Bundle catalog

frameworks bundle

COSO Enterprise Risk Management

A free, open-source set of 10 Markdown files that shows an AI assistant how to apply COSO Enterprise Risk Management to evidence, decisions, and reviewable outputs.

Use this bundle to apply COSO Enterprise Risk Management to a concrete question while keeping evidence, assumptions, stakeholder judgment, and review criteria visible. The page previews a framework guide, an overview, a workflow, and a template; the intended output is COSO ERM risk and strategy brief. Start source review with coso.org — Enterprise Risk Management.

Project-reviewed beta

10 Markdown files · 1,454 words · no signup · CC-BY-4.0

Inspect before downloading

See what is inside

These previews come from the published bundle files, so you can judge the method and writing before using it.

Is this bundle right for your task?

Who it is for

  • Practitioners using COSO Enterprise Risk Management to structure analysis, decisions, facilitation, or review
  • Teams working in Financial services, Public companies, Government

When to use it

  • A team needs to apply COSO Enterprise Risk Management to a concrete decision without skipping evidence, constraints, or stakeholder judgment.
  • An existing analysis needs its assumptions, reasoning, affected parties, and review criteria checked.

What you need to provide

  • The decision or question, available evidence, operating constraints, affected stakeholders, and desired outcome.
  • Existing analysis, definitions, assumptions, examples, and review criteria that the framework must reconcile.

Tasks and expected outputs

Questions it helps answer

  • Prepare a coso erm risk and strategy brief without fabricating local facts.
  • Separate verified, provided, assumed, and missing evidence.
  • Produce review-ready decisions with explicit verification and approval boundaries.

What it helps produce

  • COSO ERM risk and strategy brief

Practical example

Use it with an agent

Load the bundle as context, provide the evidence named above, then adapt this example to your situation.

Provide the decision or question, available evidence, operating constraints, affected stakeholders, and desired outcome. Ask the agent to apply COSO Enterprise Risk Management and produce COSO ERM risk and strategy brief that shows how evidence maps to the framework, where judgment is required, and what remains unresolved. Begin with coso.org — Enterprise Risk Management, then confirm that the reference is current and applicable. Inspect COSO Enterprise Risk Management Source-Aware Application Framework before drafting.

Context path: bundles/frameworks/coso-erm-framework

What the bundle includes

Frameworks

  • source-evidence matrix
  • enterprise risk management and strategy application matrix
  • qualified-review gate

Evaluations

  • COSO Enterprise Risk Management source-awareness check

Sources used to build this bundle

These are the public references behind the role definition and operating guidance. The bundle does not replace current documentation or evidence from your site.

Limitations and safe use

Do not use this for

  • Applying the framework mechanically when the decision requires missing evidence, stakeholder judgment, or qualified review.

Known limitations

  • Use the cited official or primary sources for general enterprise risk management and strategy context; local facts, configuration, records, values, states, and permissions require inspected evidence.
  • Task-specific work requires current evidence for framework edition and official guidance, mission, strategy, and business objectives, risk appetite, tolerances, and governance, risk inventory, definitions, assessment method, and evidence, responses, owners, dependencies, and portfolio view, and performance, review, change, and reporting evidence.
  • Do not infer risk scope, risk appetite, likelihood, impact, response effectiveness, and portfolio interaction.

Safety notes

  • Minimize personal, customer, employee, financial, credential, and other sensitive data.
  • Require explicit confirmation before accepting risk, changing strategy or controls, making regulatory or assurance claims, or reporting risk conclusions without accountable governance.
  • Route legal, privacy, security, compliance, financial, employment, safety, and other qualified judgments to accountable reviewers.

Next step

Inspect it before relying on it

Download the bundle for use, review its source files and evidence, or read the agent guidance. If the project is useful, starring the repository helps others discover it.