Internal Control
What is Internal Control?
A process effected by an organisation's board, management, and other personnel designed to provide reasonable assurance regarding the achievement of objectives in operations, reporting, and compliance. The COSO framework defines the standard for internal control.
Terms that appear alongside internal control
Each of these is named in at least one of the same controls as internal control. The number is how many controls name both.
- audit 12 shared controls
- governance 11 shared controls
- compliance 11 shared controls
- internal audit 9 shared controls
- control environment 7 shared controls
- corporate governance 5 shared controls
- risk appetite 4 shared controls
- policy 4 shared controls
Frameworks that govern internal control
What the standards actually require on internal control
Requirements naming internal control across 6 standards, quoted from the control text.
The organization holds individuals accountable for their internal control responsibilities. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.
COSO-IC-CE-05 · The organization holds individuals accountable for their internal control responsibilities →Identifies and assesses changes that could significantly impact the system of internal control
SOC2-CC3.4 · COSO principle 9: Identifies and assesses changes that could impact internal controls →Adequate internal control system including administrative and accounting procedures, internal control framework, and appropriate reporting arrangements (Article 46).
SII-P2-05 · Internal Control System →The entity must design, implement and embed internal controls that mitigate its operational risks in line with its risk appetite and allow it to meet its compliance obligations.
CPS230-24 · Design and Embedding of Internal Controls →Continually monitor and evaluate the control environment and effectiveness of internal controls.
MEA02 · Managed System of Internal Control →Recommendation 17 (Reliance on Third Parties): countries may permit financial institutions to RELY on third parties to perform elements of CDD (R.10 + R.11 elements (a) (b) (c)) provided that: the institution relying on the third party immediately obtains the...
FATF-R.17_18_19 · Reliance on Third Parties + Internal Controls + Higher-Risk Countries (FATF R.17, R.18, R.19) →Questions people ask about internal control
What is Internal Control?
Why is Internal Control important for compliance?
Which compliance frameworks address Internal Control?
Where can I learn more about Internal Control?
See how Internal Control applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.