COSO ERM ↔ AI Governance Map
How to fit AI governance into the enterprise risk framework your board or internal audit already uses — without building a parallel structure.
What's included
- Word document with the 5 components of COSO ERM 2017 translated into AI governance
- Comparison table: COSO ERM vs ISO 23894 / NIST AI RMF — what each contributes, and at what level
- Guide on how to present AI governance to a board or audit committee
- Legal Notice
Why this document exists
If your organization already uses COSO ERM to manage enterprise risk, the biggest obstacle to AI governance usually isn't technical: it's explaining how it fits within the risk framework that already exists. This document translates the 5 components of COSO ERM (2017 version, the current one) into concrete AI governance decisions.
The 5 components, one line each
- Governance and culture: a committee with real authority, not just advisory.
- Strategy and objective-setting: AI risk appetite defined alongside strategy, not after.
- Performance: identification and response to AI risks tied to concrete objectives.
- Review and revision: continuous monitoring — AI systems change after deployment.
- Information, communication and reporting: compliance KPIs a board can actually read.
Frequently asked questions
Does this replace a technical AI risk checklist?
No. This map operates one level above — it connects AI governance to your board's enterprise risk framework. For technical detail, see the ISO/IEC 23894 Checklist or the NIST AI RMF Checklist.
Do I need COSO ERM already implemented?
This document assumes you already have it or are implementing it. If you don't use COSO, it can still serve as an introduction.
Does this replace legal advice?
No. It's a template that organizes the governance conversation, but it doesn't constitute legal advice — see the included Legal Notice.
What format is it delivered in?
A Word document with the mapping and comparison tables, plus the Legal Notice, delivered instantly after purchase.