Compliance guide · 12 min read

Risk Management Frameworks: A Practical Guide

Compare COSO ERM, ISO 31000, NIST RMF, and COBIT — and learn how to operationalize them alongside the day-to-day compliance obligations your team already tracks.

Why frameworks matter

A risk management framework is the connective tissue between strategy and execution. Without one, risk conversations happen in silos: finance owns fraud risk, legal owns regulatory risk, IT owns cyber, and operations owns everything else. A framework gives every team the same taxonomy, the same scoring scale, and the same escalation path — so risks can be compared, prioritized, and retired against a common standard.

The four frameworks below account for the vast majority of enterprise risk programs. Each has a different center of gravity. Picking the right one — or the right combination — depends on your industry, your regulator, and how mature your existing controls already are.

COSO ERM (2017)

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) publishes the most widely adopted enterprise risk management framework in North America. The 2017 update, Enterprise Risk Management — Integrating with Strategy and Performance, reframes risk as inseparable from strategy: risk appetite is defined at the board level and cascades into every operating decision.

COSO ERM organizes its guidance into five interrelated components:

  • Governance and culture — the board's oversight role and the tone it sets.
  • Strategy and objective-setting — aligning risk appetite with strategic choices.
  • Performance — identifying, assessing, and prioritizing risks against objectives.
  • Review and revision — monitoring performance and adjusting as conditions change.
  • Information, communication, and reporting — the flow of risk data across the enterprise.

Use COSO ERM when: you report to a U.S. board of directors, you're publicly traded, or your auditors are expecting a SOX-aligned narrative that ties risk directly to financial reporting.

ISO 31000 (2018)

ISO 31000 is the international standard for risk management. It is deliberately shorter and more principles-based than COSO — 16 pages of substance versus COSO's several hundred. Rather than prescribing a process, it defines eight principles that any well-run risk program should exhibit (it should be integrated, structured, tailored, inclusive, dynamic, best-available-information based, human-and-cultural, and continually improving) and a simple three-part model: framework, process, and principles.

The ISO 31000 process itself is a familiar loop: establish the context → identify risks → analyze → evaluate → treat → monitor and review → communicate and consult. Because it is process-agnostic and regulator-neutral, ISO 31000 travels well across jurisdictions and pairs cleanly with sector-specific standards (ISO 27001 for information security, ISO 22301 for continuity, etc.).

Use ISO 31000 when: you operate internationally, you already run other ISO management systems, or you want a lightweight spine you can extend rather than a heavyweight framework you have to wrestle down to size.

NIST Risk Management Framework

The NIST RMF (Special Publication 800-37) is the U.S. federal standard for managing information security and privacy risk. It is mandatory for federal agencies and their contractors and is the de facto standard for any organization pursuing FedRAMP, CMMC, or FISMA authorization.

Its seven steps are prescriptive by design:

  1. Prepare — organizational and system-level readiness.
  2. Categorize — classify the system by impact (low, moderate, high).
  3. Select — choose baseline controls from NIST SP 800-53.
  4. Implement — deploy the selected controls.
  5. Assess — verify the controls are working as intended.
  6. Authorize — a senior official accepts residual risk and grants an ATO.
  7. Monitor — continuous monitoring against defined metrics.

Use the NIST RMF when: you sell to the U.S. government, you handle Controlled Unclassified Information, or your customers expect a mapping to NIST SP 800-53 controls in your security questionnaire responses.

COBIT 2019

COBIT (Control Objectives for Information and Related Technologies), maintained by ISACA, is the leading framework for the governance and management of enterprise IT. Where NIST RMF is control-focused, COBIT is decision-focused — it defines who owns which IT decision, what good governance looks like, and how to measure whether IT is delivering value against the risks it introduces.

COBIT 2019 splits its 40 governance and management objectives across five domains: Evaluate, Direct, and Monitor (EDM) for governance; plus Align/Plan/Organize, Build/Acquire/Implement, Deliver/Service/ Support, and Monitor/Evaluate/Assess for management.

Use COBIT when: you need to demonstrate IT governance maturity to auditors, you're aligning IT investment with business strategy, or you're pairing it with ITIL for service management.

Choosing (or combining) frameworks

Most mature programs don't pick one framework — they layer them. A common enterprise stack looks like this:

  • COSO ERM at the board and audit-committee level for strategic and financial risk.
  • ISO 31000 as the day-to-day operational risk process across business units.
  • NIST RMF or ISO 27001 for information security and technology risk.
  • COBIT for IT governance and to bridge business-technology accountability.

The frameworks are complementary, not competitive. What matters is that risks identified anywhere in the stack are recorded in one place, scored on one scale, and assigned to a named owner with a due date.

From framework to obligation

Frameworks describe how risk should be managed. Compliance obligations are what actually gets managed — the licenses that expire, the certifications that must be renewed, the policies that require annual attestation, the controls that need quarterly evidence. A framework without an obligation ledger is a binder on a shelf; an obligation ledger without a framework is a to-do list without priorities.

This is where Vurtti fits. Every risk-treatment decision your framework produces — implement a control, transfer risk to insurance, renew a certification, monitor a vendor — becomes an obligation with an owner, a due date, evidence, and an audit trail. When your auditor asks "how do you manage cyber risk," you don't reach for a PDF; you export the live register.

Getting started

Whichever framework you adopt, the first 90 days look the same:

  1. Inventory the obligations you already have — licenses, contracts, policies, certifications, regulatory filings.
  2. Map each obligation to a risk category the framework recognizes.
  3. Assign a single accountable owner to every obligation.
  4. Set a review cadence that matches the obligation's risk level, not the calendar year.
  5. Publish the register so leadership can see it without asking.

If you're operationalizing any of these frameworks and need a system of record for the obligations they produce, take a look at Vurtti's pricing or talk to us about your program.