COSO framework
Also known as: Internal Control-Integrated Framework, COSO ICIF
The COSO framework is a widely accepted standard used by organizations to design, implement, and evaluate their internal control systems. It provides a structured approach to managing risk through five integrated components: control environment, risk assessment, control activities, information and communication, and monitoring. Its primary goal is to ensure the reliability of financial reporting, operational effectiveness, and legal compliance.
In practice
An auditor uses COSO as a benchmark to test whether a company's internal controls are properly designed and operating effectively. For example, they may evaluate if management has established a formal process for identifying business threats (Risk Assessment) or documented policies to prevent fraud (Control Activities).