the coso cube is a part of a control framework generally called the coso framework. the purpose of internal control is to ensure these objectives are achieved. the cube is made up of a number of columns and rows that visualize internal control systems. the control environment is a set of standards, processes and structures that form internal control.

the coso framework also outlines 17 principles an organization should adopt in order to reach its internal control objectives. the coso cube can continue to be useful to organizations since it still provides a framework for improving risk management and internal control. an understanding of the coso cube provides a fair amount of background knowledge for the 2017 version of the framework as well.

the coso enterprise risk management framework helps organizations identify, assess, respond to, and monitor risks to align with business objectives. the coso erm works with a company’s control environment and is designed to give organizations a balanced perspective on risk. the 2004 coso erm framework utilized a diagram called the “coso cube” to illustrate the multidimensional nature of risk management in organizations. due to evolving business environments, the coso erm process was updated in 2017 to emphasize integrating risk with strategy-setting and performance.

having a good understanding of the coso erm framework can lead to substantial advantages for your organization. the coso erm framework ensures that risks are not viewed in isolation by tying risk management to organizational objectives. the coso erm framework is ideal for financial organizations because it incorporates the sarbanes-oxley act (sox). organizations looking to enhance their security or enterprise risk management can take advantage of a variety of other common frameworks