The 17 COSO principles are the specific requirements that sit under the five components of the COSO Internal Control—Integrated Framework, and every one of them must be present and functioning for an organization’s internal control system to be considered effective.1COSO. Internal Control Miss one principle, and the framework treats the whole system as having a gap. The principles are grouped five, four, three, three, and two across Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.
The Standard Each Principle Has to Meet
Two words carry most of the weight: present and functioning. A principle is present when it exists in the design and implementation of the control system. It is functioning when it keeps operating as intended over time.1COSO. Internal Control A well-drafted vendor approval workflow that nobody actually reviews each month is present but not functioning. Both halves have to hold.
To help judge whether a principle clears that bar, the framework provides “points of focus” tied to each principle. They are example characteristics, not a checklist. An organization does not need to satisfy every point of focus, but it does need to show the principle itself is met. If management concludes a relevant principle is not present and functioning, the framework treats that as a major deficiency.
This matters outside the framework’s own pages. The SEC has identified COSO as a suitable control framework for meeting the Sarbanes-Oxley requirement that management assess internal control over financial reporting, and it remains the dominant choice among U.S. public companies.2U.S. Securities and Exchange Commission. Commission Guidance Regarding Management’s Report on Internal Control Over Financial Reporting3GovInfo. Sarbanes-Oxley Act of 2002
Control Environment: Principles 1 Through 5
The Control Environment sets the tone. It shapes how seriously the organization treats controls from the boardroom down, and every other component rests on it.
Principle 1: Commitment to Integrity and Ethical Values
The organization demonstrates a commitment to integrity and ethical values.1COSO. Internal Control This goes past a code of conduct on the wall. The board and senior leadership set clear behavioral expectations, evaluate whether people meet them, and address violations promptly. When an executive’s ethical breach is quietly ignored while a junior employee is disciplined for the same conduct, the operative message is the one the workforce actually sees.
Principle 2: Board Independence and Oversight
The board of directors demonstrates independence from management and exercises oversight of the control system’s development and performance. Directors who are financially entangled with or personally beholden to the CEO are not positioned to challenge management’s assumptions about risk. The audit committee should meet regularly in executive session, without management present, to hold candid conversations about weaknesses and ethical concerns. Under the Sarbanes-Oxley Act, audit committees of listed companies must also establish procedures for confidential, anonymous employee complaints about accounting or auditing matters.3GovInfo. Sarbanes-Oxley Act of 2002
Principle 3: Structure, Authority, and Responsibility
Management establishes the organizational structure, reporting lines, and appropriate authorities and responsibilities needed to pursue objectives. Vague reporting lines create control gaps. If two people each assume the other is reviewing journal entries, nobody is reviewing journal entries. Clear role definition also supports segregation of duties, so the person who authorizes a payment is not the same person who records it or reconciles the bank account.
Principle 4: Commitment to Competence
The organization attracts, develops, and retains people competent enough to carry out their control responsibilities. A well-designed control fails if the person executing it does not know what to look for. This principle shows up in hiring, training budgets, and whether the organization keeps its people current on regulatory changes and technical skills. It is one of the easier principles to shortchange when budgets tighten, and one of the first to produce problems when it is.
Principle 5: Enforces Accountability
Individuals are held accountable for their internal control responsibilities. Accountability ties the rest of the control environment together. Ethical expectations, organizational structure, and competence only work if people know their performance will be measured against those expectations. That means performance evaluations, incentive structures, and disciplinary action that connect individual behavior to control outcomes.
Risk Assessment: Principles 6 Through 9
Risk Assessment is how the organization identifies what could go wrong and decides how to prioritize its response. Controls exist to address risks, so without a clear-eyed assessment, control activities are either misallocated or missing.
Principle 6: Specifies Suitable Objectives
The organization specifies objectives with enough clarity to identify and assess risks related to them. You cannot assess what might go wrong if you have not defined what right looks like. “Produce accurate reports” is too vague to point at specific risks. “Close the books within five business days with all intercompany transactions reconciled” surfaces identifiable risks like delayed subsidiary data or unreconciled accounts.
Principle 7: Identifies and Analyzes Risk
The organization identifies risks across the entity and analyzes them to decide how each should be managed. Analysis involves estimating significance, likelihood, and the appropriate response. It happens at multiple levels, from broad strategic risks to process-level risks in payroll or revenue recognition, and it runs continuously as the business evolves. Cybersecurity threats are increasingly part of this analysis, and COSO has published supplemental guidance on integrating cyber risk into enterprise risk management.4COSO. Managing Cyber Risk in a Digital Age
Principle 8: Assesses Fraud Risk
The organization specifically considers the potential for fraud when assessing risks. The framework asks management to think about fraudulent financial reporting, misuse of assets, and corruption, and to examine where incentives and opportunities exist. High-pressure sales targets that reward aggressive revenue recognition are one example. A single employee with unchecked access to both the general ledger and the bank account is another. One area deserves particular attention: how management itself could override controls. The people who design the system are often best positioned to circumvent it.
Principle 9: Identifies and Analyzes Significant Change
The organization identifies and assesses changes that could significantly affect its control system. Mergers, leadership turnover, new regulations, or a move to cloud-based systems can make existing controls obsolete quickly. A company migrating financial reporting to a new enterprise system needs to reevaluate access controls, data integrity checks, and change management procedures. Treating last year’s design as automatically adequate for this year’s environment is how gaps form unnoticed.
Control Activities: Principles 10 Through 12
Control Activities are the specific actions that carry out management’s risk mitigation directives: approvals, reconciliations, access restrictions, reviews. They happen at every level and at every stage within business processes.
Principle 10: Selects and Develops Control Activities
The organization selects and develops control activities that reduce risks to acceptable levels. Management picks a mix of preventive controls, such as requiring dual signatures on payments above a threshold, and detective controls, such as monthly bank reconciliations. Each control should tie to a specific risk identified during the risk assessment. A control that does not address a real risk is paperwork for its own sake.
Segregation of duties is one of the most important control activities. No single person should control every step of a financial transaction. The functions to separate are custody of assets, recording of transactions, authorization of transactions, and reconciliation. In payroll, the person who adds employees and changes pay rates should not also generate paychecks or reconcile the payroll bank account. When an organization is too small to fully separate these roles, compensating controls such as manager review of transaction logs become essential.
Principle 11: General Controls Over Technology
The organization selects and develops general controls over technology to support its objectives. These Information Technology General Controls, or ITGCs, are the foundation under every automated control and every piece of system-generated data.5PCAOB. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements If access controls are weak, change management is sloppy, or system operations are unstable, every automated control downstream is unreliable. ITGCs cover access security, change management, system operations, and controls over how new technology is developed and deployed.
Principle 12: Deploys Through Policies and Procedures
Control activities are deployed through policies that state what is expected and procedures that spell out how to do it. A policy might say all vendor invoices over $10,000 require approval from the department head. The corresponding procedure details who receives the invoice, how it is routed for approval, what documentation is required, and what happens when the department head is unavailable. Without written procedures, controls depend on institutional memory, which walks out the door with every departure.
Information and Communication: Principles 13 Through 15
Controls run on information. This component addresses the quality of data moving through the system and whether the right people receive the right information at the right time.
Principle 13: Uses Relevant, Quality Information
The organization obtains or generates relevant, quality information to support internal control. Quality information is accurate, timely, accessible to those who need it, and protected from unauthorized changes. If the data feeding a control activity is stale or riddled with errors, the control itself is worthless. A transaction monitoring report built on yesterday’s data will not catch today’s anomaly. Management has to confirm that the underlying systems and data processes actually meet these quality standards.
Principle 14: Communicates Internally
Internal communication ensures everyone in the organization understands their control responsibilities. Information has to flow in every direction: up to the board, down from leadership, and across departments. Formal channels like compliance training and policy distribution matter, and so do informal ones. Employees need a safe path to report control deficiencies or potential ethical violations. Confidential hotlines are common, and SOX specifically requires audit committees of listed companies to establish anonymous reporting procedures for accounting and auditing concerns.3GovInfo. Sarbanes-Oxley Act of 2002 SOX also protects employees who report suspected fraud from retaliation.6Occupational Safety and Health Administration. Investigator’s Desk Aid to the Sarbanes-Oxley Act Whistleblower Protection Provision
Principle 15: Communicates Externally
The organization communicates with external parties about matters that affect its internal controls. This covers reporting to regulators, disclosing material weaknesses to shareholders, responding to external auditor findings, and managing information exchanges with vendors and customers. What you tell the market about your controls has legal and financial consequences.
Monitoring Activities: Principles 16 and 17
Monitoring is what keeps the control system from going stale. Controls that worked two years ago may have degraded because of staff turnover, system changes, or shifting business processes. These two principles close the feedback loop.
Principle 16: Conducts Ongoing and Separate Evaluations
The organization performs ongoing and separate evaluations to determine whether the components and principles of internal control are present and functioning. Ongoing monitoring is embedded in daily operations, such as a supervisor reviewing exception reports or an automated system flagging transactions above a threshold. Separate evaluations are periodic assessments like internal audits or departmental self-assessments that take a deeper look on a scheduled basis. Ongoing monitoring provides real-time feedback but can become routine; separate evaluations provide rigor but only at intervals. The combination covers both gaps.
Principle 17: Evaluates and Communicates Deficiencies
The organization evaluates internal control deficiencies and communicates them promptly to those responsible for corrective action, including senior management and the board where appropriate. Identifying a weakness means nothing if it sits in a report nobody reads. The severity determines who needs to hear about it: a minor process gap might be resolved by a department manager, while a material weakness in financial reporting controls goes straight to the audit committee.
What Happens When a Principle Is Not Met
Not every failure carries the same weight. The framework, reinforced by PCAOB auditing standards, sorts deficiencies into three tiers:
- Control deficiency. A control is missing or does not work as designed, but the gap is not severe enough to rise to the next level. The design does not allow employees to prevent or detect misstatements on a timely basis, but the risk of a material misstatement is low.
- Significant deficiency. A deficiency, or combination of deficiencies, less severe than a material weakness but important enough to merit attention from those overseeing financial reporting, typically the audit committee.
- Material weakness. A deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on time.
The evaluation turns on three factors considered together: how likely a misstatement is, how large it could be, and whether compensating controls reduce the severity.7PCAOB. Auditing Standard 5 Appendix A – Definitions A material weakness triggers mandatory disclosure and, for accelerated filers, appears in the external auditor’s report. The SEC has said disclosure alone does not satisfy the company’s obligations; management must actively remediate, and prolonged inaction can lead to enforcement.8U.S. Securities and Exchange Commission. SEC Charges Four Public Companies With Longstanding ICFR Failures
Applying the 17 Principles at a Smaller Organization
The 17 principles apply regardless of size, but implementation looks different at a 50-person company than at a Fortune 500. The framework is principles-based specifically to allow that flexibility: it says what has to be accomplished, not exactly how.1COSO. Internal Control Smaller organizations typically have fewer management layers, less formal documentation, and limited staff for segregating duties. What the framework does not allow is treating size as a reason to skip a principle.
Where a small company cannot fully segregate duties because only three people handle all of finance, compensating controls fill the gap. The owner reviews every bank reconciliation. An outside accountant performs monthly reviews. The board receives detailed transaction reports. Smaller issuers that do not qualify as accelerated filers are also exempt from the external auditor attestation requirement under SOX Section 404(c), which reduces compliance cost, but management still must assess its own controls and report on their effectiveness.3GovInfo. Sarbanes-Oxley Act of 2002