Skip to content

Evidence request lists

COSO Internal Control - Integrated Framework (2013)

Evidence request list. 46 controls, 46 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Control Activities

CA-10
Selects and Develops Control Activities

The organization selects and develops control activities that contribute to the mitigation of risks to acceptable levels.

Artefacts an auditor will ask for
  • Control matrix
  • Risk-control linkage
  • Control descriptions
  • Preventive vs detective mix
Where this commonly fails
  • Controls not linked to risks
  • Over-reliance on detective controls
CA-11
Selects and Develops General Controls over Technology

The organization selects and develops general control activities over technology to support the achievement of objectives.

Artefacts an auditor will ask for
  • Access management policy
  • Change management procedures
  • Operations monitoring records
  • ITGC testing
Where this commonly fails
  • No segregation of duties in IT
  • Change management informal
CA-12
Deploys Through Policies and Procedures

The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.

Artefacts an auditor will ask for
  • Policy library
  • Standard operating procedures
  • Acknowledgement records
  • Policy review cycle
Where this commonly fails
  • Policies outdated
  • No procedures backing policies
COSO-IC-CA-10
The organization selects and develops control activities for asset safeguarding and mitigating risks to the achievement of objectives

The organization selects and develops control activities that contribute to mitigating risks. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Activities.

Artefacts an auditor will ask for
  • Control matrix
  • ITGC documentation
  • Policy register
  • Procedure manuals
Where this commonly fails
  • ITGCs untested
  • Policies stale
  • Controls not segregated
COSO-IC-CA-11
The organization selects and develops general controls over technology

The organization selects and develops general controls over technology. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Activities.

Artefacts an auditor will ask for
  • Control matrix
  • ITGC documentation
  • Policy register
  • Procedure manuals
Where this commonly fails
  • ITGCs untested
  • Policies stale
  • Controls not segregated
COSO-IC-CA-12
The organization deploys control activities through policies and procedures

The organization deploys control activities through policies and procedures. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Activities.

Artefacts an auditor will ask for
  • Control matrix
  • ITGC documentation
  • Policy register
  • Procedure manuals
Where this commonly fails
  • ITGCs untested
  • Policies stale
  • Controls not segregated
P10
Selects and Develops Control Activities

The organization selects and develops control activities that contribute to mitigation of risks to the achievement of objectives to acceptable levels.

Artefacts an auditor will ask for
  • Control matrix mapped to risks
  • Process narratives/flowcharts
  • Segregation of duties analysis
Where this commonly fails
  • Control selection not linked to risk assessment results
  • Mix of preventive and detective controls unbalanced
  • Control activities not refreshed when processes change
  • Manual controls relied upon where automation is feasible
  • Control rationalisation not performed leading to redundancy
P11
Selects and Develops General Controls over Technology

The organization selects and develops general control activities over technology to support the achievement of objectives.

Artefacts an auditor will ask for
  • IT general controls policy (access, change, operations)
  • IT control framework mapping (COBIT)
Where this commonly fails
  • IT general controls scope not aligned to in scope applications
  • Cloud and SaaS environments excluded from ITGC coverage
  • Control ownership for shared platforms unclear
  • Configuration management absent for critical infrastructure
  • Reliance on third party ITGCs without verification
P12
Deploys through Policies and Procedures

The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.

Artefacts an auditor will ask for
  • Policy and procedure library
  • Policy ownership and approval workflow
  • Policy review schedule
Where this commonly fails
  • Policies exist but procedures to operationalise them are missing
  • Policy ownership unclear and review cadence lapsed
  • Local procedures contradict global policy
  • No mechanism to confirm staff awareness of policies
  • Exceptions to policy not formally approved or tracked

Control Environment

CE-1
Demonstrates Commitment to Integrity and Ethical Values

The organization demonstrates a commitment to integrity and ethical values.

Artefacts an auditor will ask for
  • Code of conduct
  • Ethics training records
  • Annual ethics attestations
  • Disciplinary action logs
Where this commonly fails
  • Code not refreshed annually
  • No measurement of adherence
CE-2
Exercises Oversight Responsibility

The board demonstrates independence from management and exercises oversight of internal control development and performance.

Artefacts an auditor will ask for
  • Audit committee charter
  • Independence assessments
  • Board minutes covering ICFR
  • Director qualifications
Where this commonly fails
  • Audit committee lacks financial expert
  • No documented ICFR oversight
CE-3
Establishes Structure, Authority, and Responsibility

Management establishes structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.

Artefacts an auditor will ask for
  • Org charts
  • Delegation of authority matrix
  • Job descriptions
  • RACI matrices
Where this commonly fails
  • Unclear authority levels
  • Stale org chart
CE-4
Demonstrates Commitment to Competence

The organization demonstrates commitment to attract, develop, and retain competent individuals.

Artefacts an auditor will ask for
  • Competency frameworks
  • Training plans
  • Performance reviews
  • Certification tracking
Where this commonly fails
  • No competency baseline
  • Training not role-specific
CE-5
Enforces Accountability

The organization holds individuals accountable for their internal control responsibilities.

Artefacts an auditor will ask for
  • Performance scorecards with control measures
  • Incentive structures
  • Control owner attestations
Where this commonly fails
  • No control accountability in performance plans
COSO-IC-CE-01
The organization demonstrates commitment to integrity and ethical values

The organization demonstrates commitment to integrity and ethical values. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.

Artefacts an auditor will ask for
  • Code of conduct
  • Board charter
  • Org structure document
  • Accountability matrix
Where this commonly fails
  • Code not communicated
  • Board not independent
  • Accountability unclear
COSO-IC-CE-02
The board demonstrates independence from management and exercises oversight of internal control

The board demonstrates independence from management and exercises oversight of internal control. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.

Artefacts an auditor will ask for
  • Code of conduct
  • Board charter
  • Org structure document
  • Accountability matrix
Where this commonly fails
  • Code not communicated
  • Board not independent
  • Accountability unclear
COSO-IC-CE-03
Management establishes structures, reporting lines, authorities, and responsibilities

Management establishes structures, reporting lines, authorities, and responsibilities. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.

Artefacts an auditor will ask for
  • Code of conduct
  • Board charter
  • Org structure document
  • Accountability matrix
Where this commonly fails
  • Code not communicated
  • Board not independent
  • Accountability unclear
COSO-IC-CE-04
The organization demonstrates commitment to attract, develop, and retain competent individuals

The organization demonstrates commitment to attract, develop, and retain competent individuals. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.

Artefacts an auditor will ask for
  • Code of conduct
  • Board charter
  • Org structure document
  • Accountability matrix
Where this commonly fails
  • Code not communicated
  • Board not independent
  • Accountability unclear
COSO-IC-CE-05
The organization holds individuals accountable for their internal control responsibilities

The organization holds individuals accountable for their internal control responsibilities. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.

Artefacts an auditor will ask for
  • Code of conduct
  • Board charter
  • Org structure document
  • Accountability matrix
Where this commonly fails
  • Code not communicated
  • Board not independent
  • Accountability unclear
P1
Demonstrates Commitment to Integrity and Ethical Values

The organization demonstrates a commitment to integrity and ethical values, set by tone at the top and reinforced through standards of conduct.

Artefacts an auditor will ask for
  • Code of conduct/ethics
  • Tone-at-the-top communications
  • Ethics policy approved by board
Where this commonly fails
  • Code of conduct not refreshed or attested annually
  • Whistleblower channel lacks anonymity or follow up
  • Ethics violations not consistently sanctioned
  • Tone at the top not measurable through employee surveys
  • Third parties not bound to equivalent ethical standards
P2
Exercises Oversight Responsibility

The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.

Artefacts an auditor will ask for
  • Board charter
  • Audit committee charter
  • Director independence assessments
Where this commonly fails
  • Board lacks members with relevant risk or technology expertise
  • Audit committee charter not reviewed or refreshed
  • Executive sessions with assurance providers infrequent
  • Oversight of management override risk absent
  • Reporting to the board not structured to surface emerging risks
P3
Establishes Structure, Authority, and Responsibility

Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in pursuit of objectives.

Artefacts an auditor will ask for
  • Organizational chart
  • Delegation of authority matrix
  • Job descriptions/RACI
Where this commonly fails
  • Delegations of authority outdated and unsigned
  • Three lines model not implemented in practice
  • Roles and responsibilities ambiguous at process boundaries
  • Span of control too wide weakening supervision
  • Restructuring not followed by control reassignment
P4
Demonstrates Commitment to Competence

The organization demonstrates a commitment to attract, develop, and retain competent individuals aligned with objectives.

Artefacts an auditor will ask for
  • Competency frameworks
  • Training and development policy
  • Succession plan
Where this commonly fails
  • Job competency requirements not defined for control owners
  • Training completion not enforced or tracked
  • Succession plans absent for key control roles
  • Performance evaluations omit control responsibilities
  • Skills gaps not assessed against control needs
P5
Enforces Accountability

The organization holds individuals accountable for their internal control responsibilities in pursuit of objectives.

Artefacts an auditor will ask for
  • Accountability policy
  • Performance management procedures
  • Incentive/compensation policies linked to controls
Where this commonly fails
  • Control failures not reflected in performance reviews
  • Incentive structures conflict with control objectives
  • Consequences for repeat issues inconsistent
  • Ownership of cross functional controls disputed
  • No mechanism to track personal accountability for issues

Information and Communication

COSO-IC-IC-13
The organization obtains or generates and uses relevant quality information

The organization obtains or generates and uses relevant quality information. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Information and Communication.

Artefacts an auditor will ask for
  • Information requirements memo
  • Internal comms plan
  • External disclosure controls
  • Whistleblower channel
Where this commonly fails
  • Data quality issues
  • Whistleblower channel unused
  • Disclosures untimely
COSO-IC-IC-14
The organization internally communicates information including internal control objectives

The organization internally communicates information including internal control objectives. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Information and Communication.

Artefacts an auditor will ask for
  • Information requirements memo
  • Internal comms plan
  • External disclosure controls
  • Whistleblower channel
Where this commonly fails
  • Data quality issues
  • Whistleblower channel unused
  • Disclosures untimely
COSO-IC-IC-15
The organization communicates with external parties regarding internal control matters

The organization communicates with external parties regarding internal control matters. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Information and Communication.

Artefacts an auditor will ask for
  • Information requirements memo
  • Internal comms plan
  • External disclosure controls
  • Whistleblower channel
Where this commonly fails
  • Data quality issues
  • Whistleblower channel unused
  • Disclosures untimely
IC-13
Uses Relevant Information

The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.

Artefacts an auditor will ask for
  • Data quality controls
  • Source system documentation
  • Reporting accuracy reviews
  • EUC inventory
Where this commonly fails
  • No EUC controls
  • Data lineage unclear
IC-14
Communicates Internally

The organization internally communicates information, including objectives and responsibilities for internal control.

Artefacts an auditor will ask for
  • Internal control communication plan
  • Townhalls
  • Intranet articles
  • Whistleblower channels
Where this commonly fails
  • No documented communication cadence
IC-15
Communicates Externally

The organization communicates with external parties regarding matters affecting the functioning of internal control.

Artefacts an auditor will ask for
  • Vendor communication procedures
  • Customer communications
  • Regulatory filings
  • Investor relations records
Where this commonly fails
  • No external whistleblower channel
  • Vendor expectations unclear
P13
Uses Relevant Information

The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.

Artefacts an auditor will ask for
  • Information requirements per process
  • Data quality standards
  • System of record inventory
Where this commonly fails
  • Information sources for controls not assessed for reliability
  • End user computing tools used for key reports without controls
  • Data lineage from source to report undocumented
  • Report logic changes deployed without recertification
  • Critical reports not identified or inventoried
P14
Communicates Internally

The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.

Artefacts an auditor will ask for
  • Internal communication plan
  • Whistleblower/escalation channels policy
Where this commonly fails
  • Control responsibilities not embedded in job descriptions
  • Cross functional communication on issues delayed
  • Escalation paths to leadership unclear
  • Board reporting on internal control quality inconsistent
  • Changes to objectives not communicated to control owners
P15
Communicates Externally

The organization communicates with external parties regarding matters affecting the functioning of internal control.

Artefacts an auditor will ask for
  • External communications policy
  • Regulatory reporting calendar
  • Investor relations procedures
Where this commonly fails
  • External stakeholder feedback channels limited or unused
  • Regulatory communications not coordinated centrally
  • Customer reported issues not routed to control owners
  • Vendors not informed of expectations on internal control
  • Public commitments not aligned to operational reality

Monitoring Activities

COSO-IC-MA-16
The organization selects and performs ongoing and/or separate evaluations

The organization selects and performs ongoing and/or separate evaluations. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Monitoring Activities.

Artefacts an auditor will ask for
  • Monitoring plan
  • Internal audit reports
  • Deficiency register
  • Remediation tracker
Where this commonly fails
  • No internal audit
  • Deficiencies untracked
  • Remediation slow
COSO-IC-MA-17
The organization evaluates and communicates internal control deficiencies in a timely manner

The organization evaluates and communicates internal control deficiencies in a timely manner. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Monitoring Activities.

Artefacts an auditor will ask for
  • Monitoring plan
  • Internal audit reports
  • Deficiency register
  • Remediation tracker
Where this commonly fails
  • No internal audit
  • Deficiencies untracked
  • Remediation slow
MON-16
Conducts Ongoing and/or Separate Evaluations

The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

Artefacts an auditor will ask for
  • Internal audit plan
  • Control self-assessment results
  • Continuous monitoring dashboards
  • Management testing
Where this commonly fails
  • No CCM in place
  • Testing only annual
MON-17
Evaluates and Communicates Deficiencies

The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action.

Artefacts an auditor will ask for
  • Deficiency log
  • Remediation tracking
  • Severity assessment criteria
  • Board reports on deficiencies
Where this commonly fails
  • No severity classification
  • Remediation slow
P16
Conducts Ongoing and/or Separate Evaluations

The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether components of internal control are present and functioning.

Artefacts an auditor will ask for
  • Internal audit plan
  • Management self-assessment methodology
  • Continuous monitoring program design
Where this commonly fails
  • Continuous monitoring limited to a small subset of controls
  • Internal audit scope not refreshed against current risks
  • Self assessments lack independent validation
  • Evaluation results not consolidated for management view
  • Coverage gaps between assurance providers not identified
P17
Evaluates and Communicates Deficiencies

The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board.

Artefacts an auditor will ask for
  • Deficiency evaluation methodology (deficiency, significant deficiency, material weakness)
  • Remediation tracking policy
Where this commonly fails
  • Deficiency severity classification inconsistent
  • Issues aged beyond agreed remediation timelines
  • Root cause analysis shallow and not addressing systemic causes
  • Communication to audit committee delayed or filtered
  • No trending or thematic analysis across deficiencies

Risk Assessment

P6
Specifies Suitable Objectives

The organization specifies objectives with sufficient clarity to enable identification and assessment of risks relating to objectives.

Artefacts an auditor will ask for
  • Strategic plan
  • Operational/reporting/compliance objectives
  • Materiality thresholds
Where this commonly fails
  • Objectives not cascaded to process and control level
  • Reporting objectives not aligned to applicable frameworks
  • Compliance objectives incomplete for regulatory landscape
  • Tolerances and risk appetite not defined
  • Objectives not refreshed when strategy changes
P7
Identifies and Analyzes Risk

The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how they should be managed.

Artefacts an auditor will ask for
  • Enterprise risk assessment methodology
  • Risk register
  • Risk rating criteria (likelihood/impact)
Where this commonly fails
  • Risk universe incomplete missing emerging risks
  • Inherent versus residual risk not consistently distinguished
  • Risk likelihood and impact scales applied subjectively
  • Process owners not engaged in risk identification
  • Aggregation of risks across the entity not performed
P8
Assesses Fraud Risk

The organization considers the potential for fraud in assessing risks to the achievement of objectives, including fraudulent reporting, misappropriation, and corruption.

Artefacts an auditor will ask for
  • Fraud risk assessment
  • Anti-fraud policy
  • Whistleblower policy
Where this commonly fails
  • Fraud risk assessment not refreshed annually
  • Management override risk not specifically addressed
  • Fraud schemes considered too narrow in scope
  • Anti fraud controls not mapped to identified schemes
  • No fraud risk reporting to audit committee
P9
Identifies and Analyzes Significant Change

The organization identifies and assesses changes that could significantly impact the system of internal control.

Artefacts an auditor will ask for
  • Change management policy
  • Triggers for risk reassessment
Where this commonly fails
  • Significant change criteria undefined or interpreted inconsistently
  • Risk reassessment not triggered by organisational change
  • External changes such as regulation not monitored centrally
  • Control impact of new systems not assessed pre go live
  • Change triggered reviews not documented as evidence
RA-6
Specifies Suitable Objectives

The organization specifies objectives with sufficient clarity to enable identification and assessment of risks.

Artefacts an auditor will ask for
  • Financial reporting objectives
  • Operational objectives
  • Compliance objectives
  • Materiality thresholds
Where this commonly fails
  • Objectives too vague
  • Materiality not defined
RA-7
Risk Response

Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so identified risk is treated rather than only recorded.

Artefacts an auditor will ask for
  • Control implementation statement for RA-7 citing the system mission and inheritance from common controls
  • Risk register with likelihood, impact, and treatment owners
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
Where this commonly fails
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
RA-8
Assesses Fraud Risk

The organization considers the potential for fraud in assessing risks to the achievement of objectives.

Artefacts an auditor will ask for
  • Fraud risk assessment
  • Fraud scenarios catalog
  • Anti-fraud controls mapping
  • Whistleblower data
Where this commonly fails
  • No fraud risk assessment
  • Override risks not addressed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the COSO Internal Control - Integrated Framework (2013) framework page.