5.3 COSO 2013 Internal Control Framework: 5 Components & 17 Principles

Key Takeaways

  • The COSO 2013 Internal Control - Integrated Framework defines internal control as a process effected by an entity's board, management, and personnel, designed to provide reasonable assurance regarding operations, reporting, and compliance objectives.
  • Internal control consists of five interrelated components (CRIME): Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.
  • The framework articulates 17 principles across the five components; an effective system of internal control requires that all five components and all 17 relevant principles are present and functioning in an integrated manner.
  • The Control Environment sets the overall tone at the top and provides the structural discipline and ethical foundation for all other internal control components.
  • Segregation of duties under Control Activities requires separating the incompatible functions of Authorization, Recording (recordkeeping), Custody of assets, and periodic Reconciliation (ARC).
Last updated: September 2026

5.3 COSO 2013 Internal Control Framework: 5 Components & 17 Principles

CPA Exam Relevance: The Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework is the foundational architecture of internal control tested on the CPA AUD examination. Candidates must know the five components backwards and forwards (mnemonic: CRIME), understand how the 17 principles map to each component, and apply rules regarding segregation of duties and control effectiveness.


1. COSO Framework Architecture & Foundational Definition

The COSO was organized in 1985 by five major financial and accounting professional organizations: the American Accounting Association (AAA), the American Institute of CPAs (AICPA), Financial Executives International (FEI), the Institute of Internal Auditors (IIA), and the Institute of Management Accountants (IMA). In 2013, COSO issued an updated, codified version of its Internal Control — Integrated Framework to reflect the modern global business and technological landscape.

The Authoritative Definition of Internal Control

Authoritative Definition: Internal control is a process, effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.

Key Conceptual Attributes of Internal Control

  1. A Dynamic Process: Internal control is not a static checklist or policy binder; it is an ongoing series of actions and mechanisms embedded into day-to-day operations.
  2. Effected by People: Controls are designed, implemented, and executed by human beings at every level of the organization—from the board of directors down to operational clerks.
  3. Provides Reasonable (Not Absolute) Assurance: Due to inherent limitations (cost-benefit constraints, human error, management override, and collusion), no system of internal control can guarantee absolute financial accuracy or zero fraud.
  4. Geared to the Achievement of Objectives (The Three Categories - ORC):
    • Operations Objectives: Pertain to the effectiveness and efficiency of operations, including operational and financial performance goals and safeguarding assets against loss.
    • Reporting Objectives: Pertain to internal and external financial and non-financial reporting, encompassing reliability, timeliness, and transparency. (This is the primary domain of the external financial statement audit!)
    • Compliance Objectives: Pertain to adherence to applicable laws, regulations, and industry mandates.

2. The Five Components of Internal Control (CRIME)

The COSO Framework arranges internal control into five integrated components. Candidates must memorize the mnemonic CRIME:

+-------------------------------------------------------------------------+
|                   THE FIVE COSO COMPONENTS (CRIME)                      |
|                                                                         |
|   C - Control Environment       (Tone at the top; ethics & governance)  |
|   R - Risk Assessment           (Identifying & analyzing business risks) |
|   I - Information & Comm.       (Capturing & exchanging quality data)   |
|   M - Monitoring Activities     (Ongoing & separate evaluations)        |
|   E - Existing Control Act.     (Policies & procedures that enforce)    |
+-------------------------------------------------------------------------+
+-------------------------------------------------------------------------+
|                        THE COSO CUBE DIMENSIONS                         |
|                                                                         |
|   OBJECTIVES:       Operations | Reporting | Compliance                 |
|   COMPONENTS:       Control Environment                                 |
|                     Risk Assessment                                     |
|                     Control Activities                                  |
|                     Information and Communication                       |
|                     Monitoring Activities                               |
|   ORGANIZATIONAL    Entity-Level | Division | Operating Unit | Function |
|   STRUCTURE:                                                            |
+-------------------------------------------------------------------------+

3. The 17 Principles Codified Across the 5 Components

COSO 2013 formalizes 17 explicit principles that represent the fundamental concepts necessary to achieve effective internal control across the five components:

Component 1: Control Environment (5 Principles)

The Control Environment sets the tone of the organization, influencing the control consciousness of its people. It is the foundation for all other components.

  • Principle 1 (Ethics & Integrity): The organization demonstrates a commitment to integrity and ethical values. (Top leadership communicates a zero-tolerance policy for unethical behavior, publishes a code of conduct, and removes incentives that tempt employees to act dishonestly).
  • Principle 2 (Board Oversight): The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control. (The board maintains an active, independent audit committee composed entirely of outside directors who interface directly with internal and external auditors).
  • Principle 3 (Organizational Structure): Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives. (Defines clear reporting channels, prevents overlapping authorities, and avoids organizational bottlenecks).
  • Principle 4 (Competence): The organization demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives. (Enforces rigorous hiring standards, provides ongoing technical training, evaluates job performance, and plans for succession).
  • Principle 5 (Accountability): The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives. (Establishes clear performance metrics, links compensation and promotions to control adherence, and applies disciplinary measures consistently for control breaches).

Component 2: Risk Assessment (4 Principles)

Risk Assessment involves a dynamic and iterative process for identifying and assessing risks to achieving the entity's objectives.

  • Principle 6 (Specify Objectives): The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives. (Defines financial reporting materiality boundaries and GAAP presentation standards clearly).
  • Principle 7 (Analyze Risks): The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed. (Assesses likelihood and magnitude of risks across operational units and decides whether to accept, avoid, reduce, or share them).
  • Principle 8 (Fraud Risk Consideration): The organization considers the potential for fraud in assessing risks to the achievement of objectives. (Analyzes the fraud triangle: incentives/pressures, opportunities for management override or asset theft, and rationalizations/attitudes).
  • Principle 9 (Assess Significant Change): The organization identifies and assesses changes that could significantly affect the system of internal control. (Monitors shifts in the external regulatory environment, rapid business model evolution, corporate acquisitions, or leadership turnover).

Component 3: Control Activities (3 Principles)

Control Activities are the actions established through policies and procedures that help ensure that management's directives to mitigate risks are carried out.

  • Principle 10 (Select & Develop Controls): The organization selects and develops control activities that contribute to the mitigation of risks to acceptable levels. (Establishes preventative and detective controls, approvals, authorizations, verifications, reconciliations, and supervisory reviews).
  • Principle 11 (Technology Controls / ITGCs): The organization selects and develops general control activities over technology to support the achievement of objectives. (Implements IT general controls over access security, software development, change management, and computer operations).
  • Principle 12 (Deploy Through Policies & Procedures): The organization deploys control activities through policies that establish what is expected and procedures that put policies into action. (Documents standard operating procedures and holds process owners responsible for executing designated tasks on a timely schedule).

Component 4: Information and Communication (3 Principles)

Information and Communication enables the organization to carry out internal control responsibilities in support of its objectives.

  • Principle 13 (Obtain Quality Information): The organization obtains or generates and uses relevant, quality information to support the functioning of internal control. (Ensures information is timely, accurate, complete, accessible, and protected).
  • Principle 14 (Internal Communication): The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control. (Operates secure, anonymous whistleblower reporting hotlines and ensures two-way communication channels from front-line staff to the board).
  • Principle 15 (External Communication): The organization communicates with external parties regarding matters affecting the functioning of internal control. (Communicates transparently with shareholders, regulatory bodies, external auditors, rating agencies, and customers).

Component 5: Monitoring Activities (2 Principles)

Monitoring Activities are ongoing evaluations, separate evaluations, or some combination of the two used to ascertain whether each of the five components of internal control is present and functioning.

  • Principle 16 (Ongoing & Separate Evaluations): The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. (Ongoing monitoring includes continuous supervisory reviews and automated system exception logs; separate evaluations include periodic reviews conducted by internal auditors).
  • Principle 17 (Deficiency Reporting): The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors. (Ensures remediation happens promptly and control gaps are tracked to resolution).

4. Criteria for an Effective System of Internal Control

Under COSO 2013, management or an auditor evaluating internal control can conclude that an effective system of internal control is in place only when:

  1. Present: The components and relevant principles exist in the design and implementation of the system of internal control.
  2. Functioning: The components and relevant principles continue to operate in the execution of the system of internal control.
  3. Operating in an Integrated Manner: All five components work together in an interrelated fashion to reduce, to an acceptable level, the risk of not achieving an entity objective.

The "Major Deficiency" Rule

Under COSO, a Major Deficiency is defined as an internal control deficiency or combination of deficiencies that severely reduces the likelihood that an entity can achieve its operational, reporting, or compliance objectives.

Key Exam Rule: If a major deficiency exists with respect to the presence and functioning of even one component or relevant principle, or if the components do not operate in an integrated manner, the entity cannot conclude that it has an effective system of internal control under COSO.


5. Control Activities in Action: Segregation of Duties (ARC)

Of all control activities, Segregation of Duties (SoD) is the most frequently tested on the CPA exam. Proper segregation of duties ensures that no single individual is in a position to both perpetrate and conceal errors or fraud in the normal course of their duties.

The ARC Framework

To maintain robust internal control, an entity must assign four fundamentally incompatible functions to different individuals or separate departments:

+-------------------------------------------------------------------------+
|                     THE ARC FRAMEWORK OF SEGREGATION                    |
|                                                                         |
|   [A] AUTHORIZATION  --> Approving transactions, purchase orders, credit |
|   [R] RECORDING      --> Creating journal entries, posting to ledgers    |
|   [C] CUSTODY        --> Holding cash, checks, warehouse inventory       |
|   -------------------------------------------------------------------   |
|   [*] RECONCILIATION --> Independent comparison of physical vs. records  |
+-------------------------------------------------------------------------+
FunctionScope & PurposeIncompatible Pairing / Severe Hazard
Authorization (A)Approval of transactions, credit limits, contracts, and payment vouchers by authorized managers.Pairing Authorization with Custody: A manager who can authorize purchase orders and also holds custody of physical goods can order unauthorized items for personal use.
Recording (R)Entering invoices, creating journal entries, maintaining subsidiary ledgers, and posting to the general ledger.Pairing Recording with Custody: An accountant who maintains accounts receivable records and also handles customer cash receipts can divert cash and cover the theft via improper write-offs (lapping).
Custody (C)Physical access to or electronic control over assets: cash, checks, negotiable securities, warehouse inventory, equipment.Pairing Custody with Reconciliation: A clerk who signs cash disbursements and also prepares the monthly bank reconciliation can write fraudulent checks and hide them by misstating reconciling items.
Reconciliation (*)Verifying the accuracy of records by comparing independent records to physical counts or bank statements.Reconciliation must always be performed by an independent individual who has neither custody of the asset nor recording responsibility for the underlying ledger.

6. Realistic Case Scenario: Evaluating COSO Deficiencies

Scenario: Midwest Distribution Corporation

Midwest Distribution Corp is a privately owned wholesale distributor. During the financial statement audit, the external auditor identifies three specific practices:

  1. The Warehouse Manager's Dual Role: The warehouse manager maintains physical custody of inventory and has sole authority to sign off on inventory write-down vouchers for damaged goods without review by the corporate controller.
  2. Audit Committee Absence: The company's board of directors consists solely of the founder/CEO and two family members who serve as vice presidents. The company has no independent directors and no formal audit committee.
  3. Accounting Software Access: The accounts payable clerk enters vendor invoices into the general ledger and also generates the weekly batch of automated electronic payment checks sent to the bank.

Auditor's Evaluation Under COSO 2013

  • Warehouse Manager: Direct violation of segregation of duties. Combining Custody (warehouse manager) with Authorization (signing write-down vouchers) allows the manager to steal inventory and mask the shortage by authorizing a "damaged goods" write-down. This is a severe deficiency in Control Activities (Principle 10).
  • Board Composition: A weakness in the Control Environment (Principle 2). A board made up only of the founder and family executives provides little objective oversight of management. COSO lets smaller entities scale oversight, but the auditor should weigh this weakness when assessing the risk of management override.
  • Accounts Payable Clerk: Incompatible pairing of Recording (entering invoices) with Custody (check generation). An AP clerk could enter a fictitious vendor invoice, generate an automated check to a personal bank account, and manipulate the ledger. This represents a significant breakdown in Control Activities (Principles 10 & 11).

7. Common Exam Traps & Pitfalls

  • Trap 1: Confusing Client Risk Assessment with Auditor Risk Assessment. Candidates frequently mix up COSO Component 2 (Risk Assessment) with the external auditor's risk assessment procedures. COSO Risk Assessment refers to management's internal process of identifying, analyzing, and managing risks that threaten the entity's business objectives. The external auditor merely evaluates how effectively management performs this process.
  • Trap 2: Assuming Strong Control Activities Can Compensate for a Rotten Control Environment. If executive management creates an aggressive, intimidating environment, falsifies executive expenses, or ignores internal controls, no automated reconciliations or password controls can overcome the risk of management override. The Control Environment is the pervasive foundation; if it fails, the entire system is ineffective.
  • Trap 3: Believing Internal Audit Belongs to Control Activities. The internal audit function is an evaluation mechanism that assesses whether controls are functioning across the organization. Therefore, internal audit activities reside primarily within Monitoring Activities (Component 5), not Control Activities.
Test Your Knowledge

An entity's board of directors fails to establish an independent audit committee, and executive management consistently overrides established financial reporting controls to meet quarterly earnings expectations. Which component of the COSO 2013 framework is most directly compromised by this condition?

A
B
C
D
Test Your Knowledge

According to the COSO 2013 Internal Control - Integrated Framework, what condition must be met for management or an auditor to conclude that an entity's system of internal control is effective?

A
B
C
D
Test Your Knowledge

In designing internal control activities over cash disbursements, an entity seeks to establish adequate segregation of duties. Which of the following job descriptions reflects an incompatible assignment of responsibilities that creates a severe internal control deficiency?

A
B
C
D
Test Your Knowledge

Under the Risk Assessment component of the COSO 2013 framework, which principle specifically requires management to evaluate incentives, pressures, opportunities, and rationalizations that could lead to material misstatements in financial reporting?

A
B
C
D