,

COSO’s 17 Principles: The Complete List, What Each Requires, and How to Evaluate Them

COSO’s 2013 Internal Control, Integrated Framework says that internal control has five components, that the five components rest on seventeen principles, and that a system of internal control is effective only when all seventeen are present and functioning and the five components operate together. Every SOX assessment in the United States, most internal control frameworks elsewhere, and a large share of internal audit methodology are built on that sentence, and most auditors can name the five components and fewer than half of the principles. This guide lists all seventeen, explains what each requires and what it looks like when it is missing, shows how to evaluate them (present, functioning, operating together), maps them to the entity-level controls a SOX program tests, and works through a bank’s principle-by-principle assessment.

Two facts of context. The 2013 framework replaced COSO’s original 1992 framework, whose five components it kept while making the seventeen principles explicit; COSO’s transition guidance treated the 1992 version as superseded after 15 December 2014. And the framework’s authors attached to each principle a set of points of focus, characteristics that a principle typically exhibits, which are not requirements but are the best available checklist for evaluating one; the framework lists several per principle, more than seventy in all. Companion guides on this site cover what a control is, the internal controls primer, and the preventive, detective and corrective controls guide; this one is about the principles.

This guide was rewritten in September 2026 from a shorter version published on 1 September 2026. Principle titles follow the COSO 2013 framework; descriptions, evidence and deficiency notes are practitioner paraphrase, not COSO text.

In this guide

The framework in one view: five components, seventeen principles

The five components are the layers of the system; the principles are what each layer has to do. Control Environment sets the tone and the structure; Risk Assessment decides what could go wrong; Control Activities are the actions that address it; Information and Communication carry what everyone needs to know; Monitoring Activities check that the rest is working. The table is the whole framework on one screen, with the question each principle asks of an organisation and the kind of evidence that answers it.

ComponentPrincipleThe question it asksEvidence that answers it
Control Environment1. Demonstrates commitment to integrity and ethical valuesDoes leadership set and live a standard of conduct, and is it enforced?Code of conduct; tone-at-the-top communications; attestation and training; ethics hotline data and case outcomes; disciplinary consistency
Control Environment2. Exercises oversight responsibilityIs the board independent of management and does it actually oversee the system of internal control?Board and committee charters; independence assessments; committee minutes showing challenge; skills matrix
Control Environment3. Establishes structure, authority and responsibilityAre reporting lines, authorities and responsibilities defined so that objectives can be achieved?Organisation charts; delegation of authority; job descriptions; entity and legal structure documentation
Control Environment4. Demonstrates commitment to competenceDoes the organisation attract, develop and retain people who can do the job?Competency requirements; hiring and evaluation processes; training; succession plans for key roles
Control Environment5. Enforces accountabilityAre people held accountable for internal control responsibilities, with incentives that do not undermine them?Performance measures tied to control responsibilities; incentive plan review for pressure; consequences applied
Risk Assessment6. Specifies suitable objectivesAre objectives clear enough that risks to them can be identified?Strategic, operating, reporting and compliance objectives documented; materiality and tolerances set; alignment to reporting frameworks
Risk Assessment7. Identifies and analyses riskAre risks to objectives identified across the entity and analysed as a basis for managing them?Risk assessment process and outputs; entity-level and process-level risk registers; risk ratings and responses
Risk Assessment8. Assesses fraud riskDoes the risk assessment consider fraud, including management override, incentives and pressures?Fraud risk assessment by scheme and by account; anti-fraud controls mapped; override controls
Risk Assessment9. Identifies and analyses significant changeDoes the organisation identify changes (external, business model, leadership) that could affect the system?Change identification in the risk process; assessments after acquisitions, system changes, new leadership
Control Activities10. Selects and develops control activitiesAre control activities chosen to mitigate the risks identified, at the right levels, with segregation of duties considered?Risk and control matrices; control design documentation; segregation analysis
Control Activities11. Selects and develops general controls over technologyAre IT general controls in place over the technology the other controls depend on?ITGC program: access, change, operations; dependency mapping from application controls to ITGCs
Control Activities12. Deploys through policies and proceduresAre control activities written into policies and procedures, performed by competent people, and reviewed and corrected?Policies and procedures; evidence of timely performance and of corrective action; periodic reassessment
Information and Communication13. Uses relevant informationDoes the organisation obtain, generate and use quality information to support internal control?Information requirements; data sources and their controls; report inventories; completeness and accuracy controls over information
Information and Communication14. Communicates internallyDoes information about internal control, including responsibilities, flow inside the organisation, including to the board and through separate lines such as a hotline?Internal communication channels; board reporting; whistleblower channel; policy communication evidence
Information and Communication15. Communicates externallyDoes the organisation communicate with external parties about internal control and receive their input?External reporting; communication with regulators, auditors, customers, suppliers; inbound channel for external concerns
Monitoring Activities16. Conducts ongoing and separate evaluationsIs the system monitored through ongoing activities, separate evaluations, or both, by people with the knowledge to do it?Management monitoring; internal audit; other assurance; scope and frequency tied to risk
Monitoring Activities17. Evaluates and communicates deficienciesAre deficiencies evaluated and communicated to the people who can fix them, and to the board where appropriate, and are they tracked to closure?Deficiency evaluation process; reporting to management and the board; remediation tracking

Control Environment: Principles 1 to 5

The control environment is the component auditors find hardest to test and boards find easiest to assume, which is why it fails quietly. Its five principles describe an organisation in which leaders set a standard and enforce it (1), an independent board oversees the system rather than receiving reports about it (2), authority and responsibility are defined so that nobody can say the control was someone else’s job (3), the people in control roles are competent to perform them (4), and performance and incentives hold people accountable for control without pushing them to override it (5). The evidence is real but indirect: how consistently misconduct is dealt with, whether the board’s minutes show challenge, whether the delegation of authority matches the organisation chart, whether the people signing off on controls were ever trained to, and whether the bonus plan rewards the numbers a control is meant to protect.

The deficiencies that reach the material weakness category most often start here. Management override, the fraud pattern behind most financial reporting failures, is a Principle 1 and Principle 5 failure before it is a Principle 8 failure: the override happens because the tone permitted it and the incentives rewarded it. A board that approves without questioning is a Principle 2 deficiency that no process-level control can compensate for, which is why external auditors weight the principle so heavily in entity-level control evaluation. And competence (Principle 4) is where control operating failures are born: a review performed by someone who cannot recognise the error is a control that operates without functioning, and the test of design vs operating effectiveness guide explains why that matters for how the control is tested.

Risk Assessment: Principles 6 to 9

Risk assessment in the framework is not the enterprise risk process; it is the specific discipline of stating objectives clearly enough that risks to them can be identified (6), identifying and analysing those risks (7), considering fraud explicitly (8), and noticing when something has changed enough to make the last assessment wrong (9). Principle 6 is the one most organisations skip, because it seems obvious that they have objectives; the framework’s point is that a financial reporting objective has to be specified down to materiality, the applicable framework and the assertions before the risks of misstatement can be assessed, and an operations objective has to be specified with tolerances before anyone can say a control keeps it within them. The internal audit risk assessment guide shows the process-level version; Principle 7 is that process applied entity-wide.

Principle 8, the fraud risk assessment, is the one that produced the most findings when the 2013 framework was first adopted and still does: many organisations had a fraud policy and no assessment of the schemes that could actually occur, by account, by process and by the people with the access and incentive to commit them. A conformant fraud risk assessment identifies incentives and pressures, opportunities (including management override) and attitudes, maps the anti-fraud controls to each significant scheme, and is refreshed when the business changes; the fraud red flags list lists the schemes and indicators to consider. Principle 9 closes the component with the requirement that the organisation actually looks for change: acquisitions, new systems, new products, new leadership, and external shifts, each of which can leave last year’s assessment describing a business that no longer exists.

Control Activities: Principles 10 to 12

Control activities are the component everyone means when they say internal control, and the framework spends three principles on them. Principle 10 requires that control activities be selected and developed to mitigate the risks identified, at the right level of the organisation, with a mix of types (preventive and detective, manual and automated), with segregation of duties built in where the risk warrants it and alternatives where segregation is impractical. Principle 11 singles out general controls over technology, because every automated control and every IT-dependent manual control rests on the access, change and operations controls over the systems that produce them; the ITGC vs application controls guide explains the dependency and the SOX ITGC scoping guide how to scope it. Principle 12 is about deployment: control activities written into policies and procedures, performed by competent people at the right time, with exceptions investigated and corrected, and reassessed periodically for continued relevance.

Principle 12 is where most process-level deficiencies are classified, and where the difference between a design and an operating deficiency becomes a principle question: a control that was selected (10) but never written into a procedure (12) fails Principle 12 at the design stage; a control written into the procedure and skipped fails it at the operating stage. Auditors mapping process findings to the framework should resist the temptation to file everything under Principle 10; the framework distinguishes choosing controls from deploying them because organisations fail at both in different ways.

Information and Communication: Principles 13 to 15

Principle 13 is the framework’s answer to a question auditors ask in every process: can the information the controls rely on be trusted? It requires the organisation to identify what information internal control needs, to obtain it from reliable internal and external sources, to process it into something usable, and to maintain its quality; in practice that is the report inventory, the data sources behind it and the completeness and accuracy controls over each, which the IPE testing guide covers as a testing discipline. Principle 14 requires internal communication of internal control objectives and responsibilities, including to the board and including a channel that bypasses normal reporting lines when those lines are the problem, which is the whistleblower or ethics hotline requirement in framework form. Principle 15 is the external counterpart: communicating relevant information to external parties (shareholders, regulators, customers, suppliers, external auditors) and receiving what they send back, including complaints and allegations.

Monitoring Activities: Principles 16 and 17

Monitoring is the component that makes the framework a system rather than a snapshot. Principle 16 requires ongoing evaluations (built into business processes, performed by management as part of running them), separate evaluations (internal audit, external assurance, self-assessment programmes), or a mix, with the scope and frequency of separate evaluations set by risk and the evaluators competent to judge what they see. Principle 17 requires that the deficiencies monitoring finds are evaluated for severity, communicated to the parties responsible for corrective action and, where appropriate, to senior management and the board, and tracked until they are corrected. Internal audit is a separate evaluation under Principle 16 and a source of deficiencies under Principle 17, and the function’s own follow-up process (Standard 15.2 in the Global Internal Audit Standards, the issue validation guide in practice) is part of the organisation’s conformance with the principle. A function that finds deficiencies and does not confirm their correction has left Principle 17 half done.

Evaluating the seventeen: present, functioning, operating together

The framework’s test for an effective system has three parts, and evaluators have to apply all three. Each of the five components and each of the seventeen principles must be present, meaning it exists in the design and implementation of the system, and functioning, meaning it continues to operate. And the five components must operate together in an integrated manner, meaning the evaluator has to consider how a weakness in one component affects the others rather than scoring each in isolation. A principle that is not present or not functioning is, in the framework’s terms, a major deficiency, and a system with a major deficiency in any principle cannot be concluded effective, whatever the other sixteen look like. For SOX purposes the evaluation of severity then runs through the deficiency framework in AS 2201, which the control deficiency evaluation guide sets out, and a major deficiency at the principle level is usually a significant deficiency or a material weakness at the ICFR level.

Evaluation questionWhat it meansHow to evidence itWhat a failure looks like
Is the principle present?It exists in the design and implementation of the system: the policies, structures and controls that embody it are in placeMap each principle to the controls, documents and structures that embody it; walk through themNo fraud risk assessment exists (Principle 8 not present); no whistleblower channel (Principle 14 not present)
Is the principle functioning?It continues to operate: the embodying controls run, and the points of focus are observable in practiceTest the operating effectiveness of the embodying controls over the periodThe board oversight committee exists and met once (Principle 2 present, not functioning); the code of conduct exists and violations go unaddressed (Principle 1)
Do the components operate together?Weaknesses in one component do not undermine the others, and the components are integrated rather than parallelAnalyse cross-component effects: for each deficiency, ask which other principles it impairsStrong control activities undermined by an incentive plan that rewards override; monitoring that never reaches the board
Is any deficiency a major deficiency?A deficiency that makes a component or principle not present or not functioning, or that means the components do not operate togetherAggregate deficiencies by principle; judge severity against the principle’s purposeSeveral individually minor gaps in Principle 12 that together mean policies are not deployed

Mapping the principles to entity-level controls in a SOX program

Under SOX 404, management uses the framework as the criteria for its assessment of internal control over financial reporting, and the external auditor evaluates entity-level controls against it under AS 2201, whose paragraphs 22 to 24 explain how entity-level controls of different precision bear on the assessment. The practical mechanism is a principle mapping: each of the seventeen principles is mapped to the entity-level controls that embody it for financial reporting purposes, each control is tested, and the results are rolled up to a conclusion per principle. The table shows a typical mapping; the counts vary with the organisation, and the SOX scoping guide shows where entity-level controls sit in the scoping.

PrincipleTypical entity-level controls that embody it (financial reporting focus)PrecisionUsual test
1. Integrity and ethical valuesCode of conduct and annual attestation; ethics hotline operation and case handling; consistent disciplinary actionIndirectInspection of attestations and case logs; inquiry; review of a sample of cases for consistent treatment
2. Oversight responsibilityAudit committee charter, independence and financial expertise; committee review of financial statements, judgments and control deficiencies; private sessions with auditorsIndirect to directMinutes and materials; committee self-assessment; inquiry of members
3. Structure, authority, responsibilityDelegation of authority matrix; organisation structure; financial reporting roles and reporting linesIndirectInspection; comparison of delegations to system authorisation limits
4. CompetenceFinance hiring and performance criteria; accounting technical training; succession for controller and key rolesIndirectInspection of criteria and records; inquiry
5. AccountabilityPerformance objectives including control responsibilities; compensation committee review of incentive plans for financial reporting pressureIndirectInspection; review of incentive metrics against override risk
6. Suitable objectivesFinancial reporting objectives, materiality and applicable framework documented; scoping memoDirect for scopingInspection of the scoping documentation
7. Risk identification and analysisFinancial reporting risk assessment by account and assertion; what-could-go-wrong analysis in the control matricesDirectInspection; reperformance of the risk assessment for a sample of accounts
8. Fraud riskFraud risk assessment by scheme; management override controls (journal entry review, estimates review, unusual transactions)DirectInspection of the assessment; testing of override controls as key controls
9. Significant changeChange identification in the quarterly risk refresh; assessment of acquisitions, system implementations and new standardsDirectInspection; testing that changes triggered reassessment
10. Control activitiesThe process-level control matrices themselves; segregation of duties frameworkDirect via process controlsProcess-level testing; segregation analysis
11. General controls over technologyThe ITGC program over in-scope systemsDirect via ITGCsITGC testing; dependency mapping
12. Policies and proceduresAccounting policies and procedures manual; close calendar and checklist; policy review cycleDirectInspection; testing of the close checklist
13. Relevant informationReport inventory; controls over information produced by the entity; data governance over financial dataDirectIPE testing; inspection of the inventory
14. Internal communicationCommunication of accounting policies and control responsibilities; whistleblower channel to the audit committee; sub-certification processIndirect to directInspection; testing of the sub-certification cascade
15. External communicationDisclosure committee; external auditor communications; regulator correspondence handlingDirect for disclosureInspection of disclosure committee records
16. Ongoing and separate evaluationsManagement’s monitoring of controls; internal audit’s SOX testing; self-assessment programDirectInspection of monitoring results; evaluation of internal audit’s competence and objectivity
17. Deficiency evaluation and communicationDeficiency evaluation process and log; reporting to the audit committee; remediation trackingDirectInspection; testing that deficiencies were evaluated and reported on time

Using the seventeen outside SOX: the principles as audit criteria

The framework was written for three categories of objective, operations, reporting and compliance, and its principles apply to all three; SOX uses one slice of the reporting category. For an internal auditor the seventeen are therefore a ready-made criteria set for any engagement whose subject is a system of control rather than a single process: an audit of a subsidiary’s control environment, of a new business line’s readiness, of a compliance program, or of a function’s governance. Standard 13.4 of the Global Internal Audit Standards requires evaluation criteria for every engagement, and the principles are among the most defensible criteria available because management and the board already recognise them. The table shows how the same principles read in each objective category, with the kind of engagement that would use them.

Objective categoryHow the principles readEngagement that uses themPrinciples that carry most weight
OperationsObjectives stated with tolerances (6); risks to them identified (7); controls selected and deployed to keep operations within tolerance (10, 12); monitoring built into the process (16)Audit of a plant, a depot network, a claims operation, a new product launch6, 7, 10, 12, 16
Reporting (financial and non-financial, external and internal)Reporting objectives tied to the applicable framework and materiality (6); fraud and override considered (8); information quality controlled (13); disclosure communicated (15)SOX, sustainability reporting under COSO’s 2023 supplemental guidance, management reporting integrity6, 8, 11, 13, 15, 17
ComplianceObligations identified as objectives (6); compliance risks assessed (7); controls deployed through policies (12); channels for reporting concerns (14); deficiencies escalated (17)Compliance program audit, regulatory readiness, ethics program review1, 5, 7, 12, 14, 17
Entity-wide (all categories)All seventeen, with the operating-together test applied across categoriesGovernance audit; assessment of a subsidiary or acquisition; the annual entity-level control assessment1, 2, 3, 5, 9, 16

One caution for functions adopting the principles as criteria: state them as criteria in the planning memo and agree them with management before fieldwork, as Standard 13.4 expects, because a finding that a business line “does not meet COSO Principle 9” lands very differently when management knew the principles were the yardstick from the start.

The principle mapping worksheet: a template

COSO principle mapping and evaluation worksheet

Header: Entity or reporting unit | Objective category (financial reporting / operations / compliance / all) | Period | Framework version: COSO 2013 | Prepared, reviewed, dates.

One row per principle (17): Component | Principle number and title | Points of focus considered (list or reference) | Controls, documents and structures that embody the principle (references) | Present? (yes / no, with basis) | Functioning? (yes / no, with test references and results) | Deficiencies identified (references) | Cross-component effects (which other principles a deficiency impairs) | Conclusion (present and functioning / deficiency / major deficiency).

Component summary (5 rows): Component | Principles present and functioning (count of 17) | Deficiencies | Operating together assessment | Conclusion.

Overall: Any major deficiency? | Components operate together? | Overall conclusion on the system of internal control for the objective category | Reported to (management, audit committee) on (date).

Common mistakes

MistakeWhy it mattersThe fix
Treating the points of focus as requirementsOrganisations write controls for every point of focus and lose sight of the principle; the points are characteristics, not a checklistEvaluate the principle; use the points to guide judgment and explain a conclusion
Mapping every finding to Principle 10The framework distinguishes selecting controls (10), technology controls (11) and deploying them (12); mis-mapping hides where the system actually failsAsk whether the control was never chosen, never written down, or not performed
Scoring principles in isolationThe operating-together requirement is ignored; a tone or incentive problem is scored as one principle when it undermines fiveAdd the cross-component column; aggregate before concluding
Assuming Principle 8 is met by a fraud policyA policy is not an assessment; the principle requires identified schemes, override consideration and mapped controlsPerform and document a fraud risk assessment by scheme and account
Evaluating presence and not functioningDocuments prove existence; only operating tests prove functioningTest the embodying controls over the period, not at a date
Using the framework only for SOXThe framework covers operations and compliance objectives; functions that apply it only to financial reporting miss its use as audit criteria elsewhereUse the principles as criteria in operational and compliance engagements (Standard 13.4)
Confusing COSO’s internal control framework with its ERM frameworkDifferent documents (2013 and 2017), different purposes; the ERM framework has twenty principles of its ownCite the right framework; the risk management frameworks comparison compares them

Worked example: a bank’s principle-by-principle assessment

Lakeshore Bancorp, the nine-billion-dollar public regional bank used as the running example across this site’s SOX guides, assesses its entity-level controls against the seventeen principles every year as part of its 404 program, with a materiality of 6.5 million dollars and 212 key controls at the process level. The FY26 assessment mapped the principles to 41 entity-level controls, tested them over the year, and produced the results in the table. It is a normal outcome for a well-run program: most principles present and functioning, a few observations, and one principle whose evidence needed strengthening before the auditors would accept the conclusion.

ComponentPrinciples present and functioningObservationsWhat changed
Control Environment (1 to 5)5 of 5Principle 5: the incentive plan for the mortgage subsidiary rewarded origination volume with no offsetting quality measure; the compensation committee’s review did not document consideration of reporting pressureCompensation committee review documented against Principle 5; a credit-quality clawback added to the plan for FY27
Risk Assessment (6 to 9)4 of 4, with one principle requiring additional evidencePrinciple 8: the fraud risk assessment had not been refreshed for the digital channels business, whose 1,340 annual deployments and 14-engineer team created override opportunities the assessment did not name; Principle 9 had identified the change but Principle 8 had not acted on itFraud risk assessment extended to the digital channels schemes before year end; the deployment-log reconciliation control (see the SDLC and DevOps pipeline audit guide) added to the anti-fraud control mapping
Control Activities (10 to 12)3 of 3Principle 11: the deferred-fee spreadsheet error found in the year-end deficiency evaluation (see the control deficiency evaluation guide) traced to an end-user computing tool outside the ITGC programThe 212-item EUC inventory and Tier 1 control set described in the end-user computing audit guide; the workbook retired into the loan module
Information and Communication (13 to 15)3 of 3Principle 13: the report inventory grew from 31 to 74 reports during the year as IPE testing found reports the controls relied on that nobody had listedInventory maintained by the SOX team with quarterly reconciliation to the control matrices
Monitoring Activities (16 and 17)2 of 2Principle 17: two of the five year-end deficiencies had been known to process owners for two quarters before reaching the deficiency logQuarterly deficiency attestation added to the sub-certification cascade

The overall conclusion was that all seventeen principles were present and functioning and the components operated together, which supported management’s effective conclusion on ICFR alongside the three significant deficiencies at the process level that the year-end evaluation had already reported. The assessment’s value was less in the conclusion than in the four observations, each of which pointed at a place where the system was drifting: incentives, an unrefreshed fraud assessment, an ungoverned spreadsheet, and deficiencies that took two quarters to surface. Those are the framework’s early warnings, and a principle-by-principle assessment done properly is the only place they appear together.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading