, and reporting. These components work together across an organization's entity structure, from subsidiary operations through divisions to the enterprise level. For Canadian publicly traded companies and organizations subject to securities regulation, COSO's integration with financial reporting and internal control concepts makes it particularly relevant because Canadian securities administrators across all provinces and territories require public companies to maintain effective disclosure controls and internal controls over financial reporting. While the specific requirements vary slightly between the Canadian Securities Administrators' national instruments and the frameworks referenced in those instruments, COSO provides a recognized methodology for designing and evaluating these controls.