Global (COSO; used for SOX 404 ICFR assessments in the United States and for internal control generally)

COSO Internal Control

72 controls. 225 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

72 controls 225 frameworks share controls with it Global (COSO; used for SOX 404 ICFR assessments in the United States and for internal control generally) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

COSO 2013 Internal Control Integrated Framework Evidence & Implementation Kit

72 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CA-10Selects and Develops Control Activities121
CA-11Selects and Develops General Controls over Technology0
CA-12Deploys Through Policies and Procedures150
CE-1Demonstrates Commitment to Integrity and Ethical Values5
CE-2Exercises Oversight Responsibility0
CE-3Establishes Structure, Authority, and Responsibility0
CE-4Demonstrates Commitment to Competence5
CE-5Enforces Accountability0
COSO-IC-CA-10The organization selects and develops control activities for asset safeguarding and mitigating risks to the achievement of objectives0
COSO-IC-CA-11The organization selects and develops general controls over technology0
COSO-IC-CA-12The organization deploys control activities through policies and procedures0
COSO-IC-CE-01The organization demonstrates commitment to integrity and ethical values9
COSO-IC-CE-02The board demonstrates independence from management and exercises oversight of internal control16
COSO-IC-CE-03Management establishes structures, reporting lines, authorities, and responsibilities0
COSO-IC-CE-04The organization demonstrates commitment to attract, develop, and retain competent individuals0
COSO-IC-CE-05The organization holds individuals accountable for their internal control responsibilities0
COSO-IC-IC-13The organization obtains or generates and uses relevant quality information0
COSO-IC-IC-14The organization internally communicates information including internal control objectives10
COSO-IC-IC-15The organization communicates with external parties regarding internal control matters0
COSO-IC-MA-16The organization selects and performs ongoing and/or separate evaluations0
COSO-IC-MA-17The organization evaluates and communicates internal control deficiencies in a timely manner0
COSO-IC-OV-01COSO Internal Control Framework - integrated operation of all five components (Control Environment, Risk Assessment, Control Activities, Information & Communication, Monitoring Act0
IC-13Uses Relevant Information0
IC-14Communicates Internally0
IC-15Communicates Externally0
MON-16Conducts Ongoing and/or Separate Evaluations0
MON-17Evaluates and Communicates Deficiencies0
P1Demonstrates Commitment to Integrity and Ethical Values32
P10Selects and Develops Control Activities0
P11Selects and Develops General Controls over Technology0
P12Deploys through Policies and Procedures0
P13Uses Relevant Information0
P14Communicates Internally0
P15Communicates Externally0
P16Conducts Ongoing and/or Separate Evaluations0
P17Evaluates and Communicates Deficiencies0
P2Exercises Oversight Responsibility0
P3Establishes Structure, Authority, and Responsibility0
P4Demonstrates Commitment to Competence0
P5Enforces Accountability0
P6Specifies Suitable Objectives0
P7Identifies and Analyzes Risk32
P8Assesses Fraud Risk0
P9Identifies and Analyzes Significant Change0
RA-6Specifies Suitable Objectives0
RA-7Risk Response11
RA-8Assesses Fraud Risk0
COMP-CAControl Activities (Principles 10 to 12)0
COMP-CEControl Environment (Principles 1 to 5)0
COMP-ICInformation and Communication (Principles 13 to 15)0
COMP-MAMonitoring Activities (Principles 16 to 17)0
COMP-RARisk Assessment (Principles 6 to 9)0
EFFECTIVENESSObjectives, components, the requirements for effective internal control, and limitations0
FRAMEWORKCOSO Internal Control, Integrated Framework (2013): what it is and what is held0
ICFR-SOXThe framework's use for internal control over financial reporting, and COSO's later guidance0
P1Principle 1: Demonstrates commitment to integrity and ethical values0
P10Principle 10: Selects and develops control activities1
P11Principle 11: Selects and develops general controls over technology1
P12Principle 12: Deploys through policies and procedures1
P13Principle 13: Uses relevant information0
P14Principle 14: Communicates internally1
P15Principle 15: Communicates externally1
P16Principle 16: Conducts ongoing and/or separate evaluations1
P17Principle 17: Evaluates and communicates deficiencies1
P2Principle 2: Exercises oversight responsibility1
P3Principle 3: Establishes structure, authority and responsibility1
P4Principle 4: Demonstrates commitment to competence1
P5Principle 5: Enforces accountability1
P6Principle 6: Specifies suitable objectives1
P7Principle 7: Identifies and analyzes risk1
P8Principle 8: Assesses fraud risk0
P9Principle 9: Identifies and analyzes significant change0

Tell me when COSO Internal Control files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Risk register with likelihood, impact, and treatment owners
  • Control implementation statement for RA-7 citing the system mission and inheritance from common controls
  • Risk assessment methodology approved by leadership

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for COSO Internal Control, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition