COSO Internal Control-Integrated Framework
Also known as: COSO IC
Five-component framework for designing internal controls: control environment, risk assessment, control activities, information and communication, monitoring.
The COSO Internal Control — Integrated Framework, originally published in 1992 and substantially revised in 2013, is the dominant US framework for designing, implementing, and evaluating internal controls. It defines internal control as a process effected by board, management, and other personnel to provide reasonable assurance regarding objectives in operations, reporting, and compliance, organized through five components and (in the 2013 revision) seventeen principles. Following Sarbanes-Oxley, the SEC and PCAOB endorsed the framework as a suitable basis for management's Section 404 ICFR assessment, making it the de facto standard at US registrants and a foundational reference globally. COSO ERM, the related enterprise risk management framework, was developed as a complementary structure rather than a replacement.
Core components
- Five components: Control Environment
- Risk Assessment
- Control Activities
- Information and Communication
- Monitoring Activities
- Seventeen principles (added in 2013)
- Three categories of objectives (operations, reporting, compliance)
- Entity, division, operating unit, and function levels
Primary use case
Design and assessment of internal control over financial reporting (ICFR) at SEC registrants; broader internal control program design at non-public organizations.
Common criticisms
- Seventeen principles can drive checklist compliance and substantial documentation overhead
- focus on financial reporting controls historically overshadowed operations and compliance objective categories
- principles abstraction creates implementation variability
- substantial overlap with COSO ERM creates confusion about which framework governs which decisions.
Lineage
- Parent of
- COSO ERM
- Siblings
- COSO ERM, ISO 31000, Three Lines Model, Sarbanes-Oxley