COSO Internal Control: The 17 Principles Explained Simply

AUD

Kyle Ashcraft, CPA · 2019 CPA Exam Scores · 95 FAR · 98 BEC · 91 REG · 90 AUD

You cannot study for AUD and skip COSO. It is the framework every internal-control question on the exam is built on, and the AICPA does not just want the 17 principles memorized, it wants you to recognize how each one shows up inside a real business scenario.

This guide breaks the framework into its 5 components and 17 principles, using the CRIME mnemonic so the five components stick on exam day.

Why does COSO matter on the AUD exam?

COSO sits inside Area II of the AUD blueprint, Assessing Risk and Developing a Planned Response, and it shows up in two question formats. Multiple choice questions ask you to identify which component a specific activity belongs to, for example "hiring competent employees belongs to which component?" Simulations hand you a memo describing a company's problems and ask which COSO principle is being violated.

Want to master AUD concepts like COSO?

My free CPA 101 course walks through the exact framework I used to score a 90 on AUD, with the same mnemonic techniques used here.

Start CPA 101 free

How do you remember all five COSO components?

It's a CRIME not to have all five in place:

CControl Environment
RRisk Assessment
IInformation and Communication
MMonitoring
EExisting Control Activities (the standard framework just calls this "Control Activities"; the E is a memory hook, not its official name)

What's in the Control Environment component?

Control Environment is the foundation, the company's culture around controls. If that culture is weak, nothing built on top of it matters. It has 5 principles:

  1. Commitment to integrity and ethical values. Usually formalized through a code of conduct.
  2. Exercises oversight responsibility. The board of directors oversees the internal control process.
  3. Establishes structure, authority, and responsibility. Management makes job roles and reporting lines clear.
  4. Commitment to competence. Hiring and retaining people skilled enough to minimize errors.
  5. Enforces accountability. Employees feel responsible for following the rules.

Watch for "tone at the top." If senior management doesn't take controls seriously, nobody down the chain will either. It's the most frequently tested idea inside Control Environment, and it is the exam's shorthand for principle 1 and 2 failing together.

What's in the Risk Assessment component?

Management has to identify where things could go wrong before it can control for it. This component has 4 principles:

  1. Specifies suitable objectives. You cannot assess risk against a goal that was never defined.
  2. Identifies and analyzes risk. Determines how to manage risks once they're found.
  3. Assesses fraud risk. Looks specifically for the opportunities, pressures, and rationalizations that enable fraud.
  4. Identifies and analyzes significant change. Risk assessment is not a one-time event; a change in the economy, technology, or leadership means reassessing.

What's in the Control Activities component?

These are the policies on the ground that make sure management's directives actually get carried out. It has 3 principles:

  1. Selects and develops control activities. The actual checks and balances.
  2. Selects and develops general controls over technology. Increasingly central: for example, making sure accountants can't access the source code of the software they rely on.
  3. Deploys through policies and procedures. The manuals that tell employees exactly how to follow the controls.

What's in the Information and Communication component?

Controls only work if the people running them know about them. This component has 3 principles:

  1. Uses relevant information. High-quality data produces high-quality controls.
  2. Communicates internally. Everyone from the warehouse floor to the C-suite is working from the same information.
  3. Communicates externally. Engaging outside parties, like auditors or regulators, for an outside perspective.

What's in the Monitoring component?

Monitoring assesses the quality of the whole control system over time. It has 2 principles:

  1. Conducts ongoing and/or separate evaluations. Ongoing monitoring runs constantly; a separate evaluation, like an internal audit review every couple of months, happens periodically.
  2. Evaluates and communicates deficiencies. A broken control needs both a fix and a path to the people who need to know about it.

A useful way to picture monitoring in practice: establish a baseline for what "normal" looks like, identify deviations from it, implement the fix, then set the new baseline. That cycle repeats continuously.

How is Internal Control different from COSO ERM?

A common exam trap confuses Internal Control with Enterprise Risk Management. They are separate COSO frameworks with separate jobs.

FrameworkWhat it's for
COSO Internal Control (this guide)Making sure the numbers are right and the assets are safe
COSO ERMStrategy: helping the company hit its goals while taking the right amount of risk

How many principles does each component have?

Component# of principles
Control Environment5
Risk Assessment4
Control Activities3
Information and Communication3
Monitoring2
Total17

Ready to master COSO and the rest of AUD?

COSO is one piece of the AUD puzzle. My free CPA 101 course covers the other high-yield AUD topics with the same mnemonic-driven, practical approach used here.

Start CPA 101 free

Kyle Ashcraft, CPA scored 90 or above on every section of the CPA exam in 2019, including a 95 on FAR. He is the founder and sole instructor of Maxwell CPA Review, a complete CPA review course covering all six sections, where he creates every lecture, textbook and study outline himself.

Previous
Previous

Prevent, Detect, and Correct – Internal Controls

Next
Next

Internal Control Objectives