Skip to main content
Image coming soon

RSK1797 Assessing and Evidencing COSO ERM Results

$199.00
Adding to cart… The item has been added

The Executive Diagnostic and Governance Toolkit

Assessing and Evidencing COSO ERM Results

Score your own function red, amber or green, find out which part is weakest, and walk into the next budget round able to defend what you want to fix. Built for leaders reviewing they already hold the COSO erm playbook: the implementation guide, the roadmap and the working files, so repeating any of that is worthless. What is missing is the layer after implementation. How to assess the function honestly, what evidence to retain, how to score maturity, and how to put the result in front of a manager, an auditor or a client who was not involved. The immediate question: for one month of COSO erm work, can you show what was measured, against what target, and what changed as a result.

$199 one-time
30-day money-back guarantee Verified against latest insights, updated access provided within 24h

Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

What you walk out with
A scored, ranked picture of your own function, and a defensible answer to what to fix first.
1 You stop guessing where you stand.
You finish with a score, not an opinion: every part of your function rated red, amber or green, with the weakest ranked first. Evidence: a Quick Scan for the shape of it, then seven domain assessments of 30 scored questions each, 210 in all, rolled into one scorecard, plus a maturity radar and a current-versus-target gap analysis.
2 You can defend the decision.
You walk into the budget round with the gap named, the owner named and done defined, instead of a case built on instinct. Evidence: project charter, scope statement, RACI, requirements traceability and work breakdown structure, pre-filled in your domain's language.
3 The work actually moves.
The month after the decision is already built, so nothing stalls waiting for someone to design a form. Evidence: more than 60 project templates across all five PMBOK process groups, plus runbooks, SOPs, a KPI framework, audit checklists and a risk matrix. 55 to 65 files in total.
4 You use it the day it lands.
No blank templates to interpret. Every workbook opens with what it is, who uses it, when, how, a 1 to 5 scoring guide, what good looks like, and a worked example you delete and type over.
The Quick Scan is one sitting. You will know your weakest area before the day is out.
Nothing in it is generic project management: the build rejects any file that could belong to another course. Updated after you enrol, so it reflects where the work stands now. The 144-chapter course is included behind it, for the parts you want to go deeper on.
You’ve implemented COSO ERM. Now someone is asking: Where’s the proof it works?

The situation this is built for

You already have the implementation playbook, the roadmap, and the working files. But when leadership or auditors ask what changed, you’re stuck describing activity instead of outcomes. You need to assess maturity objectively, retain the right evidence, and report progress in a way that satisfies governance requirements — not just check a box. The gap isn’t implementation. It’s proving it.

Who this is for

A risk or compliance professional who owns the COSO ERM function in their organization, has completed foundational implementation, and now must demonstrate its effectiveness to executives, auditors, or regulators.

Who this is not for

This is not for consultants building ERM programs from scratch, vendors selling automation tools, or teams still setting up their first risk register.

What you walk away with

  • Score ERM maturity across all 20 COSO principles with calibrated confidence
  • Retain and organize evidence that survives internal audit scrutiny
  • Produce standardized reports for risk committees and board reviewers
  • Conduct unbiased self-assessments using challenge frameworks and peer validation
  • Identify and close maturity gaps with targeted, defensible actions

How this maps to your situation

  • You’ve implemented COSO ERM and need to prove it works
  • You must report maturity to auditors or executives
  • You lack a repeatable, defensible assessment method
  • You need evidence that survives scrutiny

Before vs. after

Before
You have implemented COSO ERM but struggle to prove its effectiveness, retain inconsistent evidence, and face questions you can’t answer with confidence.
After
You conduct rigorous, repeatable assessments, maintain defensible documentation, and report maturity with clarity to auditors, executives, and regulators.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 12 hours of focused work, designed to be completed in tandem with your existing ERM responsibilities.

If nothing changes
Without a structured assessment and evidence strategy, your ERM function appears reactive rather than strategic. Auditors may question compliance, executives may underfund risk initiatives, and a single incident could expose undocumented gaps — undermining years of implementation effort.

How this compares to the alternatives

Public training often focuses on ERM implementation basics or generic audit preparation. This course is unique in addressing the post-implementation challenge: how to assess, evidence, and report on an existing COSO ERM function with precision, using field-tested methods and templates not available in vendor guides or frameworks.

Also included: the full course, for when you want the reasoning behind a finding (12 modules, 144 chapters)

Depth reference. The diagnostic and the templates stand on their own; this is what to read when you want the reasoning behind a finding.

Module 1. Foundations of COSO ERM Assessment
Establish the purpose, scope, and governance of assessing an existing ERM function against COSO’s 2017 framework.
12 chapters in this module
  1. Understanding the difference between implementation and assessment
  2. Defining the objectives of a COSO ERM maturity evaluation
  3. Mapping COSO principles to measurable assessment criteria
  4. Identifying stakeholders who require ERM evidence
  5. Setting boundaries for function-specific assessment scope
  6. Aligning assessment timing with audit and reporting cycles
  7. Distinguishing between process and outcome metrics
  8. Using the COSO scorecard as a baseline measurement tool
  9. Documenting assumptions in maturity scoring methodology
  10. Integrating assessment findings into governance workflows
  11. Establishing roles for assessors, reviewers, and challengers
  12. Creating an assessment charter for internal approval
Module 2. Evidence Requirements for Each COSO Principle
Determine the specific artifacts and documentation required to validate each of the 20 COSO principles.
12 chapters in this module
  1. Listing required evidence for Principle 1: Governance and Culture
  2. Capturing documentation for Principle 2: Board Risk Oversight
  3. Validating evidence for Principle 3: Organizational Structure
  4. Retaining records for Principle 4: Commitment to Core Values
  5. Demonstrating proof for Principle 5: Organizational Objectives
  6. Linking risk appetite statements to Principle 6 evidence
  7. Proving risk identification processes under Principle 7
  8. Documenting risk assessment outputs for Principle 8
  9. Showing response to risk under Principle 9 criteria
  10. Verifying information systems under Principle 10
  11. Demonstrating communication flow for Principle 11
  12. Validating monitoring activities under Principle 12
Module 3. Designing a Repeatable Assessment Process
Build a structured, auditable process for evaluating ERM maturity that can be replicated annually or quarterly.
12 chapters in this module
  1. Selecting assessment frequency based on organizational risk profile
  2. Creating standardized data collection workflows for assessors
  3. Developing evidence checklists for each COSO principle
  4. Assigning ownership for evidence submission and review
  5. Scheduling assessment timelines with department leads
  6. Integrating assessment deadlines into operational calendars
  7. Building evidence repositories with version control
  8. Using timestamps and digital signatures for authenticity
  9. Establishing escalation paths for missing documentation
  10. Training reviewers to apply consistent scoring criteria
  11. Incorporating legal hold procedures for audit readiness
  12. Maintaining assessment independence through role separation
Module 4. Scoring Maturity Across COSO Principles
Apply calibrated scoring models to measure maturity levels consistently and defendably across all 20 principles.
12 chapters in this module
  1. Defining maturity levels from ad hoc to optimized
  2. Using five-point scales to score each COSO principle
  3. Applying scoring rubrics to Principle 13 activities
  4. Evaluating risk response integration under Principle 14
  5. Measuring effectiveness of risk reporting under Principle 15
  6. Assessing risk culture maturity under Principle 16
  7. Scoring risk-informed decision making under Principle 17
  8. Rating change management under Principle 18 criteria
  9. Measuring external reporting alignment with Principle 19
  10. Evaluating continuous improvement under Principle 20
  11. Weighting scores based on organizational priorities
  12. Aggregating individual scores into composite maturity index
Module 5. Conducting Internal Challenge and Validation
Ensure assessment integrity by introducing structured challenge and peer validation mechanisms.
12 chapters in this module
  1. Designing challenge questions for Principle 1 evaluations
  2. Using devil’s advocate role in scoring validation
  3. Conducting peer reviews of evidence completeness
  4. Applying red teaming techniques to risk assessments
  5. Validating scoring consistency across assessors
  6. Resolving scoring disagreements using panel review
  7. Testing assumptions in risk appetite documentation
  8. Challenging evidence quality for Principle 10 systems
  9. Reviewing risk reporting transparency under Principle 15
  10. Auditing internal conclusions before external release
  11. Documenting rationale for all final maturity scores
  12. Creating challenge logs for audit trail purposes
Module 6. Preparing Auditor-Ready Reporting Packages
Assemble complete, organized documentation sets that satisfy internal and external audit requirements.
12 chapters in this module
  1. Structuring evidence binders for internal audit review
  2. Formatting risk register extracts for compliance teams
  3. Compiling sign-off logs for risk response actions
  4. Organizing board presentation materials for Principle 2
  5. Creating evidence matrices aligned to COSO principles
  6. Annotating documentation with cross-reference tags
  7. Producing summary dashboards for executive reviewers
  8. Including version history in all submitted artifacts
  9. Highlighting maturity improvements year over year
  10. Preparing response plans for identified gaps
  11. Using cover memos to explain assessment scope
  12. Redacting sensitive information while preserving context
Module 7. Communicating Results to Governance Bodies
Translate technical assessment findings into clear, actionable insights for executives and board members.
12 chapters in this module
  1. Summarizing maturity scores for board-level presentations
  2. Explaining scoring methodology to non-technical leaders
  3. Highlighting top risk exposure areas from assessment data
  4. Linking maturity gaps to strategic objectives
  5. Presenting trend analysis from prior year comparisons
  6. Using visual indicators to show principle-level performance
  7. Framing improvement plans as risk reduction initiatives
  8. Reporting on culture indicators under Principle 16
  9. Discussing risk appetite adherence with finance leaders
  10. Aligning ERM findings with enterprise performance goals
  11. Responding to governance questions on evidence quality
  12. Documenting board feedback for future assessments
Module 8. Integrating Findings into Ongoing ERM Activities
Ensure assessment outcomes directly inform risk planning, control enhancements, and policy updates.
12 chapters in this module
  1. Updating risk registers based on maturity findings
  2. Revising risk response plans to close gaps
  3. Incorporating assessment insights into risk committee agendas
  4. Adjusting risk appetite thresholds based on evidence
  5. Enhancing control testing frequency after low scores
  6. Revising training programs to address cultural gaps
  7. Updating escalation protocols based on monitoring results
  8. Aligning internal audit plans with maturity outcomes
  9. Feeding assessment data into enterprise dashboards
  10. Scheduling follow-up reviews for high-risk principles
  11. Linking ERM improvements to performance metrics
  12. Documenting action closure in central tracking systems
Module 9. Managing Evidence Retention and Access
Implement policies for storing, securing, and retrieving ERM assessment documentation over time.
12 chapters in this module
  1. Defining retention periods for each evidence type
  2. Classifying documentation by sensitivity and access level
  3. Storing signed risk appetite statements securely
  4. Archiving historical assessment scorecards annually
  5. Controlling access to evidence repositories
  6. Using encryption for cloud-based document storage
  7. Establishing retrieval procedures for audit requests
  8. Maintaining metadata logs for all evidence files
  9. Applying legal hold protocols during investigations
  10. Purging outdated documents per retention schedule
  11. Auditing access logs for compliance verification
  12. Back-up and disaster recovery for critical evidence
Module 10. Benchmarking Against Industry Standards
Compare your organization’s ERM maturity to sector-specific norms and regulatory expectations.
12 chapters in this module
  1. Identifying relevant industry benchmarks for ERM
  2. Comparing maturity scores to peer group medians
  3. Adjusting expectations based on organizational size
  4. Using regulatory guidance to calibrate scoring rigor
  5. Interpreting differences in public versus private sector norms
  6. Benchmarking risk culture assessments across sectors
  7. Evaluating reporting transparency against best practices
  8. Assessing external communication maturity levels
  9. Incorporating lessons from enforcement actions
  10. Using benchmark data to justify improvement investments
  11. Updating internal targets based on industry shifts
  12. Documenting rationale for deviating from benchmarks
Module 11. Improving Assessment Credibility Over Time
Refine assessment methods, evidence standards, and scoring consistency to increase stakeholder trust.
12 chapters in this module
  1. Collecting feedback from auditors on evidence quality
  2. Reviewing scoring accuracy after risk events occur
  3. Updating assessment templates based on lessons learned
  4. Training new assessors using past evaluation examples
  5. Standardizing evidence labeling across departments
  6. Reducing subjectivity in maturity scoring
  7. Increasing automation of evidence collection gradually
  8. Validating process improvements with pilot assessments
  9. Publishing internal assessment guidelines annually
  10. Measuring assessor performance over time
  11. Aligning terminology with COSO’s official definitions
  12. Conducting pre-mortems to anticipate challenges
Module 12. Sustaining ERM Maturity Beyond Initial Assessment
Embed assessment practices into ongoing governance to maintain and advance ERM maturity.
12 chapters in this module
  1. Scheduling annual ERM maturity reassessments
  2. Integrating ERM health checks into quarterly reviews
  3. Updating evidence requirements as regulations change
  4. Tracking maturity progress across multiple cycles
  5. Recognizing teams for sustained maturity performance
  6. Linking ERM outcomes to executive compensation
  7. Revising assessment scope for organizational changes
  8. Adapting to new technology impacts on risk reporting
  9. Maintaining independence in ongoing evaluations
  10. Publishing internal maturity reports enterprise-wide
  11. Using trend data to forecast future risk exposure
  12. Evolving the assessment model with organizational growth

Frequently asked

I already have the COSO implementation guide. Why do I need this?
This course covers what comes after implementation: how to assess maturity, retain evidence, and report outcomes. It builds on your existing playbook but adds the layer of verification and communication that implementation guides omit.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does this course help me pass an audit?
Yes. It teaches you how to assemble evidence packages and scoring documentation that satisfy internal and external auditors reviewing your ERM program.
Will I learn how to create a maturity model?
Yes. You’ll build a calibrated scoring system across all 20 COSO principles, with templates and examples showing how to apply it consistently.
Is this relevant for highly regulated industries?
Absolutely. The evidence and reporting standards taught meet or exceed expectations in financial services, healthcare, and public sector environments.
What formats do the templates come in?
The implementation playbook downloads as PDF and editable XLSX. The course reads in your learning environment and exports to PDF for offline use. The files are yours to keep.
Can I share this with my team?
The licence is per person. Team pricing opens from three seats: reply to the order confirmation with TEAM and we will set it up.
How quickly can I start?
The diagnostic is one sitting and the templates work straight out of the kit. Account access takes up to 24 hours rather than being instant, because every order is checked and updated against the latest sources before it is delivered.
$199 one-time. Approximately 12 hours of focused work, designed to be completed in tandem with your existing ERM responsibilities..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee·Know your weakest area today·210 scored questions·Course included· Account access within 24 hours
30-day money-back guarantee, no questions asked.
Thousands of organisations have bought from The Art of Service since 2000.