COSO Internal Control-Integrated Framework

Also known as: COSO IC

framework · governance and compliance · regulatory-standard

Five-component framework for designing internal controls: control environment, risk assessment, control activities, information and communication, monitoring.

The COSO Internal Control — Integrated Framework, originally published in 1992 and substantially revised in 2013, is the dominant US framework for designing, implementing, and evaluating internal controls. It defines internal control as a process effected by board, management, and other personnel to provide reasonable assurance regarding objectives in operations, reporting, and compliance, organized through five components and (in the 2013 revision) seventeen principles. Following Sarbanes-Oxley, the SEC and PCAOB endorsed the framework as a suitable basis for management's Section 404 ICFR assessment, making it the de facto standard at US registrants and a foundational reference globally. COSO ERM, the related enterprise risk management framework, was developed as a complementary structure rather than a replacement.

Originators

Committee of Sponsoring Organizations of the Treadway Commission (COSO) high

Year / Decade

1992 (original); 2013 (revision) high

Primary sources

COSO (1992). Internal Control — Integrated Framework, COSO (2013). Internal Control — Integrated Framework (revised) high

Core components

Primary use case

Design and assessment of internal control over financial reporting (ICFR) at SEC registrants; broader internal control program design at non-public organizations.

Common criticisms

Lineage

Parent of
COSO ERM
Siblings
COSO ERM, ISO 31000, Three Lines Model, Sarbanes-Oxley