ZenGRC

COSO-Based Internal Auditing

The COSO Framework, developed by a U.S. commission formed in 1985 and sponsored by five major professional organizations, provides a comprehensive risk management and internal control framework widely used by internal audit and compliance departments to assess corporate risk, prevent fraud, and improve governance, with internal auditors playing a crucial role in evaluating and enhancing these controls while maintaining independence.

Internal audit and compliance departments benefit from having a comprehensive framework to perform corporate risk assessment and internal control testing, as well as to fight fraud. The most popular framework is the COSO Framework.

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) was formed in the United States in 1985 to combat corporate fraud. This commission developed recommendations for public companies, internal audit departments, and educational institutions. COSO provides thought leadership by developing comprehensive frameworks and guidance on internal controls, fraud prevention, and enterprise risk management.

COSO Internal Control-Integrated Framework

The COSO Internal Control-Integrated Framework provides an applied risk management approach to internal controls relevant to both external financial reporting and internal control activities. The framework aims to help companies, particularly publicly traded ones, reduce fraud and better manage risk via internal controls and executive oversight. Organizations that don’t meet COSO’s objectives can face problems such as corruption, fraud, and reputational damage.

Five organizations sponsor COSO: the Institute of Management Accountants (IMA), the American Accounting Association (AAA), the American Institute of Certified Public Accountants (AICPA), the Institute of Internal Auditors (IIA), and Financial Executives International (FEI).

The International Standards for the Professional Practice of Internal Auditing require internal audit activities to evaluate and contribute to the improvement of governance, risk management, and control processes. Internal auditors play a key role in assessing the effectiveness of an organization’s internal control system. They offer guidance to senior management and evaluate the internal control system, contributing to its continued effectiveness. To maintain independence, internal auditors should not have direct responsibility for designing, creating, or maintaining the controls they evaluate; they can only advise on improvements.

The COSO Framework helps organizations develop a system of internal control that adapts to changing business and operating environments, mitigates corporate risks to acceptable levels, and enables better business decisions. The framework defines an internal control system as “a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.”

According to the IIA, a control environment is the foundation on which an effective system of internal control is built and operated in a company that aims to:

  • Achieve its strategic objectives
  • Provide reliable financial reporting to internal and external stakeholders
  • Operate its business efficiently and effectively
  • Comply with all applicable laws and regulations
  • Safeguard its assets

The 2013 update to the COSO Internal Control-Integrated Framework broadened the application of internal control in addressing operations and reporting objectives and clarified the requirements for determining what constitutes effective internal control. The 2017 update to the COSO Enterprise Risk Management – Integrated Framework integrated risk considerations into the design and implementation of internal controls and strategic objectives.

Five Components of the COSO Internal Control-Integrated Framework

The COSO Internal Control-Integrated Framework is structured around five key components that form the foundation of a robust internal control system:

  1. 1.Control Environment: Sets the tone for the organization, encompassing integrity, ethical values, and the environment in which internal control operates. It establishes the discipline and structure that influence the effectiveness of internal controls.
  2. 2.Risk Assessment: A systematic approach to identifying and managing business and financial risks, ensuring that potential threats are recognized, assessed, and managed effectively.
  3. 3.Control Activities: Policies and procedures that help ensure management’s directives are carried out. These include approvals, verifications, reconciliations, and security measures designed to address and mitigate specific risks.
  4. 4.Information and Communication: Involves the identification, capture, and communication of pertinent information in a form and timeframe that enables people to carry out their responsibilities. Effective communication must flow down, across, and up the organization.
  5. 5.Monitoring: Continuous or periodic evaluations to ascertain whether each component of the internal control system is functioning as intended. Monitoring ensures that shortcomings are identified and addressed timely.

Beyond these core components, the COSO Framework is further refined by 17 principles associated with these components, offering a detailed structure for implementing and evaluating internal control. These principles provide a comprehensive approach for organizations to assess and enhance their internal control systems, ensuring effectiveness and efficiency in achieving business objectives, reliable financial reporting, and compliance with laws and regulations.

Control Environment

The control environment is the set of standards, processes, and structures that provide the foundation for carrying out internal control across a company. It is the most important component in the COSO-based audit framework. During an audit, the control environment is assessed via discussions with management and employees.

At the top, the board of directors and senior management set the tone as to the importance of internal control, including the standards of conduct the organization expects. Managers reinforce these expectations throughout the organization. Adequate training, written policies and procedures, and the general control structure are components of the control environment evaluation.

The five principles of the COSO control environment component are:

  • The company’s integrity and ethical values
  • The parameters that allow the board of directors to carry out governance oversight responsibilities
  • The company’s organizational structure and the assignment of responsibility and authority
  • The process for attracting, developing, and retaining competent employees
  • The care and thoroughness around performance measures, incentives, and rewards to ensure employees are accountable for their work

Risk Assessment

Every organization faces risks from external and internal sources. Risk is defined as the possibility that an event will happen and have a negative effect on the achievement of objectives.

Risk assessment involves identifying and assessing the risks to the achievement of objectives. Risks are related to established risk tolerances. Risk assessment is the basis for determining how a company will manage its risks.

Risk assessment requires management to consider the impacts of possible changes in the internal and external environments that may render its internal controls ineffective and then take action to manage those impacts.

The four principles of the COSO risk assessment component are:

  • Specify appropriate objectives
  • Identify and analyze risks
  • Evaluate fraud risks
  • Identify and analyze changes that could significantly affect internal controls

Control Activities

Control activities are policies, procedures, and internal controls put in place to mitigate risks to the achievement of objectives, particularly those deemed too risky during the risk assessment.

These activities are tested by management, staff, and internal auditors to ensure compliance. For example, if improper cash handling is the risk identified, a control activity might be to have two employees involved in cash payments.

Control activities are performed throughout a company, at all levels, and in all areas. They encompass manual and automated activities, including verifications, reconciliations, authorizations and approvals, asset safety, and business performance reviews.

The three principles of the COSO control activities component are:

  • Select and develop control activities that mitigate risks
  • Select and develop technology controls
  • Deploy control activities through policies and procedures

Information and Communication

Information systems play a major role in internal control systems because they produce reports, including operational and financial reports, as well as compliance-related information, which make the operation and control of the business possible.

Information is necessary for an organization to carry out its internal control responsibilities to support the achievement of its objectives. Management obtains or generates and uses relevant and quality information from internal and external sources to support the functioning of the internal control system.

Effective communication ensures that the information workers need to fulfill their responsibilities flows down, across, and up the company. This enables employees to receive a clear message from senior management that control responsibilities are taken seriously.

Effective communication with third parties, such as customers, suppliers, regulators, and shareholders, is also necessary. Inbound communication lets employees receive relevant information from third parties and provides information to third parties about the company’s requirements and expectations.

The three principles of the COSO information and communication component are:

  • The organization obtains or generates and uses relevant, quality information to support the functioning of internal control
  • The organization internally communicates the information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control
  • The organization communicates with third-party providers about things that affect the functioning of internal control

Monitoring Activities

Organizations must monitor their internal control system, a process that evaluates the quality of system performance over time. This can be done via ongoing monitoring evaluations, separate evaluations, or a combination of the two.

Ongoing evaluations, built into business processes at different levels, provide timely information. Separate evaluations, conducted periodically, will vary depending on risk assessment, effectiveness of ongoing evaluations, and other management considerations.

Deficiencies detected through monitoring activities must be reported to senior management, who must correct them to ensure continuous improvement of the system.

The two principles of the COSO monitoring activities component are:

  • The organization selects, develops, and performs ongoing and/or separate evaluations to determine if the components of internal control exist and are functioning
  • The organization evaluates and communicates internal control deficiencies in a timely manner to those responsible for corrective action, including the board of directors and senior management

How does COSO Framework Integrate with Risk Management in an Audit Process?

The COSO Framework plays a pivotal role in integrating risk management within the audit process. It provides a structured approach for identifying, assessing, and managing risks, which is essential for thorough auditing.

By aligning risk management with the framework’s five components – control environment, risk assessment, control activities, information and communication, and monitoring – auditors can ensure a comprehensive evaluation of an organization’s risk profile.

This integration helps in identifying potential risk areas, evaluating the effectiveness of current controls, and recommending enhancements to mitigate identified risks. The framework encourages a proactive approach to risk management, ensuring that risks are continuously identified, analyzed, and managed throughout the audit cycle.

This holistic view of risk management within the audit process leads to more effective decision-making and strengthens the organization’s overall internal control system.

How does the COSO Framework Assist Auditors in Evaluating Internal Controls?

The COSO Framework is an invaluable tool for auditors in evaluating an organization’s internal controls. It provides a well-defined structure that auditors can use to assess the effectiveness and efficiency of internal control systems.

Each of the five components of the COSO Framework offers specific criteria and principles that guide auditors in their evaluation. For instance, the control environment component helps assess the tone at the top and the overall governance structure of the organization. The risk assessment component aids in understanding how well the organization identifies and manages its risks.

Control activities focus on the policies and procedures in place to mitigate identified risks. The information and communication component evaluates how information flows within the organization and how well the control-related information is communicated. Lastly, the monitoring component assists in determining how effectively the organization assesses the performance of its internal controls over time.

By using the COSO Framework, auditors can provide a more thorough, consistent, and objective evaluation of internal controls, leading to more reliable and actionable audit results.

Developing Your Organization’s Internal Control System

Developing an effective internal control system within your organization is crucial for ensuring operational efficiency, reliability of financial reporting, and compliance with laws and regulations. The COSO Framework provides a comprehensive model for this development.

Start by establishing a strong control environment, setting the tone for integrity and ethical behavior at all levels of the organization. This involves defining clear roles, responsibilities, and lines of authority.

Next, conduct thorough risk assessments to identify and prioritize potential risks, followed by designing and implementing control activities tailored to mitigate these risks. Ensure that information pertinent to internal controls is captured and communicated effectively, enabling informed decision-making.

Lastly, institute a robust monitoring process to evaluate the internal control system’s effectiveness over time, making adjustments as necessary. By systematically implementing these steps, your organization can build a robust internal control system that supports business objectives and fosters a culture of accountability and continuous improvement.

Prepare for Your Internal Audit with ZenGRC

Preparing for your internal COSO audit is significantly streamlined with ZenGRC’s comprehensive software solutions. ZenGRC offers an integrated framework that aligns seamlessly with COSO’s internal control principles, ensuring thorough risk assessment and management. Its intuitive dashboard provides real-time visibility into your organization’s compliance status, enabling you to identify and address any gaps proactively.

The software’s robust reporting tools simplify the audit preparation process, offering clear and concise documentation that aligns with COSO’s guidelines. Additionally, ZenGRC’s automated features reduce the manual workload, allowing your team to focus on strategic aspects of the audit while ensuring accuracy and efficiency in compliance tracking.