Achievable logoAchievable logo
CMA Part 1
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Exam catalog
Mountain with a flag at the peak
Textbook
1. External financial reporting decisions
2. Planning, budgeting, and forecasting
3. Performance management
4. Cost management
5. Internal control
5.1 Governance, risk and compliance
5.1.1 Internal control objectives and the COSO Framework
5.1.2 Responsibility for internal control and segregation of duties
5.1.3 Internal control limitations, risks, and deficiencies
5.1.4 Corporate governance structure and responsibilities
5.1.5 Corporate governance roles and responsibilities
5.1.6 External audit
5.1.7 The Sarbanes-oxley Act
5.1.8 Other regulatory bodies
5.2 System controls and security measures
6. Technology and analytics
Achievable logoAchievable logo
5.1.1 Internal control objectives and the COSO Framework
Achievable CMA Part 1
5. Internal control
5.1. Governance, risk and compliance
Our CMA Part 1 course is currently in development and is a work-in-progress.

Internal control objectives and the COSO Framework

6 min read
Font
Discuss
Share
Feedback

Learning outcome statements

The learning outcome statements relevant for this section are:

  1. demonstrate an understanding of internal control risk and the management of internal control risk
  2. identify and describe internal control objectives
  3. describe how internal controls are designed to provide reasonable (but not absolute) assurance regarding achievement of an entity’s objectives involving (i) effectiveness and efficiency of operations, (ii) reliability of financial reporting, and (iii) compliance with applicable laws and regulations
  4. explain why personnel policies and procedures are integral to an efficient control environment
  5. define and give examples of segregation of duties
  6. explain why the following four types of functional responsibilities should be performed by different departments or different people within the same function: (i) authority to execute transactions, (ii) recording transactions, (iii) custody of assets involved in the transactions, and (iv) periodic reconciliations of the existing assets to recorded amounts
  7. identify and describe the five major components of COSO’s Internal Control— Integrated Framework
  8. assess the level of internal control risk within an organization and recommend risk mitigation strategies
  9. define and distinguish between preventive controls and detective controls
  10. identify and explain methods for testing the adequacy of internal controls, including inquiry, observation, inspection, and re-performance
  11. explain how to remediate internal control deficiencies
  12. demonstrate an understanding of the importance of independent checks and verification
  13. identify examples of safeguarding controls
  14. explain how the use of prenumbered forms, as well as specific policies and procedures detailing who is authorized to receive specific documents, is a means of control

Internal control objectives

Internal control objectives refer to the specific goals that an internal control system is designed to achieve. According to COSO, the overall aim of internal control is to provide reasonable assurance that an organization will achieve its objectives in three key categories:

1. Operations

Focuses on the effectiveness and efficiency of operations, including achieving performance and profitability targets while safeguarding resources against loss. Controls help ensure that business processes use resources optimally and support sustainable performance.

2. Reporting

Addresses the reliability of financial and non-financial reporting. Controls are designed to ensure that information is accurate, complete, and timely, providing stakeholders with credible data for decision-making.

3. Compliance

Ensures adherence to applicable laws, regulations, and internal policies. Strong compliance controls protect the organization from legal penalties, reputational damage, and potential disruptions to operations.

Sidenote
Reasonable assurance vs. absolute assurance

Internal controls are designed to provide reasonable assurance, not absolute assurance. This distinction is critical because:

  • Internal control systems operate in environments of uncertainty and human judgment.
  • There are limitations such as collusion, management override, and unforeseen external circumstances.
  • Controls are subject to cost-benefit considerations and may not eliminate all risks.

As such, internal controls increase the likelihood of achieving organizational objectives but cannot guarantee success or eliminate all risks.

The COSO Internal Control - Integrated Framework

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) was established in 1985 as a joint initiative among five private sector organizations to combat fraudulent financial reporting. Over time, its work expanded into the broader domain of enterprise risk management, internal control, and fraud deterrence. The most recognized contribution of COSO is the Internal Control—Integrated Framework, initially released in 1992 and further updated in subsequent years. This framework has become the leading model for designing, implementing, and evaluating internal controls in organizations worldwide.

COSO defines internal control as “a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives related to operations, reporting, and compliance.”

The five components of internal control

The COSO framework is built upon five interrelated components, often referred to as the five pillars, which are further broken down into 17 guiding principles. These pillars serve as the foundation for implementing effective internal controls. This will be revisited in Section F about data governance.

Sidenote
Acronym to remember: CRIME

These components are often remembered using the acronym CRIME, which provides an easy way to recall the framework while preparing for the CMA exam.

COSO internal control integrated framework acronym
COSO internal control integrated framework acronym

Together, these five components provide a comprehensive framework for designing and evaluating internal control systems that help organizations achieve their objectives.

Pillar 1: Control Environment

This is the foundation of all other components. It reflects the organization’s overall attitude, awareness, and actions regarding internal controls and ethical behavior. Key elements include integrity and ethical values, board oversight, the organizational structure, and human resource policies. A strong control environment sets the tone for the importance of internal controls within the organization.

It includes principles such as:

  1. Demonstrating commitment to integrity and ethical values.
  2. Exercising oversight responsibility for internal controls and governance.
  3. Establishing structures, authority, and responsibility for data management.
  4. Demonstrating commitment to attract, develop, and retain competent individuals.
  5. Holding individuals accountable for their responsibilities in governance frameworks. \

Pillar 2: Risk Assessment

Organizations must identify and analyze risks that may hinder the achievement of objectives. This component involves setting clear objectives, identifying potential events that could impact those objectives, assessing the likelihood and impact of those risks, and determining how to manage them.

This includes:

  1. Specifying suitable objectives related to data governance and management.
  2. Identifying and analyzing risks that could impact data integrity.
  3. Assessing fraud risks related to data security and compliance.
  4. Identifying and responding to changes that may affect data governance policies.

Pillar 3: Control Activities

These are the policies and procedures put in place to ensure that management’s directives are carried out. Examples include approvals, authorizations, verifications, reconciliations, and segregation of duties. Control activities occur throughout the organization, at all levels and in all functions.

Principles include:

  1. Selecting and developing control activities to mitigate data risks.
  2. Deploying technology controls to support data integrity and security.
  3. Establishing policies and procedures that define data handling and management practices.

Pillar 4: Information and Communication

Relevant information must be identified, captured, and communicated in a timely and effective manner. This includes internal and external communications that support the functioning of internal controls. Open lines of communication across all levels of the organization are essential.

This includes:

  1. Utilizing relevant, quality information to support data governance.
  2. Communicating internal control responsibilities clearly.
  3. Ensuring external communication regarding data governance is transparent and consistent.

Pillar 5: Monitoring Activities

Monitoring involves the ongoing evaluation of the internal control system to ensure it is functioning as intended. It may include regular management and supervisory activities, separate evaluations (such as internal audits), and corrective actions in response to identified issues.

Principles include:

  1. Conducting ongoing and periodic evaluations to maintain governance effectiveness.
  2. Implementing corrective actions to address deficiencies and improve data governance.

Internal control objectives

  • Three categories: operations, reporting, compliance
    • Operations: effectiveness, efficiency, resource safeguarding
    • Reporting: reliability, accuracy, completeness, timeliness
    • Compliance: adherence to laws, regulations, policies
  • Controls provide reasonable, not absolute, assurance
    • Limitations: human error, collusion, management override, cost-benefit constraints

The COSO Internal Control - Integrated Framework

  • COSO: leading framework for internal control design and evaluation
  • Internal control defined as a process for reasonable assurance of achieving objectives in operations, reporting, compliance
  • Five interrelated components (CRIME acronym)

Control Environment

  • Foundation for all other components
  • Emphasizes integrity, ethical values, and board oversight
  • Key elements:
    • Organizational structure and HR policies
    • Accountability for responsibilities

Risk Assessment

  • Identifies and analyzes risks to objectives
  • Involves setting objectives, risk identification, and risk management
  • Includes fraud risk assessment and response to changes

Control Activities

  • Policies and procedures to carry out management directives
  • Examples: approvals, authorizations, verifications, reconciliations, segregation of duties
  • Includes technology controls and data handling policies

Information and Communication

  • Timely, relevant information capture and dissemination
  • Clear communication of internal control responsibilities
  • Ensures transparency in internal and external communications

Monitoring Activities

  • Ongoing and periodic evaluation of controls
  • Management and supervisory reviews, internal audits
  • Corrective actions to address deficiencies and improve effectiveness

Sign up for free to take 9 quiz questions on this topic

Previous
Next  | 5.1.2 Responsibility for internal control and segregation of duties
All rights reserved ©2016 - 2026 Achievable, Inc.

Internal control objectives and the COSO Framework

Learning outcome statements

The learning outcome statements relevant for this section are:

  1. demonstrate an understanding of internal control risk and the management of internal control risk
  2. identify and describe internal control objectives
  3. describe how internal controls are designed to provide reasonable (but not absolute) assurance regarding achievement of an entity’s objectives involving (i) effectiveness and efficiency of operations, (ii) reliability of financial reporting, and (iii) compliance with applicable laws and regulations
  4. explain why personnel policies and procedures are integral to an efficient control environment
  5. define and give examples of segregation of duties
  6. explain why the following four types of functional responsibilities should be performed by different departments or different people within the same function: (i) authority to execute transactions, (ii) recording transactions, (iii) custody of assets involved in the transactions, and (iv) periodic reconciliations of the existing assets to recorded amounts
  7. identify and describe the five major components of COSO’s Internal Control— Integrated Framework
  8. assess the level of internal control risk within an organization and recommend risk mitigation strategies
  9. define and distinguish between preventive controls and detective controls
  10. identify and explain methods for testing the adequacy of internal controls, including inquiry, observation, inspection, and re-performance
  11. explain how to remediate internal control deficiencies
  12. demonstrate an understanding of the importance of independent checks and verification
  13. identify examples of safeguarding controls
  14. explain how the use of prenumbered forms, as well as specific policies and procedures detailing who is authorized to receive specific documents, is a means of control

Internal control objectives

Internal control objectives refer to the specific goals that an internal control system is designed to achieve. According to COSO, the overall aim of internal control is to provide reasonable assurance that an organization will achieve its objectives in three key categories:

1. Operations

Focuses on the effectiveness and efficiency of operations, including achieving performance and profitability targets while safeguarding resources against loss. Controls help ensure that business processes use resources optimally and support sustainable performance.

2. Reporting

Addresses the reliability of financial and non-financial reporting. Controls are designed to ensure that information is accurate, complete, and timely, providing stakeholders with credible data for decision-making.

3. Compliance

Ensures adherence to applicable laws, regulations, and internal policies. Strong compliance controls protect the organization from legal penalties, reputational damage, and potential disruptions to operations.

Sidenote
Reasonable assurance vs. absolute assurance

Internal controls are designed to provide reasonable assurance, not absolute assurance. This distinction is critical because:

  • Internal control systems operate in environments of uncertainty and human judgment.
  • There are limitations such as collusion, management override, and unforeseen external circumstances.
  • Controls are subject to cost-benefit considerations and may not eliminate all risks.

As such, internal controls increase the likelihood of achieving organizational objectives but cannot guarantee success or eliminate all risks.

The COSO Internal Control - Integrated Framework

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) was established in 1985 as a joint initiative among five private sector organizations to combat fraudulent financial reporting. Over time, its work expanded into the broader domain of enterprise risk management, internal control, and fraud deterrence. The most recognized contribution of COSO is the Internal Control—Integrated Framework, initially released in 1992 and further updated in subsequent years. This framework has become the leading model for designing, implementing, and evaluating internal controls in organizations worldwide.

COSO defines internal control as “a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives related to operations, reporting, and compliance.”

The five components of internal control

The COSO framework is built upon five interrelated components, often referred to as the five pillars, which are further broken down into 17 guiding principles. These pillars serve as the foundation for implementing effective internal controls. This will be revisited in Section F about data governance.

Sidenote
Acronym to remember: CRIME

These components are often remembered using the acronym CRIME, which provides an easy way to recall the framework while preparing for the CMA exam.

Together, these five components provide a comprehensive framework for designing and evaluating internal control systems that help organizations achieve their objectives.

Pillar 1: Control Environment

This is the foundation of all other components. It reflects the organization’s overall attitude, awareness, and actions regarding internal controls and ethical behavior. Key elements include integrity and ethical values, board oversight, the organizational structure, and human resource policies. A strong control environment sets the tone for the importance of internal controls within the organization.

It includes principles such as:

  1. Demonstrating commitment to integrity and ethical values.
  2. Exercising oversight responsibility for internal controls and governance.
  3. Establishing structures, authority, and responsibility for data management.
  4. Demonstrating commitment to attract, develop, and retain competent individuals.
  5. Holding individuals accountable for their responsibilities in governance frameworks. \

Pillar 2: Risk Assessment

Organizations must identify and analyze risks that may hinder the achievement of objectives. This component involves setting clear objectives, identifying potential events that could impact those objectives, assessing the likelihood and impact of those risks, and determining how to manage them.

This includes:

  1. Specifying suitable objectives related to data governance and management.
  2. Identifying and analyzing risks that could impact data integrity.
  3. Assessing fraud risks related to data security and compliance.
  4. Identifying and responding to changes that may affect data governance policies.

Pillar 3: Control Activities

These are the policies and procedures put in place to ensure that management’s directives are carried out. Examples include approvals, authorizations, verifications, reconciliations, and segregation of duties. Control activities occur throughout the organization, at all levels and in all functions.

Principles include:

  1. Selecting and developing control activities to mitigate data risks.
  2. Deploying technology controls to support data integrity and security.
  3. Establishing policies and procedures that define data handling and management practices.

Pillar 4: Information and Communication

Relevant information must be identified, captured, and communicated in a timely and effective manner. This includes internal and external communications that support the functioning of internal controls. Open lines of communication across all levels of the organization are essential.

This includes:

  1. Utilizing relevant, quality information to support data governance.
  2. Communicating internal control responsibilities clearly.
  3. Ensuring external communication regarding data governance is transparent and consistent.

Pillar 5: Monitoring Activities

Monitoring involves the ongoing evaluation of the internal control system to ensure it is functioning as intended. It may include regular management and supervisory activities, separate evaluations (such as internal audits), and corrective actions in response to identified issues.

Principles include:

  1. Conducting ongoing and periodic evaluations to maintain governance effectiveness.
  2. Implementing corrective actions to address deficiencies and improve data governance.
Key points

Internal control objectives

  • Three categories: operations, reporting, compliance
    • Operations: effectiveness, efficiency, resource safeguarding
    • Reporting: reliability, accuracy, completeness, timeliness
    • Compliance: adherence to laws, regulations, policies
  • Controls provide reasonable, not absolute, assurance
    • Limitations: human error, collusion, management override, cost-benefit constraints

The COSO Internal Control - Integrated Framework

  • COSO: leading framework for internal control design and evaluation
  • Internal control defined as a process for reasonable assurance of achieving objectives in operations, reporting, compliance
  • Five interrelated components (CRIME acronym)

Control Environment

  • Foundation for all other components
  • Emphasizes integrity, ethical values, and board oversight
  • Key elements:
    • Organizational structure and HR policies
    • Accountability for responsibilities

Risk Assessment

  • Identifies and analyzes risks to objectives
  • Involves setting objectives, risk identification, and risk management
  • Includes fraud risk assessment and response to changes

Control Activities

  • Policies and procedures to carry out management directives
  • Examples: approvals, authorizations, verifications, reconciliations, segregation of duties
  • Includes technology controls and data handling policies

Information and Communication

  • Timely, relevant information capture and dissemination
  • Clear communication of internal control responsibilities
  • Ensures transparency in internal and external communications

Monitoring Activities

  • Ongoing and periodic evaluation of controls
  • Management and supervisory reviews, internal audits
  • Corrective actions to address deficiencies and improve effectiveness

More from Governance, risk and compliance

  • Responsibility for internal control and segregation of duties
  • Internal control limitations, risks, and deficiencies
  • Corporate governance structure and responsibilities
  • Corporate governance roles and responsibilities
  • External audit