
October 8, 2026 • 12 min read
ISO 31000 vs. COSO ERM vs. NIST RMF: How to compare and combine the frameworks
If your company files SOX 404 attestations, holds federal contracts, and operates in several countries, your risk program probably answers to ISO 31000, COSO ERM, and the NIST Risk Management Framework (RMF) at the same time. Each framework has its own terminology and documentation requirements, and each answers to a different reviewer, such as the audit committee for COSO or the authorizing official for a NIST system.
The harder work starts after you know which frameworks apply. When audit, compliance, and security teams each maintain their own framework mapping, the same access control gets tested two or three times. Control owners field repeat evidence requests, and the board receives risk reports that do not reconcile.
This guide compares ISO 31000, COSO ERM, and the NIST RMF on scope, structure, assurance expectations, and operational burden, then covers the combinations enterprises use most often.
ISO 31000, COSO ERM, and the NIST RMF each govern a different layer of risk management, so most enterprise programs need a combination of them mapped to one shared set of risks and controls.
ISO 31000 vs.COSO ERM vs. NIST RMF: What each framework is for
ISO 31000: A general guideline for any risk type
ISO 31000 is an international guideline for managing any type of risk in any organization, published by the International Organization for Standardization. The current edition, the ISO 31000:2018 risk management guideline, covers financial, operational, strategic, and reputational risk.
ISO 31000 is a guideline, so no one can certify your organization against it. Its value is a shared vocabulary and a repeatable process for identifying, analyzing, evaluating, and treating risk across business units and regions.
Because it prescribes so little, ISO 31000 leaves control selection, evidence standards, and reporting formats for your team to define.
COSO ERM: Risk tied to strategy and performance
COSO ERM is an enterprise risk management framework that ties risk appetite to strategy and performance. The Committee of Sponsoring Organizations of the Treadway Commission (COSO) published it in 2017 as Enterprise Risk Management: Integrating with Strategy and Performance. Its five components are governance and culture; strategy and objective-setting; performance; review and revision; and information, communication, and reporting. Twenty principles sit underneath them.
Boards and finance-led risk functions use COSO ERM because it frames risk in terms of the objectives they already review. Many organizations that adopt it also use COSO's separate internal control framework for SOX compliance testing.
COSO ERM says little about technical control selection, so security teams need a second framework for system-level work.
NIST RMF: A step-by-step process for information systems
The NIST RMF, defined in NIST Special Publication 800-37, Revision 2, sets out seven steps for managing risk in information systems: prepare, categorize, select, implement, assess, authorize, and monitor.
U.S. federal agencies are required to follow it. Contractors that operate federal systems follow it too, including cloud providers pursuing FedRAMP authorization, whose requirements build on NIST SP 800-53 controls. Most private companies outside the federal space use the NIST Cybersecurity Framework (CSF) instead, which organizes cyber risk at the enterprise level without the RMF's system authorization steps.
How the three frameworks compare
Scope
ISO 31000 covers the widest ground: any risk, in any organization, of any size. COSO ERM narrows the focus to risks that affect enterprise strategy and objectives, which is why boards and executives tend to adopt its language. The NIST RMF is the narrowest. It applies to information systems and the confidentiality, integrity, and availability of the data they process.
- Use ISO 31000 when you need one risk vocabulary across every business unit and geography.
- COSO ERM fits when the board expects risk reporting tied to strategic objectives and appetite.
- If your main obligation is authorizing federal information systems, the NIST RMF is the required process.
Structure
ISO 31000 prescribes the least. It gives you principles and a generic process (establish scope and context, assess risk, treat risk, monitor, and review) without mandating controls or document formats.
COSO ERM adds more shape through its five components and 20 principles, though you still design your own control activities and reporting cadence. The NIST RMF is the most rigid of the three. Each of its seven steps has defined inputs, outputs, and required documentation, such as the system security plan and the authorization package.
Assurance expectations
Assurance expectations determine how much evidence you produce and who reviews it.
ISO 31000 carries the lightest formal requirement. Because organizations cannot be certified against it, assurance comes mostly from internal audit and management review.
COSO ERM has no external attestation. Internal audit and the audit committee provide most of the assurance.
For SOX, external auditors test internal control over financial reporting against COSO's 2013 Internal Control–Integrated Framework, not COSO ERM. Using both lets you trace entity-level risk decisions to the controls your auditor tests.
The NIST RMF requires the most evidence of the three. A system cannot operate until an authorizing official formally accepts its risk, based on a control assessment and an authorization package. Continuous monitoring evidence keeps the authorization current, and higher-impact systems require assessors who are independent of the system owner.
Operational burden
ISO 31000 creates the least day-to-day work because you can fit its process into existing workflows. COSO ERM adds moderate effort, mostly in linking risk data to strategic objectives and keeping principle-level documentation current for the board.
The NIST RMF demands the most. Security teams select and tailor controls from NIST SP 800-53, assess them, maintain authorization packages, and collect monitoring evidence for every system in scope. Most organizations need dedicated staff with security assessment experience to keep up.
A side-by-side comparison of ISO 3100, COSO ERM, and NIST RMF
Dimension | ISO 31000 | COSO ERM | NIST RMF |
|---|---|---|---|
Scope | Any risk type, any organization | Strategic and enterprise-wide risk | Information systems and cyber risk |
Structure | Principles-based, flexible | Five components, 20 principles | Seven-step prescriptive process |
Assurance expectations | Internal; not certifiable | Internal audit and board oversight; SOX testing uses COSO's internal control framework | Formal authorization, control assessment, and continuous monitoring |
Operational burden | Lightest | Moderate | Heaviest |
Best fit | Common risk language across the enterprise | Boards and finance-led risk teams | Federal systems and the teams that authorize them |
Why these frameworks are not mutually exclusive
ISO 31000, COSO ERM, and the NIST RMF are not mutually exclusive, and most enterprises use at least two of them. Each one covers a different layer of the risk program. COSO ERM will not tell a security team which NIST SP 800-53 controls to select, and the NIST RMF says nothing about how risk appetite should shape strategy.
Assign each framework to a layer
- Enterprise risk language. ISO 31000 or COSO ERM defines how every team identifies, rates, and reports risk.
- Governance and strategy. COSO ERM links risk appetite to the objectives the board reviews.
- System-level execution. The NIST RMF, or the NIST CSF in non-federal environments, governs how security teams select, test, and monitor controls.
When all three layers draw from one risk register, teams stop translating between frameworks. An audit team reporting on COSO principles, a security team tracking NIST controls, and a risk team rating risks under ISO 31000 can all point to the same control and the same test result.
Common framework combinations
ISO 31000 with the NIST RMF or NIST CSF
Organizations use ISO 31000 to set one risk process across the business, then apply the NIST RMF or CSF to IT and cyber risk. This pairing suits global companies with a separate security risk function, because ISO 31000 is recognized across jurisdictions, and NIST gives the security team control-level detail.
COSO ERM with COSO's internal control framework
Public companies that already test SOX 404 controls against COSO's internal control framework often extend COSO ERM to connect those controls to strategic risk decisions. The board and the audit committee then work from one set of COSO terms instead of two.
COSO ERM with the NIST RMF
Federal contractors and cloud providers pursuing FedRAMP authorization often run COSO ERM at the governance layer and the NIST RMF for system authorization and monitoring. The board reviews enterprise risk in COSO terms, and system owners produce the authorization evidence NIST requires.
Choose based on where your obligations concentrate
- If SOX reporting drives most of your requirements, anchor the program to COSO.
- Federal contracts or federal systems in scope call for the NIST RMF at the system layer.
- For organizations spread across many risk types and countries, ISO 31000 works as the shared process that the other frameworks map to.
Run every framework from one risk register
ISO 31000 gives you a common risk process, COSO ERM connects risk to strategy and board oversight, and the NIST RMF governs how information systems are authorized and monitored. Most enterprise programs need a combination of these frameworks, mapped to one shared set of risks and controls. Without that shared set, one access control ends up mapped to a COSO principle, a NIST SP 800-53 control, and an ISO 31000 process step in three spreadsheets owned by three teams.
Optro's GRC Intelligence Platform gives audit, risk, compliance, and infosec teams one trusted system of record for risks, controls, and framework mappings. A control tested once can support every framework it maps to, and AI agents working on that record keep the control status current between assessments. Reports to the board and to external auditors then start from the same data.
You may also like to read


Shadow AI: How to find and govern unsanctioned AI

Risk management tools vs. spreadsheets: Top 5 winners

Three lines, one view: How Shawbrook connected risk across a £20B bank

Shadow AI: How to find and govern unsanctioned AI

Risk management tools vs. spreadsheets: Top 5 winners
Discover why industry leaders choose Optro
SCHEDULE A DEMO



