Skip to content

Internal Control

What is Internal Control?

A process effected by an organisation's board, management, and other personnel designed to provide reasonable assurance regarding the achievement of objectives in operations, reporting, and compliance. The COSO framework defines the standard for internal control.

Governance

Each of these is named in at least one of the same controls as internal control. The number is how many controls name both.

What the standards actually require on internal control

Requirements naming internal control across 6 standards, quoted from the control text.

The organization holds individuals accountable for their internal control responsibilities. Control from COSO Internal Control - Integrated Framework (2013) framework, domain: Control Environment.

COSO-IC-CE-05 · The organization holds individuals accountable for their internal control responsibilities
SOC 28 controls

Identifies and assesses changes that could significantly impact the system of internal control

SOC2-CC3.4 · COSO principle 9: Identifies and assesses changes that could impact internal controls
Solvency II5 controls

Adequate internal control system including administrative and accounting procedures, internal control framework, and appropriate reporting arrangements (Article 46).

SII-P2-05 · Internal Control System

The entity must design, implement and embed internal controls that mitigate its operational risks in line with its risk appetite and allow it to meet its compliance obligations.

CPS230-24 · Design and Embedding of Internal Controls
COBIT 20192 controls

Continually monitor and evaluate the control environment and effectiveness of internal controls.

MEA02 · Managed System of Internal Control

Recommendation 17 (Reliance on Third Parties): countries may permit financial institutions to RELY on third parties to perform elements of CDD (R.10 + R.11 elements (a) (b) (c)) provided that: the institution relying on the third party immediately obtains the...

FATF-R.17_18_19 · Reliance on Third Parties + Internal Controls + Higher-Risk Countries (FATF R.17, R.18, R.19)

Questions people ask about internal control

What is Internal Control?
A process effected by an organisation's board, management, and other personnel designed to provide reasonable assurance regarding the achievement of objectives in operations, reporting, and compliance. The COSO framework defines the standard for internal control.
Why is Internal Control important for compliance?
Internal Control is a key concept in Governance. Understanding internal control helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Internal Control?
Internal Control appears in the requirement text of COSO Internal Control - Integrated Framework (2013), SOC 2, Solvency II, APRA CPS 230 Operational Risk Management, COBIT 2019. Across these standards we have identified 48 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Internal Control?
Explore our compliance framework pages to see how internal control applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Internal Control applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.