Auditen
Home / Glossary / COSO framework

COSO framework

Also known as: Internal Control-Integrated Framework, COSO ICIF

The COSO framework is a widely accepted standard used by organizations to design, implement, and evaluate their internal control systems. It provides a structured approach to managing risk through five integrated components: control environment, risk assessment, control activities, information and communication, and monitoring. Its primary goal is to ensure the reliability of financial reporting, operational effectiveness, and legal compliance.

In practice

An auditor uses COSO as a benchmark to test whether a company's internal controls are properly designed and operating effectively. For example, they may evaluate if management has established a formal process for identifying business threats (Risk Assessment) or documented policies to prevent fraud (Control Activities).

More terms