COSO Framework

The COSO cube explained: objectives, components, and organizational structure

An internal control system does not operate in one department or support only one type of objective. Controls can apply to financial reporting, operations, and compliance across different levels of an organization.

 

The COSO cube illustrates this relationship. It brings together three dimensions of internal controls: objectives, components, and organizational structure. The model shows how the five components of internal control apply across different objectives and organizational levels.

 

 

What is the COSO cube?

 

The COSO cube is a visual representation of the COSO internal control framework. It shows how three dimensions of internal control intersect:

 

Dimension  What it represents
Objectives  What the organization wants its internal control system to help achieve.
Components  The five elements that make up an effective internal control system.
Organizational structure The different levels across which internal control operates.

 

The three dimensions are connected. An organization can apply the same internal control principles to different objectives and at different organizational levels.

 

For example, a control over financial reporting may operate within the finance function, while a separate control supports an operational objective within a business unit. You can evaluate both using the same COSO components.

 

The three dimensions of the COSO cube:

 

The COSO cube

 

1. Objectives

 

The top of the COSO cube represents three categories of objectives:

 

  • Operations.
  • Reporting.
  • Compliance.

 

These categories describe what an organization is trying to achieve through its activities and internal control system. The 2013 COSO framework also broadened the reporting category to include internal and external financial and nonfinancial reporting.

 

Operations objectives

 

Operations objectives relate to the effectiveness and efficiency of the organization’s activities.

 

Example: A company wants its order fulfillment process to meet delivery targets while minimizing errors and unnecessary costs.

 

Internal controls might include approval procedures, inventory checks, exception reporting, and performance monitoring.

 

Reporting objectives

 

Reporting objectives relate to the reliability, timeliness, and transparency of information used internally or communicated externally.

 

Example: A company wants its monthly financial reports to reflect sales and expenses accurately.

 

Controls might include reconciliations, review procedures, data validation, and access restrictions.

 

Compliance objectives

 

Compliance objectives relate to following applicable laws, regulations, and other requirements.

 

Example: A company needs to ensure that employees complete required regulatory training.

 

Controls could include training assignments, completion tracking, exception reports, and management follow-up.

 

The same organization can have all three types of objectives at the same time. The COSO cube helps show that internal control applies across each category rather than being limited to financial reporting.

 

2. Internal control components

 

The second dimension consists of the five components of the COSO internal control framework:

 

  1. Control environment.
  2. Risk assessment.
  3. Control activities.
  4. Information and communication.
  5. Monitoring activities.

 

Rather than looking at each component on its own, the cube shows that the components apply across the organization’s objectives and organizational levels.

 

For example, monitoring activities can evaluate controls supporting an operations objective in one business unit and controls supporting a reporting objective in another.

 

The five components are therefore a vertical dimension of the model, cutting across the organization’s objectives and structure.

 


 

3. Organizational structure

 

The third dimension shows where internal control operates within the organization. The COSO cube illustrates four levels:

 

  • Entity.
  • Division.
  • Business unit.
  • Function.

 

These levels show that internal control responsibilities do not sit only at the top of the organization. Controls can operate across different parts of the organization and at different levels.

 

For example, an organization may have an entity-wide access management policy. A business unit may apply additional access procedures based on its systems, while the IT function performs specific access reviews.

 

The COSO cube does not require every organization to have these exact organizational layers. Instead, this dimension illustrates the pervasive nature of internal control across an entity’s structure.

 

How the three dimensions work together

 

The value of the COSO cube comes from the intersections between its three dimensions.

 

Consider a company that wants to improve the accuracy of its financial reporting.

 

Objective: Reporting

 

Organizational level: Finance function

 

Risk: Financial information may contain errors before reports are issued.

 

The organization could then apply the five components to this situation:

 

  • Control environment: Assign responsibility for reporting controls and establish expectations for accurate reporting.

 

  • Risk assessment: Identify risks that could result in inaccurate financial information.

 

  • Control activities: Use reconciliations, reviews, and approval procedures to address those risks.

 

  • Information and communication: Provide finance staff with accurate and timely information needed to perform their responsibilities.

 

  • Monitoring activities: Review whether the reporting controls continue to operate effectively.

 

Now consider a different objective, such as improving order-fulfillment efficiency. The same five components apply, but the risks, controls, information, and responsible teams will differ. This is what the cube helps demonstrate: internal control is not a single set of controls. It is a system that operates across objectives and organizational levels.

 

How the COSO cube relates to the 17 principles

 

The COSO cube and the 17 principles describe different levels of the same framework.

 

The cube provides the overall structure. Its three dimensions show:

 

  • What the organization is trying to achieve.
  • The components needed for effective internal control.
  • Where internal control operates.

 

The 17 principles provide more specific criteria within the five components. For example, the control environment component includes principles covering integrity and ethical values, oversight, organizational structure, competence, and accountability. The principles therefore add detail to one dimension of the cube rather than creating a separate dimension.

 

A simple way to view the relationship is:

 

COSO cube → overall model

 

5 components → elements of an effective internal control system

 

17 principles → specific criteria within those components

 

This distinction is useful when assessing controls. The cube provides the structure for considering where and why controls apply, while the principles provide criteria for evaluating whether the components are present and functioning.

 

How CyberArrow can support COSO internal control management

 

Applying the COSO model across multiple objectives, business units, and functions can create a large amount of control, evidence, and remediation data to manage.

 

CyberArrow can help centralize this information through internal control monitoring, automated KPI assessments, evidence collection, risk management, and reporting. It also supports integrations with organizational systems and provides dashboards for monitoring control and compliance activities.

 

With CyberArrow, organizations can:

 

  • Map and manage controls across their GRC program.
  • Assign ownership and track control activities.
  • Collect evidence from connected systems.
  • Monitor control performance and thresholds.
  • Track deficiencies and remediation.
  • Use dashboards and reports to give management visibility into control activities.

 

To learn more about CyberArrow and its features, schedule a CyberArrow GRC demo.

 


 

FAQs

 

What are the three dimensions of the COSO cube?

The three dimensions are objectives, internal control components, and organizational structure.

 

What are the three COSO objective categories?

The three objective categories are operations, reporting, and compliance.

 

How do the five COSO components fit into the cube?

The five components form one dimension of the cube and apply across the organization’s objectives and organizational levels.

 

What organizational levels are shown in the COSO cube?

The cube illustrates entity, division, business unit, and function levels. These represent how internal control can operate throughout an organization.

 

How are the COSO cube and 17 principles related?

The cube provides the overall structure of the framework. The 17 principles provide specific criteria within its five internal control components.

 

How can the COSO cube be used for internal control assessment?

Organizations can use the cube to consider which objectives a control supports, where it operates, which components apply, and whether the relevant principles are present and functioning.

Avatar photo
CyberArrow team