A board chair asks a CFO whether internal control is "effective" and gets back a 200-page binder of process narratives. The right answer is one sentence: are all five COSO components present, functioning, and operating together?
After the savings-and-loan failures of the 1980s, five professional bodies (AAA, AICPA, FEI, IIA, IMA) put a common definition of internal control on paper. The Committee of Sponsoring Organizations published the framework in 1992 and revised it in 2013. The 2013 update made the principles explicit and reflected modern risks like outsourcing and technology dependence.
The framework is now the de facto standard. SEC issuers use it for SOX 404. External auditors use it to evaluate ICFR. When the exam says "the framework," it means COSO IC-IF (2013).
KEY: COSO defines internal control as a process, effected by people, designed to provide reasonable assurance about achieving objectives. Process not event, people not paper, reasonable not absolute.
HIGH-FREQUENCY: The exam tests which category an objective belongs to.
Common mistakes
- Confusing the 5 components with the 3 objective categories. Components are how internal control is structured. Objective categories are what it aims to achieve. Trap: a question lists "operations, reporting, compliance" and asks for the components, the right answer lists the five components, not those three.
- Thinking COSO provides absolute assurance. It provides reasonable assurance. Any choice claiming controls "ensure" or "guarantee" outcomes is wrong. Five inherent limitations prevent absolute assurance.
- Treating "present" and "functioning" as the same. A control is present if appropriately designed. It is functioning if it operates as designed. The procurement policy that exists on paper but the owner waives is present-not-functioning.
Bottom line
- COSO IC-IF (2013) defines internal control as a process providing reasonable, not absolute, assurance over three objective categories: operations, reporting, and compliance
- Five components, 17 principles: Control Environment (5), Risk Assessment (4), Control Activities (3), Information \& Communication (3), Monitoring (2)
- All five components must be present, functioning, and operating together; effective internal control is a system-level conclusion
- Present means appropriately designed; functioning means operating as designed
Exam shortcut
When a question asks which COSO component covers a control, look for the purpose. Tone, ethics, and oversight signals are always Control Environment. "Identify and analyze" language signals Risk Assessment. Reconciliations, authorizations, and ITGCs are Control Activities. Reporting and information flow signals Information \& Communication. Periodic evaluations and deficiency reporting signals Monitoring. Remember: Components = how, Categories = what, Levels = where, Limitations = why not absolute. Five-three-four-five.
The full lesson (about 2,149 words, 14 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- II.C1
Browse all free CPA AUD lessons or jump into free CPA AUD practice questions.