ReadSafety.com
FrameworkCommittee of Sponsoring Organizations of the Treadway Commission (COSO)Last reviewed: August 2026

COSO Internal Control

COSO Internal Control is the most widely used framework for designing and evaluating internal controls in organizations.

What You'll Learn

  • What internal control means
  • The 5 components of the COSO framework
  • The 17 principles underlying the components
  • How COSO relates to SOX compliance
  • What a control failure looks like
  • How to evaluate control effectiveness

First: What Is This?

The COSO Internal Control - Integrated Framework is the dominant framework used worldwide for designing, implementing, and evaluating internal controls within organizations. Published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO), it defines internal control as a process designed to provide reasonable assurance regarding the achievement of objectives in three categories: operations, reporting, and compliance.

The framework is not a standard that organizations get certified against. It is a reference framework - a structured way of thinking about controls. It is particularly important in the United States because the SEC and PCAOB reference COSO when evaluating internal control over financial reporting under the Sarbanes-Oxley Act.

Who Does It Apply To?

U.S. public companies (SOX compliance)
Organizations designing internal control systems
Internal auditors evaluating controls
External auditors assessing control environments
Private companies (voluntary but widely used)
Non-U.S. companies (may use COSO or alternative frameworks)
Nonprofits and government entities
The framework is voluntary - no entity is legally required to use COSO specifically, though SOX requires a recognized framework

Is It Mandatory?

COSO itself is not mandatory. However, the Sarbanes-Oxley Act requires U.S. public companies to evaluate their internal control over financial reporting using a 'suitable, recognized control framework.' COSO is the most widely used framework for this purpose. The SEC has stated that COSO satisfies this requirement.

Component 1: Control Environment

Professional

The control environment is the set of standards, processes, and structures that provide the basis for carrying out internal control across the organization. It encompasses the integrity and ethical values of the organization, the parameters enabling the board of directors to carry out its oversight responsibilities, the organizational structure and assignment of authority and responsibility, the process for attracting, developing, and retaining competent individuals, and the rigor around performance measures, incentives, and rewards.

In Plain English

The control environment is the 'tone at the top' - the culture and attitude toward controls in an organization. It answers the question: Does leadership actually care about doing things right, or do they just pay lip service to controls while pressuring people to cut corners?

🧠Explain Like I'm 10

Imagine a classroom. The control environment is like the teacher's attitude toward rules. If the teacher takes rules seriously, enforces them fairly, and follows them too, the whole class behaves better. If the teacher ignores cheating or plays favorites, students learn that rules don't really matter. The 'control environment' is whether the adults in charge actually mean it when they say 'follow the rules.'

Practical Example

Strong control environment: The CEO publicly states that meeting financial targets never justifies cutting ethical corners. The board has an independent audit committee that meets quarterly. Employees who report concerns are protected. Performance bonuses include compliance metrics.

Weak control environment: The CEO says 'I don't care how you hit the numbers, just hit them.' The board rubber-stamps management decisions. Whistleblowers are marginalized. Bonuses are based solely on revenue targets.

Why Does This Rule Exist?

Without a strong control environment, individual controls become meaningless. You can design the most sophisticated approval process in the world, but if the CEO can override it without consequence, the control provides no protection.

Common Mistake

Organizations often focus on designing specific controls (approvals, reconciliations, segregation of duties) without addressing the control environment. But if the culture does not support controls, even well-designed controls will be circumvented.

Component 2: Risk Assessment

Professional

Risk assessment involves a dynamic and iterative process for identifying and assessing risks to the achievement of objectives. Risks are assessed relative to established risk tolerances. The entity considers the potential for fraud and assesses changes in the external environment and within the business model that may render internal controls ineffective.

In Plain English

Risk assessment means figuring out what could go wrong. Before you can design controls, you need to know what you are protecting against. This component asks: What are our objectives? What could prevent us from achieving them? How likely is it? How bad would it be?

🧠Explain Like I'm 10

Before you cross a busy road, you look both ways. That's risk assessment - you are checking what could hurt you. In a business, risk assessment means asking: 'What bad things could happen to our money, our reports, or our reputation?' Then you figure out which risks are the scariest and need the most protection.

Practical Example

A company identifies these risks to accurate financial reporting:

- Revenue could be recorded in the wrong period (likelihood: medium, impact: high)

- An employee could create fake vendors and pay themselves (likelihood: low, impact: high)

- Foreign currency transactions could be translated incorrectly (likelihood: high, impact: medium)

Based on this assessment, the company designs specific controls targeting each risk.

Component 3: Control Activities

Professional

Control activities are the actions established through policies and procedures that help ensure that management's directives to mitigate risks to the achievement of objectives are carried out. Control activities are performed at all levels of the entity, at various stages within business processes, and over the technology environment.

In Plain English

Control activities are the actual things people do (or systems enforce) to prevent or detect problems. These are the specific rules and checks: requiring two signatures on large payments, reconciling bank statements monthly, restricting who can access certain systems, requiring manager approval for purchases over a threshold.

🧠Explain Like I'm 10

Control activities are like the actual safety features on a bicycle. The helmet protects your head (that's one control). The brakes stop you from going too fast (another control). The reflectors help cars see you at night (another control). Each one protects against a specific danger.

Practical Example

Common control activities:

- Segregation of duties: The person who approves a payment cannot also be the person who creates the vendor record

- Authorization: Purchases over $10,000 require VP approval

- Reconciliation: Bank statements are reconciled to the general ledger monthly

- Physical controls: Inventory is stored in a locked warehouse with access logs

- IT controls: Users cannot access financial systems without multi-factor authentication

Common Mistake

Designing controls without linking them to specific risks. Every control should exist because it mitigates an identified risk. Controls that exist 'because we've always done it that way' may not actually protect against anything meaningful.

Component 4: Information & Communication

Professional

Information is necessary for the entity to carry out internal control responsibilities in support of achievement of its objectives. Communication is the continual, iterative process of providing, sharing, and obtaining necessary information. Internal communication is the means by which information is disseminated throughout the organization. External communication enables the entity to obtain information from external parties.

In Plain English

Good controls require good information flowing to the right people at the right time. This component asks: Do people have the information they need to do their jobs and spot problems? Can employees report concerns upward? Does management communicate expectations clearly downward?

🧠Explain Like I'm 10

Imagine playing a team sport where nobody is allowed to talk to each other. Even if every player is skilled, the team would be terrible because nobody knows what anyone else is doing. Information and communication means making sure everyone on the team can talk, share what they see, and hear the coach's instructions.

Component 5: Monitoring Activities

Professional

Ongoing evaluations, separate evaluations, or some combination of the two are used to ascertain whether each of the five components of internal control is present and functioning. Findings are evaluated and deficiencies are communicated in a timely manner, with serious matters reported to senior management and the board.

In Plain English

Monitoring means checking that your controls are actually working - not just that they exist on paper. This happens through ongoing activities (supervisors reviewing work daily) and periodic evaluations (internal audits). When problems are found, they need to be reported to someone who can fix them.

🧠Explain Like I'm 10

Having rules is not enough - someone needs to check that the rules are being followed. Monitoring is like a teacher walking around the classroom during a test. The rule is 'no cheating,' but without the teacher watching, some students might cheat anyway. Monitoring makes sure the rules actually work in practice.

Practical Example

Ongoing monitoring: A manager reviews and approves all journal entries over $50,000 daily.

Separate evaluation: Internal audit conducts a quarterly review of the accounts payable process, testing whether segregation of duties is maintained and whether all payments have proper authorization.

Deficiency reporting: When internal audit finds that 3 out of 25 sampled payments lacked proper approval, they report this to the audit committee as a control deficiency.

Frequently Asked Questions

What does COSO stand for?

COSO stands for the Committee of Sponsoring Organizations of the Treadway Commission. It is a joint initiative of five professional organizations: AAA, AICPA, FEI, IMA, and IIA.

Is COSO a standard or a framework?

COSO is a framework, not a certifiable standard. Organizations use it as a reference for designing and evaluating internal controls. You cannot get 'COSO certified' the way you can get ISO 9001 certified.

What is the relationship between COSO and SOX?

SOX (Sarbanes-Oxley Act) requires public companies to evaluate internal control over financial reporting using a recognized framework. COSO is the most widely used framework for meeting this SOX requirement. COSO is the 'how'; SOX is the 'must.'

How many principles does COSO have?

The 2013 COSO Internal Control framework has 17 principles organized across the 5 components. Each principle represents a fundamental concept associated with its component.

Related Guides

Issuing organization: Committee of Sponsoring Organizations of the Treadway Commission (COSO)
Current version: Internal Control - Integrated Framework (2013)
Effective date: December 2014 (superseded 1992 framework)
Official source: https://www.coso.org
Last reviewed: August 2026
Back to Finance