Guide to COSO Framework and Compliance
The COSO Framework, developed by the Committee of Sponsoring Organizations of the Treadway Commission in 1992 to combat fraud, defines internal control as a process involving an entity’s leadership and personnel designed to provide reasonable assurance in achieving operational, reporting, and compliance objectives, and is adaptable across organizational structures, with its origins tracing back to a 1985 initiative aimed at understanding and reducing fraudulent financial reporting.
What Is the COSO Framework?
Fraud deterrence was the main impetus behind forming the Committee of Sponsoring Organizations of the Treadway Commission (COSO) and its 1992 framework for internal control: Internal Control—Integrated Framework.
Known as the COSO framework, this document provided the first standard definition of “internal control” and a system that organizations could use to assess the effectiveness of their internal controls.
COSO defines “internal control” as “…a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.”
Unpacking this definition reveals five concepts regarding internal controls:
- 1.Establishing them is a process, not a destination.
- 2.They help organizations to achieve objectives—operational, reporting, and compliance.
- 3.People put them into effect.
- 4.They can provide “reasonable assurance,” but not absolute assurance, to senior management and the board regarding:
- Effectiveness and efficiency of operations
- Reliability of financial reporting
- Compliance with applicable laws and regulations.
- 5.They can be adapted to the “entity” structure, applied entity-wide, or to one or more subsidiaries, divisions, operating units, or business processes.
The COSO Framework: A Short History
The Committee of Sponsoring Organizations (COSO) was initially organized in 1985 to sponsor the National Commission on Fraudulent Reporting (NCFR). Its member organizations were the American Accounting Association (AAA), the American Institute of Certified Public Accountants (AICPA), Financial Executives International (FEI), the Institute of Management Accountants (IMA), and the Institute of Internal Auditors (IIA).
The NCFR was formed to study why and how fraudulent financial reporting at organizations occurs and to recommend ways to reduce it. The NCFR’s 1987 report focused on internal financial controls, highlighting this crucial topic for perhaps the first time. It also pointed out that there was no standard definition of “internal control” and began a project to create one. The COSO internal control framework, published in 1992, was the result.
Twenty years would pass before an update to the COSO framework. Increased business complexity, globalization, and the ascendant role of IT in business operations were among the factors inspiring the update, released in May 2013.
COSO’s Main Elements
COSO’s five key components of internal control (described in more detail in the next section) are:
- Control environment
- Risk assessment
- Control activities
- Information and communication
- Monitoring activities
Each component includes principles—17 principles in all—with supporting “points of focus” to help design, implement, conduct, monitor, and assess internal control processes.
COSO has also published other documents to improve internal control management:
- Internal Control over External Financial Reporting (ICEFR): Compendium of Approaches and Examples—to help users apply the framework to external financial reporting objectives
- Illustrative Tools—to help users assess the effectiveness of a system of internal control based on requirements listed in the updated framework
The organization in 2004 issued a second framework: Enterprise Risk Management—Integrated Framework, updated in 2017.
What Are the 5 Components of COSO Framework?
COSO defines five risk management components, which are what an organization needs to achieve its objectives, each with corresponding principles:
1. Control environment
- Commitment to integrity and ethical values
- Independent Board of Directors’ oversight
- Structures, reporting lines, authorities, and responsibilities
- Attract, develop, and retain competent people
- People held accountable for internal control responsibilities
2. Risk assessment
- Clear objectives specified
- Risks identified to achievement of objectives
- Potential for fraud considered
- Significant changes identified and assessed
3. Control activities
- Clear objectives specified
- Risks identified to achievement of objectives
- Potential for fraud considered
- Significant changes identified and assessed
4. Information and communication
- Quality information obtained, generated and used
- Internal control information internally communicated
- Internal information externally communicated
5. Monitoring activities
- Ongoing or separate evaluations are conducted
- Internal control deficiencies evaluated and communicated
The five components comprise one face of the “COSO cube,” a three-dimensional framework defining internal control from varying perspectives.
- Operations controls
- Reporting controls
- Compliance controls
The third face represents an organization’s structure: units, divisions, or processes, each of which may or may not be affected by a particular internal control:
- Business unit activities
- Division and function controls
- Business entity-level controls
Benefits of using the COSO framework
The COSO framework offers several key benefits for organizations implementing it:
- Provides a common language for internal control concepts across the organization, facilitating communication and coordination.
- Helps design, implement, and evaluate internal controls more effectively. Principles and focus points guide the process.
- Clarifying organizational structure, reporting lines, authorities, and responsibilities supports accountability.
- Identifies and analyzes risks to achieving objectives, enabling risk management.
- Considers fraud potential when assessing risks, aiding prevention.
COSO Framework Limitations
While useful, the COSO framework has some limitations:
- Principles-based guidance, not prescriptive requirements. Implementation takes effort and judgment.
- Subjectivity in assessing effectiveness can lead to consistent application.
- Focus on financial reporting objectives may result in overlooking operational and compliance risks.
- More technical guidance on control methods for specific activities like IT security is needed.
- Ongoing monitoring and updating for changes adds to the administrative workload.
Overall, the COSO frameworks are excellent tools and have assisted organizations in establishing a solid and efficient system of internal controls and fraud protection policies and procedures over the years.
Probably one of the biggest limitations in any ERM framework doesn’t lie within the concepts of the framework itself, but in an area that’s often the most difficult to entirely control—the human factor. COSO admits that even with a well-designed internal control system, internal auditors cannot always uncover risks of human error, poor judgment, management overrides, or employees colluding to circumvent internal control.
To avoid the pitfalls inherent in any framework, more organizations are replacing manual processes with automated systems. Not only does this address many of the limitations of COSO frameworks, but also makes it easier to reduce risk to lower levels and mitigate internal control deficiencies.
What Are the 3 Types of Internal Controls for COSO?
When it was published in 1992, the COSO internal control framework established for the first time a standard, common definition of effective “internal control.” This definition refers to three types of risk management “objectives,” which is what a business hopes to achieve:
1. Operations Objectives
Concerns the effectiveness and efficiency of entity operations, including operational and financial performance goals and safeguarding assets against loss.
2. Reporting Objectives
Concerns internal and external reporting, financial and non-financial. These controls may encompass reliability, timeliness, transparency, or other concepts set forth by regulators or the organization’s policies.
3. Compliance Objectives
Concerns conformance to relevant laws and regulations.
These objectives form one face of the three-sided COSO “cube,” a three-dimensional model illustrating internal control from various perspectives. The other two dimensions depict “components,” what the entity needs to achieve its objectives, and the organizational structure.
Ten years after the publication of the original COSO framework, in 2002, Congress enacted the Sarbanes-Oxley Act (SOX), which requires that U.S. publicly listed companies report on the effectiveness of their ICFR using a suitable framework. Many companies use COSO’s Integrated Control—Integrated Framework to guide SOX compliance. They may utilize the document’s appendix, The Illustrative Tools for Assessing Effectiveness of a System of Internal Control, for templates and scenarios to use when applying the COSO framework.
What are the COSO Coverage Areas?
One of the three sides of the “COSO cube,” a three-dimensional illustration of how the COSO internal control framework may be applied, lists the areas of an entity to which COSO might be used to achieve operational financial and compliance objectives:
- Entity level
- Division
- Operating unit
- Function
These four coverage area criteria correlate to the top-down structure of a typical organization. They establish that the COSO framework can be used to gauge the effectiveness of controls for an enterprise as a whole or at the division, operating unit, or function level—and that control activities should take place at all these levels.
The higher the level, the more abstract their relation to financial reporting activities. Entity-level controls often have an indirect relationship to financial statements and can be harder to quantify than more direct process-level controls. Entity-level controls also vary according to an organization’s complexity and risk profile and must be evaluated qualitatively instead of quantitatively.
Relationship of ERM and Internal Controls
Adequate internal controls are essential to Enterprise Risk Management (ERM). ERM helps an organization manage risk at every level, from strategy-setting through review and revision, and uses internal controls to achieve four types of risk-management objectives:
- Strategic
- Operations
- Financial reporting
- Compliance
Recognizing the importance of ERM and internal control to successful enterprise governance and management, COSO has published an ERM framework as well as an internal control framework:
- COSO Internal Control—Integrated Framework (updated 2013)
- COSO Enterprise Risk Management—Integrating with Strategy and Performance (updated 2017)
The COSO ERM framework defines enterprise risk management as:
A process, effected by an entity’s board of directors, management, and other personnel, applied in strategy-setting and across the enterprise, designed to identify potential events that may affect the entity and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.
According to COSO, the COSO ERM framework is a strategic guide to meeting business objectives, while the COSO internal control framework is a tactical guide.
Although they differ in the key components they list, these are complementary and intended to be applied in tandem.
The internal control framework lists five critical components of internal control:
- 1.Control environment
- 2.Risk assessment
- 3.Control activities
- 4.Information and communication
- 5.Monitoring activities
The ERM framework lists five core business activities essential to sound risk management:
- 1.Governance and culture, including the formulating of mission and vision statements, board oversight, and executive management functions
- 2.Strategy and objective setting, in which executives and, possibly, the board, define organizational risk appetite and create a high-level plan for achieving corporate goals
- 3.Performance, in which risks are identified, assessed, and prioritized, and responses to risk implemented
- 4.Review and revision, which involves assessing performance and striving for continual improvement
- 5.Information, communication, and reporting, including the use of information technology
Components in the internal control framework correspond to those listed in the ERM framework. ERM and internal control go hand-in-hand; internal control is essential to ERM. One supports the other: having solid internal controls enables managers to focus on operations and business objectives, knowing that the organization has a robust risk management program and complies with applicable laws, regulations, and standards.
Internal Control-Integrated Framework (2013)
The new internal control framework fills in some of the 1992 framework gaps.
The addition of 17 principles, describing how to incorporate the five components into an effective internal control model, transformed the COSO framework into a blueprint for developing new internal controls. The new framework also incorporated internal controls for IT systems.
A huge leap in corporate governance and risk management, the new version still contains limitations.
The 2013 Framework postulates that to be effective, an internal control system must have all five components and 17 principles “present” and “functioning” and “operating together.” What it doesn’t address is the possibility that, due to size, country of operation, or industry of the business, certain principles may not apply.
In this case, according to the COSO Framework, a business has “major deficiencies” within the internal control system.
The limitations of the COSO framework in this instance is that it doesn’t offer guidance on how to adjust accordingly.
The New COSO ERM Framework (2017)
According to COSO’s FAQ publication regarding the new framework: “it provides greater insight into strategy and the role of enterprise risk management in the setting and execution of strategy, enhances the alignment between organizational performance and enterprise risk management, and accommodates expectations for governance and oversight.”
Industry leaders and Boards of Directors alike agree the new standards offer dramatic improvement in the areas of risk tolerance, risk appetite, and risk response. It’s also acknowledged that the 2017 Framework does a much better job of incorporating risk assessment, objective setting, corporate governance, and reporting objectives across all aspects of the organizational structure, rather than handling those items separately in a silo-based approach.
A noticeable inadequacy to the new risk management framework is a lack of discussion on issues revolving around risks from external parties or external events.
COSO also guides using both frameworks in its 2014 paper, Improving Organizational Performance and Governance: How the COSO Frameworks Can Help.
COSO Guidance for Health Care Providers
The COSO Internal Control-Integrated Framework: An Implementation Guide for the Healthcare Provider Industry, was published in 2013 by the Committee of Sponsoring Organizations (COSO) in collaboration with professional services firm Crowe and CommonSpirit Health.
The guide is meant to help healthcare businesses navigate the enormously complicated world of U.S. healthcare. It addresses subjects such as access control, system integrity, clinical documentation, coding, and billing procedures; all to help healthcare businesses comply with the Affordable Care Act of 2010, and to protect patient data while health records (EHR) have become the norm. COSO’s guidance provides an outline and best practices for meeting those standards.
“Healthcare organizations experience issues with system access, system integrity, clinical documentation, coding, and billing; all of which may result in potential non-compliance with federal and state regulations—and costly mistakes,” the guide’s executive summary states.
To meet those compliance obligations, the guide says, healthcare organizations “must review their control environment to confirm proper controls are in place to ensure effective and efficient operations, proper financial reporting, and compliance; and that their control environment supports the attainment of the organization’s mission and strategy; and COSO provides the direction to do this.”
How to Implement the COSO Framework
Implementing the COSO internal control framework requires assessing its five components (control environment, risk assessment, control activities, information and communication, and monitoring activities) and 17 principles against the organization’s current internal control system and adjusting accordingly.
Failing to enforce the COSO framework principles can violate the federal Sarbanes-Oxley Act’s (SOX) requirements. Auditors evaluating an organization’s ICFR will judge against this standard: When even one of the 17 principles doesn’t function properly, a “major deficiency” is deemed to exist—a “material weakness” under SOX Section 404.
The 17 internal control principles can serve as a handy checklist for enterprises to use to evaluate and strengthen their internal control system—but first, there is the groundwork to be laid. Applying COSO’s internal control or enterprise risk management (ERM) framework requires a systematic, step-by-step approach. To help, we’re providing this roadmap that includes implementation challenges and leading practices.
Implementing the COSO Framework in Five Phases
PHASE 1: PLAN AND SCOPE
Appoint an implementation team. Here’s how it works: The board delegates implementation authority to a committee such as an audit and compliance committee. Managers assign oversight to a management function in the organization, such as internal control or ERM. The team may include accounting managers, staff, and people with a thorough knowledge of how work gets done in the organization.
Develop an implementation plan that includes timing, resources needed, and roles and responsibilities of implementation team members. Determine the scope of the framework’s implementation: Which activities will it measure, and over what period?
At this point, the implementation team will also evaluate the five components of the COSO internal control framework to understand how the enterprise’s internal control system is designed and how well it functions.
In this phase, the implementation team should also meet with the external auditors who will be assessing the organization’s COSO compliance. They must learn their roles, avoid redundancies, and communicate the plan to the board and managers.
PHASE 2: ASSESS AND DOCUMENT
In this phase, the implementation team assesses the organization’s control structure. Are its systems centralized or decentralized? How are entity-level controls structured? Is there a formal ERM process with documented risk management activities? If so, the documents should help analyze where the organization meets COSO framework guidelines and where it falls short. If there is no coordinated approach to ERM, COSO implementation may require more time and effort.
Other activities during this phase include:
- Assess fraud risk. The COSO internal control framework emphasizes the importance of considering the potential for fraud when evaluating the risks to achieving objectives.
- Document existing processes and controls. Once managers have identified which processes are relevant to the framework’s control activities, the implementation team can study and record each. Doing so allows them to identify which internal controls apply to each process and where gaps exist. This step may involve interviews with key personnel.
- Perform gap assessments. This entails comparing the COSO internal control framework’s components and principles to practices in the organization. COSO’s publication Illustrative Tools for Assessing Effectiveness of a System of Internal Control can be helpful.
PHASE 3: REMEDIATE
Now that gap assessments are drawn up, it’s time to remediate those gaps.
- Make a remediation plan. Prioritize the control deficiencies that pose the most severe vulnerabilities and move down the list to the least serious. Include milestones and a schedule for completion.
- Implement your remediation plan.
PHASE 4: DESIGN, TEST, AND REPORT
- Classify controls as critical or non-critical
- Design procedures for testing each critical control. Each test should consider the risk to be mitigated and the control description—both are equally important to determining a control’s effectiveness. Choose a method of testing for each control. Common methods include:
- Inquiring: Asking control owners to explain how their controls work
- Observing: Observing the control in action
- Examining: Studying all the transactions and documentation associated with a control’s functioning
- Analyzing: Using data analytics tools to gain insights into controls’ design and operations
- Test controls, reporting to management on progress and obstacles.
PHASE 5: OPTIMIZE INTERNAL CONTROLS’ EFFECTIVENESS
How do identified risks and controls mesh with your enterprise’s goals, plans, and strategies? The COSO internal control framework can help you align or realign goals and controls. When developing or redesigning controls, consider the following:
- Control activities such as reconciliation, verification, supervisory, and physical controls
- Whether controls are preventive, detective, i.e., occurring after a process has begun but before it has concluded, or corrective
- Whether controls are automated, partially automated (automation enabled or assisted by people) or manual
Once controls are in place, monitoring is critical to ensuring they remain effective. Continuous monitoring with software is preferable to manual tracking. Should a control fail, study the incident carefully to determine its cause for the most effective remediation.
COSO Guidance on Cloud Computing Issues
COSO released another guidance document talking about how to apply COSO’s enterprise risk management framework for issues in cloud computing. Considering that just about every business is migrating to the cloud, and that the compliance risks within such migration can be considerable, this guidance is timely.
The guidance was published in July 2021—44 pages long, free to all, and written in clear, non-technical language that any compliance, audit, or risk professional can understand.
This piece follows the same pattern as prior COSO risk management guidance. It introduces the ERM framework overall (20 principles in all), and then explores how each principle can be tailored for the subject at hand. In this case the subject is cloud computing, but prior pieces of COSO guidance addressed ethics and compliance, cybersecurity, ESG issues, and other topics.
Why is such guidance important? Because cloud computing has become a central IT strategy for most businesses today. From an operations perspective, that makes sense; cloud-based services are cheap and easy to install, and the vendors themselves are probably better at whatever business process you’re outsourcing than you are.
That said, the cloud also poses new risks for privacy, security, and compliance; plus risks around operational resilience if you outsource critical functions to a vendor that can’t deliver. So corporate boards, CISOs, audit executives, and compliance officers all have great need to understand what “migrating to the cloud” really means. This COSO guidance unpacks many of those issues.