• The Committee of Sponsoring Organizations (COSO) sets out the framework and criteria that companies and their auditors use to establish internal controls. These criteria are considered by some standards of enterprise risk management (ERM) practice.