A comparative look at how three major Canadian institutions apply the COSO Internal
Control and Enterprise Risk Management frameworks to govern sustainability reporting, and where that
approach still runs into real limitations.
A note on sourcing: This is a self-initiated governance and internal-controls
analysis, applying frameworks I studied during my Master of Accounting in Forensic Analysis. Company
information for RBC, BMO, and Enbridge is drawn from their own public sustainability reports, proxy
circulars, and regulatory filings, cited as of the time of writing. Governance structures can change,
so current practice should be checked against each company’s most recent public disclosures.
Context
Why this analysis
Sustainability reporting increasingly carries the same stakeholder weight as financial reporting,
but it’s built on non-financial data, estimates, and third-party inputs that traditional internal
control systems were never designed around. This analysis asks whether the COSO Internal Control
Integrated Framework and the COSO Enterprise Risk Management framework, both originally built for
financial reporting, can meaningfully extend to govern sustainability disclosures, and looks at how
three large Canadian institutions actually apply them in practice.
Framework
How the two frameworks combine
The COSO Internal Control Framework’s five components, Control Environment, Risk Assessment,
Control Activities, Information & Communication, and Monitoring, apply directly to sustainability
data with the same rigor traditionally reserved for financial statements.
ERM adds the second half: aligning sustainability risks (climate, social, reputational) with
enterprise strategy and risk appetite, rather than treating sustainability reporting as a standalone
compliance exercise. Together, the two frameworks support what’s increasingly called Internal Control
over Sustainability Reporting (ICSR).
Application
Three companies, three governance models
Royal Bank of Canada moved oversight of its annual sustainability reporting to its
Audit Committee, the same committee responsible for financial reporting oversight. That signals the
Board treats ESG disclosure as material information warranting the same assurance rigor as the Annual
Report, and RBC fully integrates environmental and social risk into its Enterprise Risk Appetite
Framework.
BMO Financial Group applies the Three Lines of Defence model to climate risk
specifically. Business units own front-line ESG screening, a Risk Management Committee provides
second-line oversight with quantified risk-appetite metrics, and Corporate Audit provides independent
third-line assurance, including a notable “Client Transition Readiness Assessment” that converts
climate risk into a tangible credit-risk input.
Enbridge Inc. folds sustainability risk into a single Corporate Risk Assessment
alongside financial and operational risk, overseen by a combined Audit, Finance & Risk Committee,
and engages third-party assurance (ISAE 3000/3410) over its emissions data. That effectively collapses
the usual divide between financial and non-financial control.
Feature
RBC
BMO
Enbridge
Primary Oversight Body
Audit Committee
Risk Management Committee
Audit, Finance & Risk Committee
Risk Framework
Enterprise Risk Appetite Framework (incl. E&S)
Three Lines of Defence (climate embedded throughout)
Formal transfer of ESG reporting approval to Audit Committee
Climate metrics embedded into credit adjudication
Unified view of safety, financial, and climate risk
Critical Analysis
Where the model still runs into limits
Applying financial-reporting-grade controls to sustainability data runs into real constraints, and
the frameworks alone don’t solve them:
Measurement uncertainty: many sustainability metrics (GHG estimates, climate transition risk) depend on models and projections rather than transactional data, which limits the assurance internal controls can realistically provide
Third-party data reliance: Scope 3 emissions and supply-chain data usually originate entirely outside the reporting entity’s own control environment
Evolving standards: frameworks like the ISSB are still in a transition period, which adds implementation uncertainty on top of measurement uncertainty
Governance and incentive risk: when ESG performance is tied to reputation or executive pay, the underlying risk is behavioral and cultural, not something a control checklist alone can fix
Assurance and audit maturity: there’s no settled consensus yet on the appropriate level of external assurance for sustainability data, and internal audit functions often lack the specialized technical skills to evaluate it
Achievements
Key achievements
Worked out how COSO Internal Control and ERM combine to support Internal Control over Sustainability Reporting (ICSR), illustrated with an original integration diagram
Analyzed and compared governance structures at three major Canadian financial and energy institutions using their own public disclosures
Identified BMO’s “Client Transition Readiness Assessment” as a notable practice that converts climate risk into a tangible credit-risk input
Identified five specific, real limitations of applying financial-control rigor to sustainability data, beyond a generic “ESG is hard to measure” framing
Stack
Frameworks & sources used
COSO Internal Control – Integrated FrameworkCOSO Enterprise Risk ManagementPublic company disclosures (RBC, BMO, Enbridge)
Download
Explore the analysis
The Exhibit Case Brief plus the full written documentation behind this analysis.