The 5 components and 17 principles of COSO’s internal control framework
An effective internal control system needs more than individual policies or control activities. Organizations also need the right oversight, risk assessment, information, communication, and monitoring processes to make those controls work.
The COSO internal control framework organizes these requirements into five components and 17 principles. The 2013 framework uses these principles to make the requirements for effective internal control more explicit and to provide a structure for designing and evaluating internal controls.
This guide explains each component and its principles, with practical examples of how to apply them in an organization.
The components and principles of the COSO internal control framework
The five components are:
| Components | Number of principles | focus |
| Control environment | 5 | Culture, oversight, accountability, and organizational structure |
| Risk assessment | 4 | Identifying and assessing risks to objectives |
| Control activities | 3 | Actions that address identified risks |
| Information and communication | 3 | Getting relevant information to the right people |
| Monitoring activities | 2 | Checking whether controls continue to function effectively |
The components are interconnected, not separate steps. For example, risk assessment can identify a need for access controls, control activities can establish those controls, information and communication can ensure the responsible teams understand them, and monitoring can determine whether they continue to work.
Let’s explore the components and principles of the COSO internal control framework in detail.
1. Control environment
The control environment sets the organizational conditions in which internal control operates. It covers standards of conduct, oversight, organizational structure, competence, and accountability. COSO describes it as the basis for carrying out internal control across the organization.
It contains five principles.
Principle 1: Commit to integrity and ethical values
Management and the board should establish and reinforce expectations around ethical behavior and integrity.
Example: An organization establishes a code of conduct, provides ethics training, and requires employees to report suspected misconduct through defined channels.
Principle 2: Exercise oversight responsibility
The board or other governing body should oversee internal controls rather than leaving responsibility entirely to management.
Example: The audit committee regularly reviews significant control deficiencies and asks management about remediation progress.
Principle 3: Establish structure, authority, and responsibility
The organization should define reporting lines, responsibilities, and decision-making authority so people know who owns each control and objective.
Example: A company assigns ownership for user access reviews to the IT security team and establishes who approves exceptions.
Principle 4: Demonstrate commitment to competence
The organization should make sure people have the knowledge and skills needed to perform their responsibilities.
Example: Employees responsible for financial controls receive training on the organization’s accounting systems and relevant control procedures.
Principle 5: Enforce accountability
People should be held accountable for their internal control responsibilities and performance.
Example: Control owners must complete quarterly control reviews and address deficiencies within assigned deadlines.
2. Risk assessment
Risk assessment helps an organization identify and analyze risks that could prevent it from achieving its objectives. It also considers fraud and significant changes that could affect those risks.
Quick link: A practical guide to cyber security risk assessment
This component contains four principles.
Principle 6: Specify suitable objectives
The organization needs clear objectives to identify and assess risks.
Example: Instead of setting a broad objective to improve financial reporting, management defines a specific objective around producing accurate and timely financial reports.
Principle 7: Identify and analyze risk
The organization should identify risks that could affect its objectives and assess their significance.
Example: Before launching a new customer portal, the organization assesses risks involving unauthorized access, data loss, system availability, and inaccurate customer information.
Principle 8: Assess fraud risk
Fraud should be considered as part of the organization’s risk assessment rather than treated as a separate concern.
Example: A company evaluates whether employees could manipulate procurement records and identifies opportunities for segregation of duties and approval controls.
Principle 9: Identify and analyze significant change
The organization should consider changes that could significantly affect its internal control system.
Example: Moving a major business process to a cloud service changes the organization’s technology environment and may require new access, vendor, and monitoring controls.
Quick link: Risk intelligence: A complete guide
3. Control activities
Control activities are the actions used to address risks and support the achievement of objectives. They can be preventive or detective and can operate at different levels of the organization.
This component contains three principles.
Principle 10: Select and develop control activities
The organization should select controls that address identified risks and consider how different controls work together.
Example: To reduce the risk of unauthorized payments, a company uses approval thresholds, segregation of duties, and payment reconciliations.
Principle 11: Select and develop general controls over technology
Technology-related controls should address risks associated with the systems that support business processes.
Example: An organization uses role-based access, change management, backup controls, and system monitoring to protect a financial application.
COSO specifically recognizes the importance of IT controls within the 2013 framework.
Principle 12: Deploy through policies and procedures
Control activities should be implemented through policies and procedures that communicate what needs to happen and how to perform it.
Example: An organization establishes a documented access review procedure that specifies who performs the review, what to check, how to handle exceptions, and how to retain evidence.
4. Information and communication
Internal control depends on relevant information reaching the people who need it. Communication must also work across the organization and with appropriate external parties.
This component contains three principles.
Principle 13: Use relevant, quality information
Management should obtain and use information that is accurate, timely, complete, and relevant to internal control responsibilities.
Example: A control owner receives current access data from the identity management system rather than relying on an outdated spreadsheet when performing an access review.
Principle 14: Communicate internally
Important information about objectives, responsibilities, risks, and controls should move through the organization.
Example: When a new security policy changes employee responsibilities, management communicates the changes to affected teams and provides guidance on the required controls.
Principle 15: Communicate externally
The organization should communicate relevant information with external parties when necessary to support internal control.
Example: A company communicates control requirements to a third-party service provider and establishes a process for reporting security incidents or control issues.
5. Monitoring activities
Monitoring determines whether the components of internal control, including controls related to the principles, are present and functioning. COSO recognizes both ongoing evaluations and separate evaluations as part of internal control monitoring.
This component contains two principles.
Principle 16: Conduct ongoing and/or separate evaluations
The organization should regularly evaluate whether its internal controls continue to operate effectively.
Example: Management continuously monitors control KPIs while internal audit performs periodic independent reviews of selected controls.
Principle 17: Evaluate and communicate deficiencies
When the organization identifies control deficiencies, it should evaluate and communicate them to those responsible for corrective action.
Example: An internal audit identifies repeated failures in quarterly access reviews, reports the deficiency to management, assigns an owner, and tracks remediation to completion.
How to apply the 17 COSO principles in practice
The principles can provide a useful structure for assessing an existing internal control system. A practical approach is to:
- Define your objectives: Establish the operations, reporting, and compliance objectives the controls need to support.
- Map existing controls: Connect current controls to the relevant COSO components and principles.
- Assess gaps: Identify missing, weak, or misoperating principles or control areas.
- Assign ownership: Assign a clear owner to each control and remediation action.
- Collect evidence: Maintain evidence showing that controls were performed and reviewed.
- Monitor and remediate: Track control performance, identify deficiencies, and follow corrective actions.
COSO’s 2013 framework provides criteria for evaluating whether the five components and relevant principles are present and functioning. The internal control assessment ultimately requires management judgment based on the organization’s circumstances.
How CyberArrow can support COSO internal controls
Managing COSO controls across spreadsheets and separate systems can make it harder to track ownership, evidence, control performance, and deficiencies.
CyberArrow supports internal control monitoring by integrating with organizational technologies and processes. It can automate KPI assessments, reporting, evidence collection, and alerts when controls fall below defined thresholds. It also supports automated risk assessments and comes with pre-mapped risks and mitigations across multiple GRC frameworks and standards.
With CyberArrow, organizations can:
- Map and manage controls across their GRC program.
- Monitor control performance and thresholds.
- Collect evidence from connected systems.
- Track risks, deficiencies, and remediation.
- Use dashboards and reports to give management visibility into control performance.
FAQs
What are the five components of the COSO internal control framework?
The five components are control environment, risk assessment, control activities, information and communication, and monitoring activities.
Why does COSO have five components and 17 principles?
The five components organize internal control into broad areas, while the 17 principles provide more specific criteria for evaluating whether those components are present and functioning effectively.
How do the COSO components work together?
The components are interrelated. Risk assessment identifies risks, control activities address those risks, information and communication support the controls, monitoring evaluates their effectiveness, and the control environment establishes the conditions in which the system operates.
Is COSO a compliance framework?
COSO is primarily an internal control framework, not a compliance framework. It can help organizations address compliance objectives by providing a structure to design and evaluate controls.
How can organizations assess COSO internal controls?
Organizations can map existing controls to the five components and 17 principles, assess whether the relevant principles are present and functioning, identify deficiencies, assign remediation owners, and monitor progress.