A manufacturing company hedges 80% of its foreign currency exposure, maintains aggressive working capital policies, and reports strong quarterly earnings. Then a supply chain disruption hits, liquidity evaporates, and the board asks why enterprise risk management failed to flag the concentration. The answer is usually that the firm managed individual risks in silos without integrating them into a strategic view. The COSO ERM framework exists precisely to prevent that failure, and the exam tests whether you can apply it.
AICPA Representative Tasks (verbatim). "Recall the purpose and objectives of the COSO ERM framework." "Recall how the COSO ERM framework can be applied to identify, respond to and report environmental, social and governance (ESG) related risks." "Apply the COSO ERM framework to identify risk/opportunity scenarios in an entity." "Use strategies to mitigate financial risks (e.g., market, interest rate, currency, liquidity)." "Compare various strategies for managing the working capital of an entity." "Derive the impact of a proposed transaction on key performance measures of an entity." "Interpret an entity's strengths, weaknesses...
Common mistakes
- Treating COSO ERM as a compliance exercise. ERM is a strategic tool, not a checkbox. The exam will describe a board treating ERM as an annual report appendix: that is a governance failure, not effective risk management.
- Ignoring risk appetite when recommending responses. A risk response must align with the board's stated appetite. Accepting a risk that exceeds appetite, or avoiding a risk well within appetite, is a mismatch the exam will flag.
- Confusing hedging instruments. A forward eliminates both downside and upside; an option preserves upside but costs a premium. The exam will describe a firm that wants upside capture and offer a forward as a trap answer.
Bottom line
- COSO ERM integrates risk with strategy through 5 components and 20 principles: governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting.
- ESG risks are handled within ERM, not a separate silo, by identifying environmental, social, and governance exposures that affect strategy and stakeholder value.
- Risk responses are accept, avoid, reduce, or share, selected by risk severity relative to the board's stated appetite.
- Financial risk mitigation uses forwards (lock rate, no upside), options (protection plus upside, premium cost), natural hedges, diversification, and liquidity buffers.
Exam shortcut
When a question describes a hedging scenario, map the firm's objective first: downside protection only → forward; downside protection with upside retention → option; long-term structural offset → natural hedge. The objective narrows the answer immediately. When a question asks about COSO ERM component placement, use the activity verb: identify/assess/prioritize → Performance; oversee/culture/values → Governance & Culture; monitor/revise/improve → Review & Revision. The verb points to the component.
The full lesson (about 6,019 words, 40 min read) adds 10 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- I.B4
Browse all free CPA BAR lessons or jump into free CPA BAR practice questions.