COSO framework
Also known as: COSO internal control framework, COSO Internal Control — Integrated Framework
The COSO framework is the most widely used model for designing and evaluating internal control, published by the Committee of Sponsoring Organizations of the Treadway Commission. It organizes internal control into five integrated components supporting operations, reporting, and compliance objectives.
The COSO framework — formally the Internal Control — Integrated Framework from the Committee of Sponsoring Organizations of the Treadway Commission — is the standard reference for how organizations design, implement, and assess internal control. Public companies commonly use it when management evaluates internal control over financial reporting, as required under the Sarbanes-Oxley Act.
The framework defines internal control as a process, driven by people at every level, that provides reasonable assurance — not a guarantee — that the organization will achieve objectives in three categories: effective and efficient operations, reliable reporting, and compliance with laws and regulations.
COSO organizes internal control into five integrated components: the control environment (the tone at the top, integrity, and accountability structures), risk assessment (identifying and analyzing risks to objectives), control activities (the policies and procedures, such as approvals, reconciliations, and segregation of duties, that address those risks), information and communication (getting relevant, quality information to the people who need it), and monitoring activities (ongoing and separate evaluations of whether controls are functioning). The framework further breaks these components into 17 supporting principles, and all five components must be present and working together for internal control to be considered effective.
The COSO framework is core testable material on the CMA Part 1 exam, which covers internal controls, governance, risk, and compliance. Candidates should be able to name the five components, match example controls to the correct component, and explain the reasonable-assurance concept and the framework's three objective categories.
Key takeaways
- COSO is the dominant framework for designing and evaluating internal control, and it underpins Sarbanes-Oxley internal control assessments.
- Internal control provides reasonable assurance — never absolute assurance — of achieving objectives.
- Objectives fall into three categories: operations, reporting, and compliance.
- The five components are control environment, risk assessment, control activities, information and communication, and monitoring.
- CMA Part 1 tests the five components, the 17 principles concept, and how example controls map to each component.
