In the COSO framework there isnt any risk response but only risk assessment.(which i believe it includes risk identification and categorisation). In the ERM framework there is a risk response where TARA is used. How can a company use the COSO if measures are not taken to tackle risks? Or is risk response part of risk assessment? IM CONFUSED