COSO Internal Control - Integrated Framework (2013)
Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Control Activities
The organization selects and develops control activities that contribute to the mitigation of risks to acceptable levels.
- Control matrix
- Risk-control linkage
- Control descriptions
- Preventive vs detective mix
- Controls not linked to risks
- Over-reliance on detective controls
The organization selects and develops general control activities over technology to support the achievement of objectives.
- Access management policy
- Change management procedures
- Operations monitoring records
- ITGC testing
- No segregation of duties in IT
- Change management informal
The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.
- Policy library
- Standard operating procedures
- Acknowledgement records
- Policy review cycle
- Policies outdated
- No procedures backing policies
The organization selects and develops control activities that contribute to mitigating risks. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Activities.
- Control matrix
- ITGC documentation
- Policy register
- Procedure manuals
- ITGCs untested
- Policies stale
- Controls not segregated
The organization selects and develops general controls over technology. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Activities.
- Control matrix
- ITGC documentation
- Policy register
- Procedure manuals
- ITGCs untested
- Policies stale
- Controls not segregated
The organization deploys control activities through policies and procedures. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Activities.
- Control matrix
- ITGC documentation
- Policy register
- Procedure manuals
- ITGCs untested
- Policies stale
- Controls not segregated
The organization selects and develops control activities that contribute to mitigation of risks to the achievement of objectives to acceptable levels.
- Control matrix mapped to risks
- Process narratives/flowcharts
- Segregation of duties analysis
- Control selection not linked to risk assessment results
- Mix of preventive and detective controls unbalanced
- Control activities not refreshed when processes change
- Manual controls relied upon where automation is feasible
- Control rationalisation not performed leading to redundancy
The organization selects and develops general control activities over technology to support the achievement of objectives.
- IT general controls policy (access, change, operations)
- IT control framework mapping (COBIT)
- IT general controls scope not aligned to in scope applications
- Cloud and SaaS environments excluded from ITGC coverage
- Control ownership for shared platforms unclear
- Configuration management absent for critical infrastructure
- Reliance on third party ITGCs without verification
The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.
- Policy and procedure library
- Policy ownership and approval workflow
- Policy review schedule
- Policies exist but procedures to operationalise them are missing
- Policy ownership unclear and review cadence lapsed
- Local procedures contradict global policy
- No mechanism to confirm staff awareness of policies
- Exceptions to policy not formally approved or tracked
Control Environment
The organization demonstrates a commitment to integrity and ethical values.
- Code of conduct
- Ethics training records
- Annual ethics attestations
- Disciplinary action logs
- Code not refreshed annually
- No measurement of adherence
The board demonstrates independence from management and exercises oversight of internal control development and performance.
- Audit committee charter
- Independence assessments
- Board minutes covering ICFR
- Director qualifications
- Audit committee lacks financial expert
- No documented ICFR oversight
Management establishes structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
- Org charts
- Delegation of authority matrix
- Job descriptions
- RACI matrices
- Unclear authority levels
- Stale org chart
The organization demonstrates commitment to attract, develop, and retain competent individuals.
- Competency frameworks
- Training plans
- Performance reviews
- Certification tracking
- No competency baseline
- Training not role-specific
The organization holds individuals accountable for their internal control responsibilities.
- Performance scorecards with control measures
- Incentive structures
- Control owner attestations
- No control accountability in performance plans
The organization demonstrates commitment to integrity and ethical values. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.
- Code of conduct
- Board charter
- Org structure document
- Accountability matrix
- Code not communicated
- Board not independent
- Accountability unclear
The board demonstrates independence from management and exercises oversight of internal control. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.
- Code of conduct
- Board charter
- Org structure document
- Accountability matrix
- Code not communicated
- Board not independent
- Accountability unclear
Management establishes structures, reporting lines, authorities, and responsibilities. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.
- Code of conduct
- Board charter
- Org structure document
- Accountability matrix
- Code not communicated
- Board not independent
- Accountability unclear
The organization demonstrates commitment to attract, develop, and retain competent individuals. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.
- Code of conduct
- Board charter
- Org structure document
- Accountability matrix
- Code not communicated
- Board not independent
- Accountability unclear
The organization holds individuals accountable for their internal control responsibilities. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.
- Code of conduct
- Board charter
- Org structure document
- Accountability matrix
- Code not communicated
- Board not independent
- Accountability unclear
The organization demonstrates a commitment to integrity and ethical values, set by tone at the top and reinforced through standards of conduct.
- Code of conduct/ethics
- Tone-at-the-top communications
- Ethics policy approved by board
- Code of conduct not refreshed or attested annually
- Whistleblower channel lacks anonymity or follow up
- Ethics violations not consistently sanctioned
- Tone at the top not measurable through employee surveys
- Third parties not bound to equivalent ethical standards
The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
- Board charter
- Audit committee charter
- Director independence assessments
- Board lacks members with relevant risk or technology expertise
- Audit committee charter not reviewed or refreshed
- Executive sessions with assurance providers infrequent
- Oversight of management override risk absent
- Reporting to the board not structured to surface emerging risks
Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in pursuit of objectives.
- Organizational chart
- Delegation of authority matrix
- Job descriptions/RACI
- Delegations of authority outdated and unsigned
- Three lines model not implemented in practice
- Roles and responsibilities ambiguous at process boundaries
- Span of control too wide weakening supervision
- Restructuring not followed by control reassignment
The organization demonstrates a commitment to attract, develop, and retain competent individuals aligned with objectives.
- Competency frameworks
- Training and development policy
- Succession plan
- Job competency requirements not defined for control owners
- Training completion not enforced or tracked
- Succession plans absent for key control roles
- Performance evaluations omit control responsibilities
- Skills gaps not assessed against control needs
The organization holds individuals accountable for their internal control responsibilities in pursuit of objectives.
- Accountability policy
- Performance management procedures
- Incentive/compensation policies linked to controls
- Control failures not reflected in performance reviews
- Incentive structures conflict with control objectives
- Consequences for repeat issues inconsistent
- Ownership of cross functional controls disputed
- No mechanism to track personal accountability for issues
Information and Communication
The organization obtains or generates and uses relevant quality information. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Information and Communication.
- Information requirements memo
- Internal comms plan
- External disclosure controls
- Whistleblower channel
- Data quality issues
- Whistleblower channel unused
- Disclosures untimely
The organization internally communicates information including internal control objectives. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Information and Communication.
- Information requirements memo
- Internal comms plan
- External disclosure controls
- Whistleblower channel
- Data quality issues
- Whistleblower channel unused
- Disclosures untimely
The organization communicates with external parties regarding internal control matters. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Information and Communication.
- Information requirements memo
- Internal comms plan
- External disclosure controls
- Whistleblower channel
- Data quality issues
- Whistleblower channel unused
- Disclosures untimely
The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.
- Data quality controls
- Source system documentation
- Reporting accuracy reviews
- EUC inventory
- No EUC controls
- Data lineage unclear
The organization internally communicates information, including objectives and responsibilities for internal control.
- Internal control communication plan
- Townhalls
- Intranet articles
- Whistleblower channels
- No documented communication cadence
The organization communicates with external parties regarding matters affecting the functioning of internal control.
- Vendor communication procedures
- Customer communications
- Regulatory filings
- Investor relations records
- No external whistleblower channel
- Vendor expectations unclear
The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.
- Information requirements per process
- Data quality standards
- System of record inventory
- Information sources for controls not assessed for reliability
- End user computing tools used for key reports without controls
- Data lineage from source to report undocumented
- Report logic changes deployed without recertification
- Critical reports not identified or inventoried
The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
- Internal communication plan
- Whistleblower/escalation channels policy
- Control responsibilities not embedded in job descriptions
- Cross functional communication on issues delayed
- Escalation paths to leadership unclear
- Board reporting on internal control quality inconsistent
- Changes to objectives not communicated to control owners
The organization communicates with external parties regarding matters affecting the functioning of internal control.
- External communications policy
- Regulatory reporting calendar
- Investor relations procedures
- External stakeholder feedback channels limited or unused
- Regulatory communications not coordinated centrally
- Customer reported issues not routed to control owners
- Vendors not informed of expectations on internal control
- Public commitments not aligned to operational reality
Monitoring Activities
The organization selects and performs ongoing and/or separate evaluations. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Monitoring Activities.
- Monitoring plan
- Internal audit reports
- Deficiency register
- Remediation tracker
- No internal audit
- Deficiencies untracked
- Remediation slow
The organization evaluates and communicates internal control deficiencies in a timely manner. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Monitoring Activities.
- Monitoring plan
- Internal audit reports
- Deficiency register
- Remediation tracker
- No internal audit
- Deficiencies untracked
- Remediation slow
The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
- Internal audit plan
- Control self-assessment results
- Continuous monitoring dashboards
- Management testing
- No CCM in place
- Testing only annual
The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action.
- Deficiency log
- Remediation tracking
- Severity assessment criteria
- Board reports on deficiencies
- No severity classification
- Remediation slow
The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether components of internal control are present and functioning.
- Internal audit plan
- Management self-assessment methodology
- Continuous monitoring program design
- Continuous monitoring limited to a small subset of controls
- Internal audit scope not refreshed against current risks
- Self assessments lack independent validation
- Evaluation results not consolidated for management view
- Coverage gaps between assurance providers not identified
The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board.
- Deficiency evaluation methodology (deficiency, significant deficiency, material weakness)
- Remediation tracking policy
- Deficiency severity classification inconsistent
- Issues aged beyond agreed remediation timelines
- Root cause analysis shallow and not addressing systemic causes
- Communication to audit committee delayed or filtered
- No trending or thematic analysis across deficiencies
Risk Assessment
The organization specifies objectives with sufficient clarity to enable identification and assessment of risks relating to objectives.
- Strategic plan
- Operational/reporting/compliance objectives
- Materiality thresholds
- Objectives not cascaded to process and control level
- Reporting objectives not aligned to applicable frameworks
- Compliance objectives incomplete for regulatory landscape
- Tolerances and risk appetite not defined
- Objectives not refreshed when strategy changes
The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how they should be managed.
- Enterprise risk assessment methodology
- Risk register
- Risk rating criteria (likelihood/impact)
- Risk universe incomplete missing emerging risks
- Inherent versus residual risk not consistently distinguished
- Risk likelihood and impact scales applied subjectively
- Process owners not engaged in risk identification
- Aggregation of risks across the entity not performed
The organization considers the potential for fraud in assessing risks to the achievement of objectives, including fraudulent reporting, misappropriation, and corruption.
- Fraud risk assessment
- Anti-fraud policy
- Whistleblower policy
- Fraud risk assessment not refreshed annually
- Management override risk not specifically addressed
- Fraud schemes considered too narrow in scope
- Anti fraud controls not mapped to identified schemes
- No fraud risk reporting to audit committee
The organization identifies and assesses changes that could significantly impact the system of internal control.
- Change management policy
- Triggers for risk reassessment
- Significant change criteria undefined or interpreted inconsistently
- Risk reassessment not triggered by organisational change
- External changes such as regulation not monitored centrally
- Control impact of new systems not assessed pre go live
- Change triggered reviews not documented as evidence
The organization specifies objectives with sufficient clarity to enable identification and assessment of risks.
- Financial reporting objectives
- Operational objectives
- Compliance objectives
- Materiality thresholds
- Objectives too vague
- Materiality not defined
Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so identified risk is treated rather than only recorded.
- Control implementation statement for RA-7 citing the system mission and inheritance from common controls
- Risk register with likelihood, impact, and treatment owners
- Vulnerability scan reports for internal, external, and authenticated scopes
- Penetration test report with retest evidence
- Threat intelligence feed subscriptions and triage workflow
- Risk acceptance memos signed by accountable executives
- Penetration tests scope narrow and exclude key applications
- Scan coverage gaps for containerised and ephemeral workloads
- Threat intelligence consumed but not operationalised into detections
- High severity vulnerabilities exceed remediation SLA without risk acceptance
The organization considers the potential for fraud in assessing risks to the achievement of objectives.
- Fraud risk assessment
- Fraud scenarios catalog
- Anti-fraud controls mapping
- Whistleblower data
- No fraud risk assessment
- Override risks not addressed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the COSO Internal Control - Integrated Framework (2013) framework page.