Internal control objectives and the COSO Framework
Learning outcome statements
The learning outcome statements relevant for this section are:
- demonstrate an understanding of internal control risk and the management of internal control risk
- identify and describe internal control objectives
- describe how internal controls are designed to provide reasonable (but not absolute) assurance regarding achievement of an entity’s objectives involving (i) effectiveness and efficiency of operations, (ii) reliability of financial reporting, and (iii) compliance with applicable laws and regulations
- explain why personnel policies and procedures are integral to an efficient control environment
- define and give examples of segregation of duties
- explain why the following four types of functional responsibilities should be performed by different departments or different people within the same function: (i) authority to execute transactions, (ii) recording transactions, (iii) custody of assets involved in the transactions, and (iv) periodic reconciliations of the existing assets to recorded amounts
- identify and describe the five major components of COSO’s Internal Control— Integrated Framework
- assess the level of internal control risk within an organization and recommend risk mitigation strategies
- define and distinguish between preventive controls and detective controls
- identify and explain methods for testing the adequacy of internal controls, including inquiry, observation, inspection, and re-performance
- explain how to remediate internal control deficiencies
- demonstrate an understanding of the importance of independent checks and verification
- identify examples of safeguarding controls
- explain how the use of prenumbered forms, as well as specific policies and procedures detailing who is authorized to receive specific documents, is a means of control
Internal control objectives
Internal control objectives refer to the specific goals that an internal control system is designed to achieve. According to COSO, the overall aim of internal control is to provide reasonable assurance that an organization will achieve its objectives in three key categories:
1. Operations
Focuses on the effectiveness and efficiency of operations, including achieving performance and profitability targets while safeguarding resources against loss. Controls help ensure that business processes use resources optimally and support sustainable performance.
2. Reporting
Addresses the reliability of financial and non-financial reporting. Controls are designed to ensure that information is accurate, complete, and timely, providing stakeholders with credible data for decision-making.
3. Compliance
Ensures adherence to applicable laws, regulations, and internal policies. Strong compliance controls protect the organization from legal penalties, reputational damage, and potential disruptions to operations.
The COSO Internal Control - Integrated Framework
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) was established in 1985 as a joint initiative among five private sector organizations to combat fraudulent financial reporting. Over time, its work expanded into the broader domain of enterprise risk management, internal control, and fraud deterrence. The most recognized contribution of COSO is the Internal Control—Integrated Framework, initially released in 1992 and further updated in subsequent years. This framework has become the leading model for designing, implementing, and evaluating internal controls in organizations worldwide.
COSO defines internal control as “a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives related to operations, reporting, and compliance.”
The five components of internal control
The COSO framework is built upon five interrelated components, often referred to as the five pillars, which are further broken down into 17 guiding principles. These pillars serve as the foundation for implementing effective internal controls. This will be revisited in Section F about data governance.
Together, these five components provide a comprehensive framework for designing and evaluating internal control systems that help organizations achieve their objectives.
Pillar 1: Control Environment
This is the foundation of all other components. It reflects the organization’s overall attitude, awareness, and actions regarding internal controls and ethical behavior. Key elements include integrity and ethical values, board oversight, the organizational structure, and human resource policies. A strong control environment sets the tone for the importance of internal controls within the organization.
Pillar 2: Risk Assessment
Organizations must identify and analyze risks that may hinder the achievement of objectives. This component involves setting clear objectives, identifying potential events that could impact those objectives, assessing the likelihood and impact of those risks, and determining how to manage them.
Pillar 3: Control Activities
These are the policies and procedures put in place to ensure that management’s directives are carried out. Examples include approvals, authorizations, verifications, reconciliations, and segregation of duties. Control activities occur throughout the organization, at all levels and in all functions.
Pillar 4: Information and Communication
Relevant information must be identified, captured, and communicated in a timely and effective manner. This includes internal and external communications that support the functioning of internal controls. Open lines of communication across all levels of the organization are essential.
Pillar 5: Monitoring Activities
Monitoring involves the ongoing evaluation of the internal control system to ensure it is functioning as intended. It may include regular management and supervisory activities, separate evaluations (such as internal audits), and corrective actions in response to identified issues.