COSO & ERM: Governance at RBC, BMO & Enbridge

portfolio info

  • Date

    July 17, 2026

Internal Controls & Governance

COSO & ERM: Governance at RBC, BMO & Enbridge

A comparative look at how three major Canadian institutions apply the COSO Internal Control and Enterprise Risk Management frameworks to govern sustainability reporting, and where that approach still runs into real limitations.

COSO Internal Control Enterprise Risk Management ICSR Governance Analysis
A note on sourcing: This is a self-initiated governance and internal-controls analysis, applying frameworks I studied during my Master of Accounting in Forensic Analysis. Company information for RBC, BMO, and Enbridge is drawn from their own public sustainability reports, proxy circulars, and regulatory filings, cited as of the time of writing. Governance structures can change, so current practice should be checked against each company’s most recent public disclosures.

Why this analysis

Sustainability reporting increasingly carries the same stakeholder weight as financial reporting, but it’s built on non-financial data, estimates, and third-party inputs that traditional internal control systems were never designed around. This analysis asks whether the COSO Internal Control Integrated Framework and the COSO Enterprise Risk Management framework, both originally built for financial reporting, can meaningfully extend to govern sustainability disclosures, and looks at how three large Canadian institutions actually apply them in practice.

How the two frameworks combine

The COSO Internal Control Framework’s five components, Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring, apply directly to sustainability data with the same rigor traditionally reserved for financial statements.

Components of Internal Control (COSO) Effective Internal Control Control Environment Ethical & governance foundation – leadership commitment to ESG accuracy Risk Assessment Identifies sustainability-metric risk: incomplete data, third-party reliance Control Activities Standard calculation methods, approvals, data validation tests Information & Communication Timely flow across operations, HR, procurement – supports traceability Monitoring Activities Management review, dashboards, internal audits over time All five components apply to sustainability disclosures with the same rigor traditionally reserved for financial reporting.

ERM adds the second half: aligning sustainability risks (climate, social, reputational) with enterprise strategy and risk appetite, rather than treating sustainability reporting as a standalone compliance exercise. Together, the two frameworks support what’s increasingly called Internal Control over Sustainability Reporting (ICSR).

How COSO Internal Control and ERM Combine to Support ICSR COSO Internal Control – Integrated Framework Provides structure and discipline: control environment, risk assessment, control activities, information flow, and monitoring COSO Enterprise Risk Management (ERM) Aligns sustainability risk with strategy and governance: climate, social, and reputational risk treated as enterprise-wide, not standalone Internal Control over Sustainability Reporting (ICSR)

Three companies, three governance models

Royal Bank of Canada moved oversight of its annual sustainability reporting to its Audit Committee, the same committee responsible for financial reporting oversight. That signals the Board treats ESG disclosure as material information warranting the same assurance rigor as the Annual Report, and RBC fully integrates environmental and social risk into its Enterprise Risk Appetite Framework.

BMO Financial Group applies the Three Lines of Defence model to climate risk specifically. Business units own front-line ESG screening, a Risk Management Committee provides second-line oversight with quantified risk-appetite metrics, and Corporate Audit provides independent third-line assurance, including a notable “Client Transition Readiness Assessment” that converts climate risk into a tangible credit-risk input.

Enbridge Inc. folds sustainability risk into a single Corporate Risk Assessment alongside financial and operational risk, overseen by a combined Audit, Finance & Risk Committee, and engages third-party assurance (ISAE 3000/3410) over its emissions data. That effectively collapses the usual divide between financial and non-financial control.

FeatureRBCBMOEnbridge
Primary Oversight BodyAudit CommitteeRisk Management CommitteeAudit, Finance & Risk Committee
Risk FrameworkEnterprise Risk Appetite Framework (incl. E&S)Three Lines of Defence (climate embedded throughout)Corporate Risk Assessment (physical & transition risk)
Key InnovationFormal transfer of ESG reporting approval to Audit CommitteeClimate metrics embedded into credit adjudicationUnified view of safety, financial, and climate risk

Where the model still runs into limits

Applying financial-reporting-grade controls to sustainability data runs into real constraints, and the frameworks alone don’t solve them:

  • Measurement uncertainty: many sustainability metrics (GHG estimates, climate transition risk) depend on models and projections rather than transactional data, which limits the assurance internal controls can realistically provide
  • Third-party data reliance: Scope 3 emissions and supply-chain data usually originate entirely outside the reporting entity’s own control environment
  • Evolving standards: frameworks like the ISSB are still in a transition period, which adds implementation uncertainty on top of measurement uncertainty
  • Governance and incentive risk: when ESG performance is tied to reputation or executive pay, the underlying risk is behavioral and cultural, not something a control checklist alone can fix
  • Assurance and audit maturity: there’s no settled consensus yet on the appropriate level of external assurance for sustainability data, and internal audit functions often lack the specialized technical skills to evaluate it

Key achievements

  • Worked out how COSO Internal Control and ERM combine to support Internal Control over Sustainability Reporting (ICSR), illustrated with an original integration diagram
  • Analyzed and compared governance structures at three major Canadian financial and energy institutions using their own public disclosures
  • Identified BMO’s “Client Transition Readiness Assessment” as a notable practice that converts climate risk into a tangible credit-risk input
  • Identified five specific, real limitations of applying financial-control rigor to sustainability data, beyond a generic “ESG is hard to measure” framing

Frameworks & sources used

COSO Internal Control – Integrated Framework COSO Enterprise Risk Management Public company disclosures (RBC, BMO, Enbridge)

Explore the analysis

The Exhibit Case Brief plus the full written documentation behind this analysis.