Internal and Forensic Audit · Internal Controls
COSO Internal Control Framework: Components and Principles
Updated 11 October 2026 · Fact-checked
The COSO Internal Control Integrated Framework defines internal control through five components: control environment, risk assessment, control activities, information and communication, and monitoring. These are supported by 17 principles. To answer an exam question, name the component, state the relevant principle, then link it to the facts given.
Understand COSO Internal Control Framework
Internal control is a process run by the board, management and other staff. It gives reasonable assurance that the entity will meet its objectives. COSO groups these objectives into three: operations, reporting and compliance.
The framework is usually drawn as a cube. One face shows the three objectives. One shows the entity levels: the whole entity, a division, a unit or a function. The third face shows the five components. The idea is that every component must work at every level for every objective.
The five components are: control environment (the tone and culture of the entity), risk assessment (identifying and analysing risks to objectives), control activities (policies and procedures that carry out management's directions), information and communication (getting the right information to the right people) and monitoring activities (checking that controls keep working over time).
The 17 principles sit under the components. Control environment has 5, risk assessment has 4, control activities has 3, information and communication has 3, and monitoring has 2. Together that is 17. A component is effective only when its principles are present and functioning, and all five components work together.
The auditing standard SA 315 uses a similar five-part split: control environment, the entity's risk assessment process, the information system and communication, control activities, and monitoring of controls. It notes that auditors may use different terminology or frameworks, provided all the components are addressed. So COSO and SA 315 map closely, but the wording differs.
Key rules to remember
- Five components of COSO
- Control environment + Risk assessment + Control activities + Information and communication + Monitoring activities
- Learn them in this order. Control environment is the foundation; monitoring closes the loop.
- Count of principles
- 5 + 4 + 3 + 3 + 2 = 17
- Control environment 5, risk assessment 4, control activities 3, information and communication 3, monitoring 2.
- Three COSO objectives
- Operations, Reporting, Compliance
- The cube links each objective to all five components.
- Principles: control environment (5)
- Integrity and ethics; board independence and oversight; structure, authority and responsibility; commitment to competence; accountability
- Compare with SA 315 para A76 elements such as integrity, competence, governance participation and HR policies.
- Principles: risk assessment (4)
- Clear objectives; identify and analyse risks; assess fraud risk; identify and assess significant change
- Fraud risk is a named principle. Do not leave it out.
- Principles: control activities (3)
- Select and develop controls; general controls over technology; deploy through policies and procedures
- SA 315 para A95 lists authorisation, performance reviews, information processing, physical controls and segregation of duties.
- Principles: information and communication (3)
- Use relevant quality information; communicate internally; communicate externally
- External communication includes customers, regulators and shareholders.
- Principles: monitoring (2)
- Conduct ongoing and/or separate evaluations; evaluate and communicate deficiencies
- SA 315 para A105 describes monitoring as ongoing activities, separate evaluations, or a combination.
How to solve COSO Internal Control Framework questions
Use this method for any question that gives a scenario and asks you to identify, evaluate or explain COSO components.
- 1Read the facts and underline each control-related event, such as a policy, a failure, a report or a review.
- 2Match each event to one of the five components. Ask whether it is about culture, risk, procedures, information flow or checking.
- 3Name the relevant principle under that component. Use the principle name, not only the component name.
- 4Say whether the principle is present and functioning, or deficient. Give the fact that shows it.
- 5State the effect on the objective affected: operations, reporting or compliance.
- 6Recommend a fix tied to the same component, such as a code of conduct, a risk register, a reconciliation or an audit committee review.
- 7Conclude on whether the component is effective and how that affects the overall system of internal control.
Quickest way: Component-Principle-Fact
When to use it: Use when you have little time and the question asks you to list or explain the framework with examples.
- Write the five components as a list in order.
- Add the principle count beside each: 5, 4, 3, 3, 2.
- Under each, write one line of meaning and one practical example.
- Add a closing line that all components must work together across the three objectives and all entity levels.
Common mistakes in COSO Internal Control Framework
Listing the components in a random order or missing one, usually monitoring.
Students memorise the names but not the logic of the sequence.
Fix: Learn the sequence as foundation, risk, action, information flow, review. Check that you have five.
Stating the wrong number of principles under a component, or the wrong total.
The split 5-4-3-3-2 is easy to mix up.
Fix: Memorise 5-4-3-3-2 and check that it adds to 17.
Confusing control activities with the whole of internal control.
Everyday usage treats a control as an approval or reconciliation only.
Fix: Treat control activities as one component. Control environment, risk assessment, information and monitoring are separate components.
Putting the tone at the top under control activities.
Students see ethics policies as procedures.
Fix: Integrity, ethics, board oversight and competence belong to the control environment.
Treating COSO and SA 315 as identical.
Both have five parts, so the wording is assumed to be the same.
Fix: Say they are similar. SA 315 refers to the entity's risk assessment process and the information system relevant to financial reporting. COSO speaks of principles and wider objectives.
Naming components without applying them to the facts.
Students recall theory but skip the analysis step the paper expects.
Fix: Always follow the pattern: component, principle, fact, effect, recommendation.
Worked examples
Example 1
Sundaram Textiles Ltd has a written code of conduct, but the managing director often overrides approval limits for purchases. The finance team prepares monthly variance reports, but nobody reviews them. Identify the COSO components affected and recommend action.
Show the solution
- The managing director overriding limits is a weakness in the control environment. The principles of integrity and ethical values, and accountability, are not working.
- Approval limits are control activities. The override defeats the principle of deploying controls through policies and procedures.
- Variance reports that nobody reviews are a failure of monitoring activities. The reports are produced, but deficiencies are not evaluated or communicated.
- The effect falls on operations and reporting. Unauthorised purchases may be made, and costs may be misstated or not controlled.
- Recommend that the board or audit committee enforce approval limits with no exceptions, and that a named senior officer review the variance reports and report deviations to the audit committee.
- Conclusion: the control environment, control activities and monitoring components are ineffective, so the internal control system cannot be called effective.
Answer: Control environment (tone and accountability), control activities (override of approval limits) and monitoring (unreviewed variance reports) are deficient. Enforce limits and assign review of the reports to a named officer who reports to the audit committee.
Example 2
Explain the five components and 17 principles of the COSO framework in brief, and state how the number of principles is split.
Show the solution
- Define internal control as a process giving reasonable assurance on operations, reporting and compliance objectives.
- Control environment (5 principles): integrity and ethics, board oversight, structure and authority, commitment to competence, accountability.
- Risk assessment (4 principles): suitable objectives, identifying and analysing risk, assessing fraud risk, assessing significant change.
- Control activities (3 principles): selecting and developing controls, general controls over technology, deployment through policies and procedures.
- Information and communication (3 principles): use of quality information, internal communication, external communication.
- Monitoring activities (2 principles): ongoing or separate evaluations, and evaluating and communicating deficiencies.
- Add the split: 5 + 4 + 3 + 3 + 2 = 17. Conclude that all components must be present and work together at every level.
Answer: There are five components with 17 principles, split 5, 4, 3, 3 and 2 across control environment, risk assessment, control activities, information and communication, and monitoring.
Exam tips
- Write the component name and the principle name for each point. Examiners reward the link between the two.
- In case questions, tag each fact to a component before writing. This keeps the answer structured.
- Mention the SA 315 parallel, with para A57 for the five-component split, when the question refers to audit or the statutory auditor.
- Link governance points to the audit committee under section 177 of the Companies Act, 2013, which includes evaluation of internal financial controls and risk management systems.
- Keep the principle count handy. A correct total and split shows command of the framework.
Practice questions from Internal Controls
- At Narmada Foods Ltd., the auditor identifies a control deficiency in the month-end reconciliation of receivables. Management has a compensa…
- Under COSO, which activity is an example of ongoing monitoring rather than a separate evaluation?
- In Ganga Foods Ltd, a whistle-blower employee believes the head of finance is overriding internal controls to conceal payments. Which featur…
- While evaluating the internal financial controls of Kaveri Pharma Ltd, its Audit Committee needs an independent technical opinion on control…
- An internal auditor of Narmada Steels Ltd documents a payroll control with several individually minor weaknesses: no review of the master fi…
COSO Internal Control Framework in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
COSO Internal Control Framework: frequently asked questions
What are the five components of the COSO framework?
They are control environment, risk assessment, control activities, information and communication, and monitoring activities. All five must be present and work together for internal control to be effective.
How many principles does COSO have and how are they split?
There are 17 principles. Control environment has 5, risk assessment 4, control activities 3, information and communication 3 and monitoring 2.
How is the COSO cube explained?
The cube has three faces. One shows the three objectives of operations, reporting and compliance. One shows entity levels. One shows the five components. It means every component applies to every objective at every level.
Is COSO the same as SA 315?
No, but they are close. SA 315 divides internal control into five components, as set out in para A57, and says auditors may use different terminology or frameworks if all components are addressed. COSO adds principles and covers wider objectives.