- Get link
- X
- Other Apps
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) provides benchmark frameworks for internal control, enterprise risk management (ERM), and fraud deterrence. Its flagship model—the COSO Internal Control – Integrated Framework—visualizes internal control as a 3D matrix (the "COSO Cube") linking organizational objectives, core internal control components, and organizational structure.
Key Framework Dimensions
1. Three Objective Categories (Top Face)
- Operations: Effectiveness and efficiency of performance, including operational and financial performance goals and safeguarding assets.
- Reporting: Financial and non-financial reporting to internal and external stakeholders (reliability, timeliness, transparency).
- Compliance: Adherence to applicable laws, regulations, and statutory mandates.
2. Five Integrated Components (Front Face)
- Control Environment: The governance foundation—tone at the top, ethical standards, organizational structure, and assignment of authority.
- Risk Assessment: Identifying and analyzing risks to achieving objectives, including fraud risk and corporate changes.
- Control Activities: Policies and procedures established to mitigate risk (e.g., authorizations, reconciliations, segregation of duties).
- Information & Communication: Relevant, quality data flow running vertically and horizontally across the enterprise.
- Monitoring Activities: Ongoing evaluations and separate audits (internal/external) to verify controls function as designed.
3. Organizational Structure (Side Face) Applies systematically from the enterprise level down through divisions, operating units, and business functions.
How Internal vs. External Audit Map to COSO
| Audit Function | Scope within COSO | Primary Role & Interaction |
|---|---|---|
| Internal Audit (IA) | All 5 Components across Operations, Reporting, and Compliance. | Acts as part of the Monitoring Activities component. IA tests the design and operating effectiveness of the entire internal control system continuously. |
| External Audit (EA) | Focused on Financial Reporting & related Control Activities / Environment. | Evaluates the control structure to determine audit risk and provide external assurance on whether financial controls prevent material misstatement. |
Comments