Control Environment
Definition
The first and foundational component of the COSO framework. It encompasses the board's oversight, management's philosophy and operating style, organisational structure, commitment to competence, and human resource policies. It sets the tone that shapes every other component.
Related terms
- COBIT
- Control Objectives for Information and Related Technologies, published by ISACA. A governance and management framework for enterprise IT that defines IT-specific control...
- COSO Integrated Framework
- A framework for internal control published by the Committee of Sponsoring Organizations of the Treadway Commission, defining five interrelated components: control environment,...
- Detective Control
- A control designed to identify an error or irregularity after it has occurred. Examples include bank reconciliations, exception reports, variance analysis, and...
- Fraud Diamond
- Wolfe and Hermanson's 2004 extension of the fraud triangle that adds capability as a fourth condition. The model holds that pressure, opportunity,...
- IT General Controls (ITGCs)
- Controls over the IT environment that support the reliable operation of application controls. Key categories include access management, change management, computer operations,...
- Management Override
- The circumvention of established internal controls by members of senior management. A key fraud risk in any organisation because those who set...
- Non-Shareable Financial Problem
- Cressey's original term for the pressure element. The problem need not be objectively severe; what matters is that the perpetrator perceives it...
- Occupational Fraud
- The ACFE defines occupational fraud as the use of one's occupation for personal enrichment through the deliberate misuse or misapplication of the...
- Preventive Control
- A control designed to stop an error or fraudulent act before it occurs. Examples include segregation of duties, mandatory authorisation limits, access...
- Rationalization
- The internal justification that allows a person to commit fraud while maintaining a self-image as an honest individual. Common forms include 'I...
Explained in these topics
- Internal Control Frameworks and Control DesignThe first and foundational component of the COSO framework. It encompasses the board's oversight, management's philosophy and operating style, organisational s...
- The Fraud Triangle and Cressey's ModelThe set of organisational policies, procedures, and cultural attitudes that collectively determine how much opportunity a fraudster has. Weak controls, missing...