← Back to list

About COSO

Committee of Sponsoring Organizations of the Treadway Commission

Aakif Shaikh, CISSP, CEH, CHFI, CISA, GWAPT · 2025-04-24 00:37 · 1 claps · 3.5 min read
#coso #internal-control #enterpriserisk-management #fraud-risk-management #coso-erm
Open on Medium ↗
Wiki topics: BIZ · Business Strategy

About COSO

Committee of Sponsoring Organizations of the Treadway Commission

Introduction

COSO stands for the Committee of Sponsoring Organizations of the Treadway Commission. Formed in 1985, COSO provides widely accepted frameworks for improving organizational governance, internal control, risk management, and fraud prevention. COSO sponsored National Commission on Fraudulent Financial Reporting (non-gov bodies).

Its frameworks help organizations across industries to strengthen:

  • Internal Controls
  • Enterprise Risk Management (ERM)
  • Fraud Risk Management

COSO was Formed in 1985 to Sponsor National Commission

COSO was Formed in 1985 to Sponsor National Commission

Three Core Frameworks

1. Internal Control–Integrated Framework (ICIF)

  • Purpose: Guide for designing and evaluating internal controls.
  • First Published: 1992, updated in 2013.
  • Focus: Helps ensure achievement of operations, reporting, and compliance objectives.
  • Built on: 5 Components and 17 Principles (e.g., Control Environment, Risk Assessment, etc.)

2. Enterprise Risk Management (ERM) Framework

  • Purpose: Integrate risk management with strategy and performance.
  • First Published: 2004, updated in 2017.
  • Focus: Identifying and managing risks that impact business goals.
  • Built on: 5 Components (e.g., Governance & Culture, Strategy & Objective-Setting)

3. Fraud Risk Management Framework (F-RMF)

  • Purpose: Help organizations prevent, detect, and respond to fraud.
  • Published: 2016 (in collaboration with ACFE).
  • Focus: All types of fraud — financial, corruption, asset misappropriation, etc.
  • Built on: 5 Principles (e.g., Fraud Risk Governance, Risk Assessment, Monitoring)

COSO Internal Controls Integrated Framework (ICIF)

The COSO Internal Control–Integrated Framework (ICIF) was first issued in 1992 and updated in 2013 to improve alignment with modern business practices. It helps organizations design, implement, and evaluate internal controls to support achievement of:

  • Operations objectives
  • Reporting objectives
  • Compliance objectives

The framework is built on 5 Components and 17 Principles:

  1. Control Environment: Sets the foundation — tone at the top, integrity, ethics, accountability.
  2. Risk Assessment: Identifies and analyzes internal and external risks to objectives.
  3. Control Activities: Implements actions and controls to address risks (e.g., approvals, authorizations).
  4. Information & Communication: Ensures relevant information is captured and communicated.
  5. Monitoring Activities: Evaluates effectiveness of controls over time and makes improvements.

COSO Enterprise Risk Management Framework (ERM)

The COSO ERM Framework, first introduced in 2004 and updated in 2017, helps organizations identify, assess, manage, and monitor risks that could impact strategic objectives. The 2017 version is titled “Enterprise Risk Management — Integrating with Strategy and Performance.” It is structured around 5 interrelated components:

Governance & Culture: Sets tone at the top, defines risk responsibilities, and promotes a risk-aware culture.

Strategy & Objective-Setting: Aligns risk with mission, vision, and business objectives.

Performance: Assesses risk impact on performance and tracks progress.

Review & Revision: Evaluates risk responses and updates ERM practices.

Information, Communication & Reporting: Ensures timely and relevant risk information is shared internally and externally.

COSO tells companies: “Here’s how you can design, implement, and assess a strong system of internal controls.”

COSO Fraud Risk Management Framework (F-RMF)

The COSO Fraud Risk Management Framework, released in 2016 in collaboration with the ACFE, helps organizations prevent, detect, and respond to fraud. It builds on COSO’s internal control and ERM principles and is structured around 5 core components:

Risk Governance: Establish tone at the top, clear roles, and fraud policies.

Risk Assessment: Identify and prioritize potential fraud risks.

Fraud Control Activities: Implement preventive and detective controls.

Fraud Investigation & Remediation: Set up protocols to investigate and address fraud.

Risk Monitoring: Continuously evaluate and improve the fraud risk program.

COSO Evolution vs SOX Connection

SOX tells companies: “You must have effective internal controls over financial reporting (ICFR).”

Key Connections Between COSO and SOX

Timelines

COSO was formed in 1985. The first framework released was the Internal Control–Integrated Framework (ICIF), initially published in 1992. It was later updated in 2013 to include 17 principles. The second framework, Enterprise Risk Management (ERM), was introduced in 2004 and revised in 2017. The third framework, the COSO Fraud Risk Management Framework (F-RMF), was published in 2016.

Other Stories


메타데이터
post_id
e09b2e1cfc29
slug
about-coso-e09b2e1cfc29
url
https://medium.com/@ismsguy/about-coso-e09b2e1cfc29
canonical_url
https://medium.com/@ismsguy/about-coso-e09b2e1cfc29
author_url
https://medium.com/@ismsguy
status
ok
fetched_at
2026-06-17 16:37:43