COSO Internal Control: The 17 Principles Explained Simply
Kyle Ashcraft, CPA · 2019 CPA Exam Scores · 95 FAR · 98 BEC · 91 REG · 90 AUD
You cannot study for AUD and skip COSO. It is the framework every internal-control question on the exam is built on, and the AICPA does not just want the 17 principles memorized, it wants you to recognize how each one shows up inside a real business scenario.
This guide breaks the framework into its 5 components and 17 principles, using the CRIME mnemonic so the five components stick on exam day.
Why does COSO matter on the AUD exam?
COSO sits inside Area II of the AUD blueprint, Assessing Risk and Developing a Planned Response, and it shows up in two question formats. Multiple choice questions ask you to identify which component a specific activity belongs to, for example "hiring competent employees belongs to which component?" Simulations hand you a memo describing a company's problems and ask which COSO principle is being violated.
Want to master AUD concepts like COSO?
My free CPA 101 course walks through the exact framework I used to score a 90 on AUD, with the same mnemonic techniques used here.
How do you remember all five COSO components?
It's a CRIME not to have all five in place:
| C | Control Environment |
| R | Risk Assessment |
| I | Information and Communication |
| M | Monitoring |
| E | Existing Control Activities (the standard framework just calls this "Control Activities"; the E is a memory hook, not its official name) |
What's in the Control Environment component?
Control Environment is the foundation, the company's culture around controls. If that culture is weak, nothing built on top of it matters. It has 5 principles:
- Commitment to integrity and ethical values. Usually formalized through a code of conduct.
- Exercises oversight responsibility. The board of directors oversees the internal control process.
- Establishes structure, authority, and responsibility. Management makes job roles and reporting lines clear.
- Commitment to competence. Hiring and retaining people skilled enough to minimize errors.
- Enforces accountability. Employees feel responsible for following the rules.
Watch for "tone at the top." If senior management doesn't take controls seriously, nobody down the chain will either. It's the most frequently tested idea inside Control Environment, and it is the exam's shorthand for principle 1 and 2 failing together.
What's in the Risk Assessment component?
Management has to identify where things could go wrong before it can control for it. This component has 4 principles:
- Specifies suitable objectives. You cannot assess risk against a goal that was never defined.
- Identifies and analyzes risk. Determines how to manage risks once they're found.
- Assesses fraud risk. Looks specifically for the opportunities, pressures, and rationalizations that enable fraud.
- Identifies and analyzes significant change. Risk assessment is not a one-time event; a change in the economy, technology, or leadership means reassessing.
What's in the Control Activities component?
These are the policies on the ground that make sure management's directives actually get carried out. It has 3 principles:
- Selects and develops control activities. The actual checks and balances.
- Selects and develops general controls over technology. Increasingly central: for example, making sure accountants can't access the source code of the software they rely on.
- Deploys through policies and procedures. The manuals that tell employees exactly how to follow the controls.
What's in the Information and Communication component?
Controls only work if the people running them know about them. This component has 3 principles:
- Uses relevant information. High-quality data produces high-quality controls.
- Communicates internally. Everyone from the warehouse floor to the C-suite is working from the same information.
- Communicates externally. Engaging outside parties, like auditors or regulators, for an outside perspective.
What's in the Monitoring component?
Monitoring assesses the quality of the whole control system over time. It has 2 principles:
- Conducts ongoing and/or separate evaluations. Ongoing monitoring runs constantly; a separate evaluation, like an internal audit review every couple of months, happens periodically.
- Evaluates and communicates deficiencies. A broken control needs both a fix and a path to the people who need to know about it.
A useful way to picture monitoring in practice: establish a baseline for what "normal" looks like, identify deviations from it, implement the fix, then set the new baseline. That cycle repeats continuously.
How is Internal Control different from COSO ERM?
A common exam trap confuses Internal Control with Enterprise Risk Management. They are separate COSO frameworks with separate jobs.
| Framework | What it's for |
|---|---|
| COSO Internal Control (this guide) | Making sure the numbers are right and the assets are safe |
| COSO ERM | Strategy: helping the company hit its goals while taking the right amount of risk |
How many principles does each component have?
| Component | # of principles |
|---|---|
| Control Environment | 5 |
| Risk Assessment | 4 |
| Control Activities | 3 |
| Information and Communication | 3 |
| Monitoring | 2 |
| Total | 17 |
Ready to master COSO and the rest of AUD?
COSO is one piece of the AUD puzzle. My free CPA 101 course covers the other high-yield AUD topics with the same mnemonic-driven, practical approach used here.
Explore more CPA guides
Kyle Ashcraft, CPA scored 90 or above on every section of the CPA exam in 2019, including a 95 on FAR. He is the founder and sole instructor of Maxwell CPA Review, a complete CPA review course covering all six sections, where he creates every lecture, textbook and study outline himself.
