COSO Framework

A widely used internal control framework built on five integrated components.

AUD loves to make you match a control to its component or pick which component a described weakness belongs to. The classic tell: a question describes “tone at the top,” ethical values, or board oversight, and you must label it control environment (the foundation, not a control activity). Reconciliations, approvals, and segregation of duties are control activities; whistleblower hotlines and separate reporting lines are information and communication (Principle 14). The 2013 framework codified 17 principles mapped to the five components, and all five components plus relevant principles must be present and functioning—and operating together in an integrated manner—for internal control to be effective.

The trap is confusing the five components with the three objective categories the COSO cube tracks: operations, reporting, and compliance (the cube’s third face is entity structure). To lock the components, try CRIME—Control environment, Risk assessment, Information and communication, Monitoring, and control Existence (control activities)—or any mnemonic that keeps all five straight, since AUD rewards labeling them cold.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Auditing and Attestation (AUD)