article thumbnail

IRM, ERM, and GRC: Is There a Difference?

Reciprocity

Organizations typically bought insurance to avoid the losses these risks could cause, thus “transferring” the risk to the insurance company. As a result, in 2004, the Committee of Sponsoring Organizations (COSO) issued a second framework: Enterprise Risk Management -Integrated Framework , subsequently updated in 2017.