What is the COSO framework? A guide to internal control and enterprise risk management
Organizations need effective controls to support their objectives and a structured way to manage the risks that could prevent them from achieving those objectives. The COSO framework helps organizations address both areas.
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) developed its internal control framework to help organizations improve confidence in their information and strengthen internal controls. It later developed the enterprise risk management (ERM) framework to help organizations connect risk management with strategy and performance.
These frameworks are related, but they are not the same. The internal control framework focuses on building and evaluating effective internal controls, while the ERM framework takes a broader view of how risk relates to strategy and performance.
COSO at a glance
| COSO internal control | COSO ERM | |
| Focus | Internal control effectiveness | Enterprise risk management |
| Main purpose | Provide reasonable assurance that objectives can be achieved | Help manage risk in relation to strategy and performance |
| Structure | Five components and 17 principles | Five components and 20 principles |
| Key areas | Operations, reporting, and compliance | Strategy, objectives, risk, performance, and value |
| Usage | Designing, implementing, and evaluating internal controls | Integrating risk management into strategy and decision-making |
What is the COSO framework?
COSO is a joint initiative of five major professional organizations that develops guidance on internal control, enterprise risk management, fraud deterrence, and related governance topics.
COSO’s frameworks are principles-based rather than prescriptive checklists. They provide a structure that organizations can use to design, implement, and evaluate their own systems of internal control and risk management.
The two COSO frameworks
COSO’s internal control and ERM frameworks address related but different needs.
COSO internal control integrated framework
COSO first issued its internal control framework in 1992 and refreshed it in 2013. The framework provides five integrated components and 17 principles for evaluating whether a system of internal control is effective.
Internal control is designed to provide reasonable assurance that an organization can achieve its objectives. The framework covers objectives related to operations, reporting, and compliance rather than limiting internal control to financial reporting.
For example, an organization might use the framework to evaluate whether access controls, approval processes, segregation of duties, or monitoring activities are designed and operating effectively.
COSO enterprise risk management framework
COSO published its original ERM framework in 2004 and updated it in 2017 as enterprise risk management (integrating with strategy and performance). The updated framework places greater emphasis on considering risk during strategy-setting and linking risk management to organizational performance.
The ERM framework consists of five interrelated components and 20 principles. It defines ERM around the culture, capabilities, and practices an organization integrates with strategy-setting and performance to manage risk while creating, preserving, and realizing value.
For example, a company considering expansion into a new market could use COSO ERM to consider the risks associated with that strategy, determine its risk responses, and monitor how those risks affect performance.
How organizations use the COSO framework in practice
Organizations can use the COSO framework in several ways depending on their objectives.
For example, a company preparing for a regulatory assessment may use the internal control framework to evaluate whether key controls are properly designed, assigned to owners, supported by evidence, and monitored over time.
A company entering a new market may use the ERM framework to identify strategy-related risks, assess their potential impact, determine risk responses, and monitor changes in its risk profile.
An organization can also use both. Its ERM process can identify and prioritize risks, while its internal control system can provide the controls used to address specific risks.
This connection is important because risk management and internal control do not need to operate as separate programs. Controls can support risk responses, while control monitoring can provide information about whether those responses are working.
How to implement the COSO framework
COSO provides principles and components, not a single implementation process every organization must follow. A practical implementation can start with the organization’s objectives and existing risk and control processes.
- Define objectives and scope: Determine what you want the COSO framework to address. This could include enterprise risk management, internal controls, a specific business process, regulatory requirements, or a combination of these areas.
- Assess the current state: Review existing policies, controls, risk assessments, responsibilities, reporting processes, and monitoring activities. Identify where practices already align with the relevant COSO principles and where gaps exist.
- Identify risks and control needs: Connect organizational objectives with the risks that could prevent them from being achieved. Determine which controls or risk responses are needed to address those risks.
- Assign ownership: Clearly assign ownership for risks, controls, evidence, testing, and remediation. This makes it easier to track whether controls are operating as intended.
- Monitor and improve: Use control assessments, risk reviews, audits, performance information, and other monitoring activities to identify deficiencies. Track remediation and update the risk and control environment as business conditions change.
The goal is not to create a separate layer of documentation around COSO. The framework should help organize the processes, controls, risks, and information the organization already needs to manage.
COSO and other frameworks
COSO does not need to operate in isolation. Organizations often use multiple frameworks and standards to address different requirements.
For example, COSO can provide a broader structure for internal control and enterprise risk management, while ISO 27001 can provide requirements for an information security management system. COBIT can support governance and management of enterprise information and technology.
The practical challenge is connecting these requirements without creating duplicate processes. A single control may support requirements from several frameworks, and the same evidence may be useful for multiple assessments.
This is why control mapping and centralized evidence management become important when organizations manage several frameworks at the same time.
Manage COSO controls and risks with CyberArrow
Managing internal controls, risk assessments, evidence, and remediation across multiple frameworks can become difficult when teams rely on spreadsheets and separate systems.
CyberArrow helps centralize these activities within its GRC platform. It supports automated risk assessments, internal control monitoring, evidence collection, and reporting. The platform also supports 80+ integrations and can map requirements across multiple frameworks and standards.
With CyberArrow, teams can:
- Manage risks centrally: Track risk assessments, risk levels, treatment, and mitigation activities.
- Monitor controls: Track control performance and receive alerts when controls fall below defined thresholds.
- Collect evidence: Gather evidence from connected systems instead of relying entirely on manual requests.
- Connect frameworks: Map controls and requirements across multiple standards and frameworks.
- Track remediation: Assign owners and monitor actions needed to address identified gaps.
- Report to stakeholders: Use dashboards and reports to provide visibility into risk and control performance.
Schedule a free demo to see how CyberArrow GRC can simplify risk and control management.
FAQs
What are the two main COSO frameworks?
The two main frameworks are the COSO internal control integrated framework, refreshed in 2013, and enterprise risk management (integrating with strategy and performance), published in 2017.
What are the five components of the COSO internal control framework?
They are control environment, risk assessment, control activities, information and communication, and monitoring activities.
What are the five components of COSO ERM?
They are governance and culture, strategy and objective-setting, performance, review and revision, and information, communication, and reporting.
How are COSO and ISO 27001 different?
COSO provides frameworks for internal control and enterprise risk management, while ISO 27001 specifies requirements for an information security management system (ISMS). Organizations can use them together when broader risk and control requirements overlap with information security.
Can the COSO framework and COBIT be used together?
Yes. COSO can support enterprise risk management and internal control, while COBIT focuses on the governance and management of enterprise information and technology. Organizations can map relevant controls and processes across the two where their requirements overlap.