COSO Internal Control, Integrated Framework: what it asks of an approval matrix
The internal control framework most financial controllers are audited against. Principle 3 asks management to define, assign and limit authority; Principle 10 asks for control activities that address segregation of duties; Principle 12 asks for policies that are reassessed.
Quoted for every matrix.
Approval families anchored here
40COSO Internal Control, Integrated Framework: every clause cited, quoted
10 of the 17 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
COSO P2 Principle 2: Exercises oversight responsibilityThe board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control. Points of focus: Establishes oversight responsibilities; Applies relevant expertise; Operates independently; Provides oversight for the system of internal control. The board identifies and accepts its oversight responsibilities for internal control, applies relevant expertise (including through committees and advisers), operates with enough independent members to be objective in evaluations and decisions, and retains oversight of management's design, implementation and conduct of the system across the five components.
Where matrices usually fall short: Board oversight limited to the audit committee's financial reporting brief; No independent directors or no relevant expertise
Source: COSO Internal Control, Integrated Framework
COSO P3 Principle 3: Establishes structure, authority and responsibilityManagement establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives. Points of focus: Considers all structures of the entity; Establishes reporting lines; Defines, assigns and limits authority and responsibilities. Management and the board consider the entity's multiple structures (operating units, legal entities, geographies, outsourced providers) in supporting objectives, establish reporting lines that enable the flow of information across activities, and define, assign and limit authorities and responsibilities at each level, including segregation of duties.
Where matrices usually fall short: Outsourced providers outside the structure considered; Authorities defined without limits
Source: COSO Internal Control, Integrated Framework
COSO P5 Principle 5: Enforces accountabilityThe organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives. Points of focus: Enforces accountability through structures, authorities and responsibilities; Establishes performance measures, incentives and rewards; Evaluates performance measures, incentives and rewards for ongoing relevance; Considers excessive pressures; Evaluates performance and rewards or disciplines individuals. Management and the board establish mechanisms that hold individuals accountable for internal control responsibilities across the entity and through outsourced providers, establish performance measures, incentives and rewards aligned with responsibilities at all levels, evaluate those measures for ongoing relevance, consider and relieve excessive pressures that could drive undesirable behavior, and evaluate performance and reward or discipline individuals accordingly.
Where matrices usually fall short: Incentives that reward results without regard to control responsibilities; Pressure from targets never considered as a control risk
Source: COSO Internal Control, Integrated Framework
COSO P8 Principle 8: Assesses fraud riskThe organization considers the potential for fraud in assessing risks to the achievement of objectives. Points of focus: Considers various types of fraud (applicable to ICFR); Assesses incentives and pressures; Assesses opportunities; Assesses attitudes and rationalizations. The assessment of risks to objectives considers the potential for fraud in its various types (fraudulent reporting, misappropriation of assets, corruption, management override), assesses the incentives and pressures, the opportunities from control weaknesses, and the attitudes and rationalizations that could lead individuals to commit fraud.
Where matrices usually fall short: Fraud risk considered only for misappropriation; Management override never assessed
Source: COSO Internal Control, Integrated Framework
COSO P9 Principle 9: Identifies and analyzes significant changeThe organization identifies and assesses changes that could significantly impact the system of internal control. Points of focus: Assesses changes in the external environment; Assesses changes in the business model; Assesses changes in leadership. The organization identifies and assesses changes that could significantly affect the system of internal control: changes in the external environment (regulatory, economic, physical), changes in the business model (new lines, acquisitions, rapid growth, foreign operations, new technologies) and changes in leadership and their effect on attitudes to internal control.
Where matrices usually fall short: Acquisitions integrated without reassessing controls; Leadership change with no reassessment of tone
Source: COSO Internal Control, Integrated Framework
COSO P10 Principle 10: Selects and develops control activitiesThe organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels. Points of focus: Integrates with risk assessment; Considers entity-specific factors; Determines relevant business processes; Evaluates a mix of control activity types; Considers at what level activities are applied; Addresses segregation of duties. Control activities are selected and developed integrated with the risk assessment, considering entity-specific factors (environment, complexity, nature, scope), the relevant business processes, a mix of control activity types (preventive and detective, manual and automated), the level at which activities are applied, and segregation of duties where practical, with alternative controls where not.
Where matrices usually fall short: Controls not traceable to assessed risks; Segregation conflicts unmitigated
Source: COSO Internal Control, Integrated Framework
COSO P11 Principle 11: Selects and develops general controls over technologyThe organization selects and develops general control activities over technology to support the achievement of objectives. Points of focus: Determines dependency between the use of technology in business processes and technology general controls; Establishes relevant technology infrastructure control activities; Establishes relevant security management process control activities; Establishes relevant technology acquisition, development, and maintenance process control activities. Management determines the dependency between the use of technology in business processes and technology general controls, and establishes the control activities over the technology infrastructure, over security management (access to the technology by role and function), and over technology acquisition, development and maintenance, appropriate to the technology in use.
Where matrices usually fall short: Application controls relied on with no general controls over the platform; Access reviews absent
Source: COSO Internal Control, Integrated Framework
COSO P12 Principle 12: Deploys through policies and proceduresThe organization deploys control activities through policies that establish what is expected and procedures that put policies into action. Points of focus: Establishes policies and procedures to support development of management’s directives; Establishes responsibility and accountability for executing policies and procedures; Performs in a timely manner; Takes corrective action; Performs using competent personnel; Reassesses policies and procedures. Policies establish what is expected and procedures put the policies into action; management establishes responsibility and accountability for executing them in the relevant units, personnel perform control activities in a timely manner, take corrective action on the matters identified, perform the activities with competence and diligence, and management periodically reassesses the policies and procedures for continued relevance.
Where matrices usually fall short: Procedures documented but not performed on schedule; Policies never reassessed after process change
Source: COSO Internal Control, Integrated Framework
COSO P16 Principle 16: Conducts ongoing and/or separate evaluationsThe organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. Points of focus: Considers a mix of ongoing and separate evaluations; Considers rate of change; Establishes baseline understanding; Uses knowledgeable personnel; Integrates with business processes; Adjusts scope and frequency; Evaluates objectively. Management includes a balance of ongoing evaluations built into business processes and separate evaluations performed periodically, considers the rate of change in the business, establishes a baseline understanding of the system's design and current state, uses evaluators with sufficient knowledge, integrates ongoing evaluations with business processes, adjusts the scope and frequency of separate evaluations by risk, and evaluates objectively.
Where matrices usually fall short: Monitoring limited to the annual SOX test cycle; Ongoing evaluations that nobody records
Source: COSO Internal Control, Integrated Framework
COSO P17 Principle 17: Evaluates and communicates deficienciesThe organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate. Points of focus: Assesses results; Communicates deficiencies; Monitors corrective actions. Management and the board assess the results of ongoing and separate evaluations, deficiencies are communicated to the parties responsible for corrective action and to senior management and the board as appropriate, and management tracks whether deficiencies are remediated on a timely basis.
Where matrices usually fall short: Deficiencies found by monitoring not escalated; Remediation never tracked to closure
Source: COSO Internal Control, Integrated Framework