COSO Integrated Framework
Definition
A framework for internal control published by the Committee of Sponsoring Organizations of the Treadway Commission, defining five interrelated components: control environment, risk assessment, control activities, information and communication, and monitoring activities. The 2013 update formalised 17 principles within the five components and is the version currently in use.
- Publisher
- Committee of Sponsoring Organizations (COSO)
- Components
- Control environment, risk assessment, control activities, information and communication, monitoring
- Principles
- 17 principles across the five components
- Current version
- 2013 update
Common questions
What did the 2013 update change compared to the original 1992 framework?+
The 2013 update formalised the 17 explicit principles underlying the five components, giving organisations and auditors concrete, testable criteria for evaluating internal control effectiveness rather than relying on the broader original component descriptions alone.
Why does a forensic accountant care about the COSO framework's components in a fraud investigation?+
Weaknesses mapped to specific components, such as a poor control environment or absent monitoring activities, often explain how a fraud went undetected, so the framework gives investigators a structured way to document control failures alongside the financial findings.
Related terms
- COBIT
- Control Objectives for Information and Related Technologies, published by ISACA. A governance and management framework for enterprise IT that defines IT-specific control...
- Control Environment
- The first and foundational component of the COSO framework. It encompasses the board's oversight, management's philosophy and operating style, organisational structure, commitment...
- Detective Control
- A control designed to identify an error or irregularity after it has occurred. Examples include bank reconciliations, exception reports, variance analysis, and...
- IT General Controls (ITGCs)
- Controls over the IT environment that support the reliable operation of application controls. Key categories include access management, change management, computer operations,...
- Preventive Control
- A control designed to stop an error or fraudulent act before it occurs. Examples include segregation of duties, mandatory authorisation limits, access...