COSO (Committee of Sponsoring Organizations)

Updated

COSO is the Committee of Sponsoring Organizations of the Treadway Commission, and "COSO" is shorthand for the internal-control framework it publishes. The COSO Internal Control—Integrated Framework (2013) is the model most US public companies use to design and evaluate internal control over financial reporting, making it the de facto backbone of SOX §404 compliance.

The framework organizes internal control into five interrelated components — control environment, risk assessment, control activities, information and communication, and monitoring activities — and elaborates them into seventeen supporting principles. COSO also publishes a separate Enterprise Risk Management framework (2017) for managing risk more broadly across an organization.

What COSO is

COSO is a private-sector body formed by five accounting and finance organizations to provide thought leadership on internal control, risk management, and fraud deterrence. Its best-known output is the Internal Control—Integrated Framework, first issued in 1992 and updated in 2013, which defines internal control as a process designed to provide reasonable assurance over operations, reporting, and compliance objectives.

COSO is a framework, not a law. It has regulatory weight because the US Securities and Exchange Commission accepts a suitable, recognized control framework for management's assessment under Sarbanes-Oxley §404, and COSO is the framework nearly all filers use. That is why SOX programs are almost always structured around COSO's components and principles.

The five components and seventeen principles

The 2013 framework groups internal control into five components, each supported by principles that must be present and functioning for the system of internal control to be considered effective. The seventeen principles distribute across the five components as follows.

COSO 2013 components and their supporting principles
ComponentWhat it coversPrinciples
Control environmentIntegrity, ethical values, board oversight, structure, and accountability that set the tone for control.1–5
Risk assessmentSetting objectives and identifying and analyzing risks to achieving them, including fraud risk and change.6–9
Control activitiesThe policies and procedures — including IT general controls — that mitigate identified risks.10–12
Information and communicationProducing and sharing relevant, quality information internally and externally to support control.13–15
Monitoring activitiesOngoing and separate evaluations that confirm the components are present and functioning, and reporting deficiencies.16–17

COSO and SOX

In a SOX program, COSO supplies the structure and the internal-control detail sits in the controls themselves. Management scopes the systems and processes relevant to financial reporting, maps controls (including IT general controls) to COSO's components and principles, and then tests whether those controls operate. A gap at the principle level — say, monitoring activities that never actually run — is what an evaluator flags when weighing whether internal control is effective.

COSO's Enterprise Risk Management—Integrating with Strategy and Performance framework (2017) is a distinct, broader model for managing risk across strategy and operations, not just financial-reporting control. Teams sometimes conflate the two; the 2013 internal-control framework is the one referenced in ICFR and SOX work, while the ERM framework addresses enterprise-wide risk governance.

Frequently asked questions

What are the five components of the COSO framework?

Control environment, risk assessment, control activities, information and communication, and monitoring activities. In the 2013 Internal Control—Integrated Framework these five components are supported by seventeen principles, all of which are expected to be present and functioning for a system of internal control to be judged effective.

Is COSO required by SOX?

SOX does not name COSO, but it requires management to base its §404 assessment on a suitable, recognized control framework. The SEC accepts such frameworks, and COSO's Internal Control—Integrated Framework is the one almost all US public companies use, so in practice SOX programs are built on COSO.

What is the difference between the COSO internal control and ERM frameworks?

The Internal Control—Integrated Framework (2013) focuses on internal control over operations, reporting, and compliance, and underpins ICFR and SOX work. The Enterprise Risk Management framework (2017) is broader, addressing how an organization manages risk across strategy and performance. They are complementary but distinct publications.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.