The Executive Diagnostic and Governance Toolkit
Assessing and Evidencing COSO ERM Results
Score your own function red, amber or green, find out which part is weakest, and walk into the next budget round able to defend what you want to fix. Built for leaders reviewing they already hold the COSO erm playbook: the implementation guide, the roadmap and the working files, so repeating any of that is worthless. What is missing is the layer after implementation. How to assess the function honestly, what evidence to retain, how to score maturity, and how to put the result in front of a manager, an auditor or a client who was not involved. The immediate question: for one month of COSO erm work, can you show what was measured, against what target, and what changed as a result.
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
| 1 |
You stop guessing where you stand. You finish with a score, not an opinion: every part of your function rated red, amber or green, with the weakest ranked first. Evidence: a Quick Scan for the shape of it, then seven domain assessments of 30 scored questions each, 210 in all, rolled into one scorecard, plus a maturity radar and a current-versus-target gap analysis. |
| 2 |
You can defend the decision. You walk into the budget round with the gap named, the owner named and done defined, instead of a case built on instinct. Evidence: project charter, scope statement, RACI, requirements traceability and work breakdown structure, pre-filled in your domain's language. |
| 3 |
The work actually moves. The month after the decision is already built, so nothing stalls waiting for someone to design a form. Evidence: more than 60 project templates across all five PMBOK process groups, plus runbooks, SOPs, a KPI framework, audit checklists and a risk matrix. 55 to 65 files in total. |
| 4 |
You use it the day it lands. No blank templates to interpret. Every workbook opens with what it is, who uses it, when, how, a 1 to 5 scoring guide, what good looks like, and a worked example you delete and type over. |
The situation this is built for
You already have the implementation playbook, the roadmap, and the working files. But when leadership or auditors ask what changed, you’re stuck describing activity instead of outcomes. You need to assess maturity objectively, retain the right evidence, and report progress in a way that satisfies governance requirements — not just check a box. The gap isn’t implementation. It’s proving it.
Who this is for
A risk or compliance professional who owns the COSO ERM function in their organization, has completed foundational implementation, and now must demonstrate its effectiveness to executives, auditors, or regulators.
Who this is not for
This is not for consultants building ERM programs from scratch, vendors selling automation tools, or teams still setting up their first risk register.
What you walk away with
- Score ERM maturity across all 20 COSO principles with calibrated confidence
- Retain and organize evidence that survives internal audit scrutiny
- Produce standardized reports for risk committees and board reviewers
- Conduct unbiased self-assessments using challenge frameworks and peer validation
- Identify and close maturity gaps with targeted, defensible actions
How this maps to your situation
- You’ve implemented COSO ERM and need to prove it works
- You must report maturity to auditors or executives
- You lack a repeatable, defensible assessment method
- You need evidence that survives scrutiny
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 12 hours of focused work, designed to be completed in tandem with your existing ERM responsibilities.
How this compares to the alternatives
Public training often focuses on ERM implementation basics or generic audit preparation. This course is unique in addressing the post-implementation challenge: how to assess, evidence, and report on an existing COSO ERM function with precision, using field-tested methods and templates not available in vendor guides or frameworks.
Also included: the full course, for when you want the reasoning behind a finding (12 modules, 144 chapters)
Depth reference. The diagnostic and the templates stand on their own; this is what to read when you want the reasoning behind a finding.
- Understanding the difference between implementation and assessment
- Defining the objectives of a COSO ERM maturity evaluation
- Mapping COSO principles to measurable assessment criteria
- Identifying stakeholders who require ERM evidence
- Setting boundaries for function-specific assessment scope
- Aligning assessment timing with audit and reporting cycles
- Distinguishing between process and outcome metrics
- Using the COSO scorecard as a baseline measurement tool
- Documenting assumptions in maturity scoring methodology
- Integrating assessment findings into governance workflows
- Establishing roles for assessors, reviewers, and challengers
- Creating an assessment charter for internal approval
- Listing required evidence for Principle 1: Governance and Culture
- Capturing documentation for Principle 2: Board Risk Oversight
- Validating evidence for Principle 3: Organizational Structure
- Retaining records for Principle 4: Commitment to Core Values
- Demonstrating proof for Principle 5: Organizational Objectives
- Linking risk appetite statements to Principle 6 evidence
- Proving risk identification processes under Principle 7
- Documenting risk assessment outputs for Principle 8
- Showing response to risk under Principle 9 criteria
- Verifying information systems under Principle 10
- Demonstrating communication flow for Principle 11
- Validating monitoring activities under Principle 12
- Selecting assessment frequency based on organizational risk profile
- Creating standardized data collection workflows for assessors
- Developing evidence checklists for each COSO principle
- Assigning ownership for evidence submission and review
- Scheduling assessment timelines with department leads
- Integrating assessment deadlines into operational calendars
- Building evidence repositories with version control
- Using timestamps and digital signatures for authenticity
- Establishing escalation paths for missing documentation
- Training reviewers to apply consistent scoring criteria
- Incorporating legal hold procedures for audit readiness
- Maintaining assessment independence through role separation
- Defining maturity levels from ad hoc to optimized
- Using five-point scales to score each COSO principle
- Applying scoring rubrics to Principle 13 activities
- Evaluating risk response integration under Principle 14
- Measuring effectiveness of risk reporting under Principle 15
- Assessing risk culture maturity under Principle 16
- Scoring risk-informed decision making under Principle 17
- Rating change management under Principle 18 criteria
- Measuring external reporting alignment with Principle 19
- Evaluating continuous improvement under Principle 20
- Weighting scores based on organizational priorities
- Aggregating individual scores into composite maturity index
- Designing challenge questions for Principle 1 evaluations
- Using devil’s advocate role in scoring validation
- Conducting peer reviews of evidence completeness
- Applying red teaming techniques to risk assessments
- Validating scoring consistency across assessors
- Resolving scoring disagreements using panel review
- Testing assumptions in risk appetite documentation
- Challenging evidence quality for Principle 10 systems
- Reviewing risk reporting transparency under Principle 15
- Auditing internal conclusions before external release
- Documenting rationale for all final maturity scores
- Creating challenge logs for audit trail purposes
- Structuring evidence binders for internal audit review
- Formatting risk register extracts for compliance teams
- Compiling sign-off logs for risk response actions
- Organizing board presentation materials for Principle 2
- Creating evidence matrices aligned to COSO principles
- Annotating documentation with cross-reference tags
- Producing summary dashboards for executive reviewers
- Including version history in all submitted artifacts
- Highlighting maturity improvements year over year
- Preparing response plans for identified gaps
- Using cover memos to explain assessment scope
- Redacting sensitive information while preserving context
- Summarizing maturity scores for board-level presentations
- Explaining scoring methodology to non-technical leaders
- Highlighting top risk exposure areas from assessment data
- Linking maturity gaps to strategic objectives
- Presenting trend analysis from prior year comparisons
- Using visual indicators to show principle-level performance
- Framing improvement plans as risk reduction initiatives
- Reporting on culture indicators under Principle 16
- Discussing risk appetite adherence with finance leaders
- Aligning ERM findings with enterprise performance goals
- Responding to governance questions on evidence quality
- Documenting board feedback for future assessments
- Updating risk registers based on maturity findings
- Revising risk response plans to close gaps
- Incorporating assessment insights into risk committee agendas
- Adjusting risk appetite thresholds based on evidence
- Enhancing control testing frequency after low scores
- Revising training programs to address cultural gaps
- Updating escalation protocols based on monitoring results
- Aligning internal audit plans with maturity outcomes
- Feeding assessment data into enterprise dashboards
- Scheduling follow-up reviews for high-risk principles
- Linking ERM improvements to performance metrics
- Documenting action closure in central tracking systems
- Defining retention periods for each evidence type
- Classifying documentation by sensitivity and access level
- Storing signed risk appetite statements securely
- Archiving historical assessment scorecards annually
- Controlling access to evidence repositories
- Using encryption for cloud-based document storage
- Establishing retrieval procedures for audit requests
- Maintaining metadata logs for all evidence files
- Applying legal hold protocols during investigations
- Purging outdated documents per retention schedule
- Auditing access logs for compliance verification
- Back-up and disaster recovery for critical evidence
- Identifying relevant industry benchmarks for ERM
- Comparing maturity scores to peer group medians
- Adjusting expectations based on organizational size
- Using regulatory guidance to calibrate scoring rigor
- Interpreting differences in public versus private sector norms
- Benchmarking risk culture assessments across sectors
- Evaluating reporting transparency against best practices
- Assessing external communication maturity levels
- Incorporating lessons from enforcement actions
- Using benchmark data to justify improvement investments
- Updating internal targets based on industry shifts
- Documenting rationale for deviating from benchmarks
- Collecting feedback from auditors on evidence quality
- Reviewing scoring accuracy after risk events occur
- Updating assessment templates based on lessons learned
- Training new assessors using past evaluation examples
- Standardizing evidence labeling across departments
- Reducing subjectivity in maturity scoring
- Increasing automation of evidence collection gradually
- Validating process improvements with pilot assessments
- Publishing internal assessment guidelines annually
- Measuring assessor performance over time
- Aligning terminology with COSO’s official definitions
- Conducting pre-mortems to anticipate challenges
- Scheduling annual ERM maturity reassessments
- Integrating ERM health checks into quarterly reviews
- Updating evidence requirements as regulations change
- Tracking maturity progress across multiple cycles
- Recognizing teams for sustained maturity performance
- Linking ERM outcomes to executive compensation
- Revising assessment scope for organizational changes
- Adapting to new technology impacts on risk reporting
- Maintaining independence in ongoing evaluations
- Publishing internal maturity reports enterprise-wide
- Using trend data to forecast future risk exposure
- Evolving the assessment model with organizational growth
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Thousands of organisations have bought from The Art of Service since 2000.