COSO Internal Control Framework
The internal control framework used by the overwhelming majority of SOX programmes, structured as five components and seventeen principles.
Published in 1992 and substantially revised in 2013, COSO’s Internal Control — Integrated Framework defines internal control across five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. The 2013 revision made explicit the seventeen principles underlying those components, and required that all seventeen be present and functioning for a system of internal control to be considered effective.
That last requirement is stronger than most programmes treat it. It means an entity cannot conclude ICFR is effective while a principle — say, the one on competence, or on assessing fraud risk — is not functioning, no matter how well the transactional controls test. In practice entity-level principles receive far less testing rigour than control activities, largely because they are harder to evidence.
COSO also publishes an ERM framework (2017), which is a different document addressing enterprise risk management and integration with strategy. Conflating the two is a common source of confusion in scoping conversations; the map at controlsmap.com carries both separately, with 17 and 20 controls respectively.
Related