
COSO has a forbidding reputation because it lives in audit reports and gets described in language designed to survive a lawsuit. Underneath, it is one of the most sensible things in the whole field: a plain account of the five ingredients a control system needs to actually work. The framework, from the Committee of Sponsoring Organizations, is the global reference for internal control, and you can use it without ever reading the standard, because the five parts are just common sense with names.1
The five parts, in plain words
Control environment is the culture and the tone: do people here take controls seriously, or route around them? This comes first because if the environment is rotten, nothing else survives. Risk assessment is naming what could actually go wrong, so you control the real risks rather than the convenient ones. Control activities are the actual controls: the approvals, checks, separations of duty that stop the bad thing. Information and communication is whether the right people get the right information in time to act. And monitoring is someone actually watching that the controls keep working, rather than assuming they do.
The one everyone underrates: the environment
People love to jump to control activities, the approvals and checklists, because they feel concrete. But COSO puts the control environment first for a reason. A brilliant set of controls in a culture that treats them as obstacles will be quietly defeated, worked around and ignored. A modest set of controls in a culture that takes them seriously will hold. The environment is the soil. You can plant the best controls in the world, and if the soil is bad they will not grow. Most control failures trace back here, not to a missing checklist.
The solution, as a five-component check
Test any control system against the five
| Component | The plain question |
|---|---|
| Control environment | Do people here actually take controls seriously? |
| Risk assessment | Have we named what could really go wrong, honestly? |
| Control activities | Is there a real control against each real risk? |
| Information | Do the right people get the right facts in time to act? |
| Monitoring | Is anyone actually watching that the controls still work? |
A "no" on any row is a leak. Most real failures are a "no" on the first or the last.
Why monitoring is the other weak spot
If the environment is the most underrated component, monitoring is the most neglected. Organisations design controls and then assume they keep working, sometimes for years, until an incident reveals that a control quietly stopped functioning long ago. A control you do not monitor is a control you are hoping about. COSO's fifth component is just the discipline of checking, on a schedule, that the things you rely on are still doing their job. It is unglamorous and it is where the surprises hide.
Questions to run your controls through
- Do people here take our controls seriously, or work around them?
- Have we honestly named what could go wrong, or just the obvious risks?
- Is there a real control against each real risk, not just a policy?
- Do decision-makers get the right information in time to act on it?
- When did we last check that our key controls actually still work?
You do not need to be an accountant to use COSO, and you certainly do not need to read it in the original. You need to remember that a control only works if it sits in a culture that respects it, targets a risk you actually named, is a real check rather than a policy, feeds the right people in time, and is watched to make sure it keeps working. Five components, five plain questions. Answer them honestly about your biggest risk and you will usually find the leak before it finds you.
Notes and sources
From the book
Key Compliance ModelsFifty-eight models of governance, risk and compliance, each explained in plain language and anchored to a real, sourced case.
