Risk management frameworks compared: ISO 31000 vs NIST RMF vs COSO ERM

Pick the right framework — then actually run it.

Three frameworks dominate serious enterprise risk conversations: ISO 31000, the NIST Risk Management Framework (RMF), and COSO ERM. They are often quoted interchangeably. They are not interchangeable — the scope, the audience and the day-to-day artefacts differ. This guide compares them for the SME and consulting audience, and shows how ISO-STANDARD.app operationalises whichever one you pick.

At a glance

FrameworkOwnerPrimary scopeBest for
ISO 31000:2018ISOAny risk, any organisationSMEs, integrated trust & risk, ISO 27001 / 9001 / 42001 alignment
NIST RMF (SP 800-37 r2)NISTFederal information systems, cyberUS federal, defense contractors, FedRAMP-adjacent
COSO ERM (2017)COSOEnterprise-wide strategic & financial riskListed companies, SOX-driven finance functions

ISO 31000 — the integrated default

ISO 31000 is deliberately generic: principles, framework and a process (scope → identify → analyse → evaluate → treat → monitor → communicate). Because every other ISO standard (27001 for security, 9001 for quality, 42001 for AI, 20000-1 for services) references it, ISO 31000 becomes the single risk methodology that lets you run multiple certifications from one register instead of maintaining three parallel ones. This is why the entire ISO-STANDARD.app workspace is built on ISO 31000 with a 5×5 likelihood/impact matrix.

NIST RMF — the US federal path

NIST RMF is prescriptive: seven steps (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) tied to control catalogues in NIST SP 800-53. If you sell to US federal agencies, work under FedRAMP, or hold CUI under CMMC, you need it. Outside that market it is heavier than most SMEs need, and its control language is cyber-specific — it does not naturally cover quality, AI ethics or supplier-financial risk.

COSO ERM — the boardroom framework

COSO ERM speaks the language of internal audit and CFOs: governance & culture, strategy & objective-setting, performance, review & revision, information & reporting. It is the reference framework behind SOX internal-controls work. It is excellent for strategic and financial risk articulation to a board, but it does not give you an ISMS, an AIMS, or an evidence vault an auditor can inspect.

How to choose

  • SME chasing ISO 27001, SOC 2 or ISO 42001? ISO 31000. One register, one methodology, every certification maps in.
  • Selling to the US federal government or defense supply chain? NIST RMF, non-negotiable.
  • Listed / regulated financial reporter? COSO ERM at the board level, ISO 31000 operationally underneath it.

Operationalising in ISO-STANDARD.app

Whichever framework you adopt at the governance layer, the day-to-day artefacts are the same: a live risk register, treatments tied to controls, evidence attached to controls, internal audits producing corrective actions, and a management review closing the loop. ISO-STANDARD.app ships all of that against an ISO 31000 spine, with NIST SP 800-53 and COSO control-category tags available so you can present the same underlying data to a federal auditor, a SOC 2 auditor, or an audit committee.

See pricing · See measurable outcomes

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.