About COSO
Committee of Sponsoring Organizations of the Treadway Commission
About COSO
Committee of Sponsoring Organizations of the Treadway Commission
Introduction
COSO stands for the Committee of Sponsoring Organizations of the Treadway Commission. Formed in 1985, COSO provides widely accepted frameworks for improving organizational governance, internal control, risk management, and fraud prevention. COSO sponsored National Commission on Fraudulent Financial Reporting (non-gov bodies).
Its frameworks help organizations across industries to strengthen:
- Internal Controls
- Enterprise Risk Management (ERM)
- Fraud Risk Management

COSO was Formed in 1985 to Sponsor National Commission
Three Core Frameworks
1. Internal Control–Integrated Framework (ICIF)
- Purpose: Guide for designing and evaluating internal controls.
- First Published: 1992, updated in 2013.
- Focus: Helps ensure achievement of operations, reporting, and compliance objectives.
- Built on: 5 Components and 17 Principles (e.g., Control Environment, Risk Assessment, etc.)
2. Enterprise Risk Management (ERM) Framework
- Purpose: Integrate risk management with strategy and performance.
- First Published: 2004, updated in 2017.
- Focus: Identifying and managing risks that impact business goals.
- Built on: 5 Components (e.g., Governance & Culture, Strategy & Objective-Setting)
3. Fraud Risk Management Framework (F-RMF)
- Purpose: Help organizations prevent, detect, and respond to fraud.
- Published: 2016 (in collaboration with ACFE).
- Focus: All types of fraud — financial, corruption, asset misappropriation, etc.
- Built on: 5 Principles (e.g., Fraud Risk Governance, Risk Assessment, Monitoring)

COSO Internal Controls Integrated Framework (ICIF)
The COSO Internal Control–Integrated Framework (ICIF) was first issued in 1992 and updated in 2013 to improve alignment with modern business practices. It helps organizations design, implement, and evaluate internal controls to support achievement of:
- Operations objectives
- Reporting objectives
- Compliance objectives
The framework is built on 5 Components and 17 Principles:
- Control Environment: Sets the foundation — tone at the top, integrity, ethics, accountability.
- Risk Assessment: Identifies and analyzes internal and external risks to objectives.
- Control Activities: Implements actions and controls to address risks (e.g., approvals, authorizations).
- Information & Communication: Ensures relevant information is captured and communicated.
- Monitoring Activities: Evaluates effectiveness of controls over time and makes improvements.

COSO Enterprise Risk Management Framework (ERM)
The COSO ERM Framework, first introduced in 2004 and updated in 2017, helps organizations identify, assess, manage, and monitor risks that could impact strategic objectives. The 2017 version is titled “Enterprise Risk Management — Integrating with Strategy and Performance.” It is structured around 5 interrelated components:
Governance & Culture: Sets tone at the top, defines risk responsibilities, and promotes a risk-aware culture.
Strategy & Objective-Setting: Aligns risk with mission, vision, and business objectives.
Performance: Assesses risk impact on performance and tracks progress.
Review & Revision: Evaluates risk responses and updates ERM practices.
Information, Communication & Reporting: Ensures timely and relevant risk information is shared internally and externally.

COSO tells companies: “Here’s how you can design, implement, and assess a strong system of internal controls.”
COSO Fraud Risk Management Framework (F-RMF)
The COSO Fraud Risk Management Framework, released in 2016 in collaboration with the ACFE, helps organizations prevent, detect, and respond to fraud. It builds on COSO’s internal control and ERM principles and is structured around 5 core components:
Risk Governance: Establish tone at the top, clear roles, and fraud policies.
Risk Assessment: Identify and prioritize potential fraud risks.
Fraud Control Activities: Implement preventive and detective controls.
Fraud Investigation & Remediation: Set up protocols to investigate and address fraud.
Risk Monitoring: Continuously evaluate and improve the fraud risk program.

COSO Evolution vs SOX Connection

SOX tells companies: “You must have effective internal controls over financial reporting (ICFR).”
Key Connections Between COSO and SOX

Timelines
COSO was formed in 1985. The first framework released was the Internal Control–Integrated Framework (ICIF), initially published in 1992. It was later updated in 2013 to include 17 principles. The second framework, Enterprise Risk Management (ERM), was introduced in 2004 and revised in 2017. The third framework, the COSO Fraud Risk Management Framework (F-RMF), was published in 2016.

Other Stories
메타데이터
- post_id
- e09b2e1cfc29
- slug
- about-coso-e09b2e1cfc29
- url
- https://medium.com/@ismsguy/about-coso-e09b2e1cfc29
- canonical_url
- https://medium.com/@ismsguy/about-coso-e09b2e1cfc29
- author_url
- https://medium.com/@ismsguy
- status
- ok
- fetched_at
- 2026-06-17 16:37:43