The COSO framework of internal controls is practiced within companies around the world. The objectives of the COSO framework are closely related to its five components. For this week’s activity, please discuss these five components of the COSO framework. Be sure to include each components’ impact on each of the COSO framework objectives. What do you feel an auditor would most be concerned with during an IT audit? Lastly, discuss suggestions for integrating COSO framework compliance into a company in which you are familiar.

Your paper should meet the following requirements:

• Be approximately four to six pages in length, not including the required cover page and reference page.

• Follow APA7 guidelines. Your paper should include an introduction, a body with fully developed content, and a conclusion.

• Support your answers with the readings from the course and at least two scholarly journal articles to support your positions, claims, and observations, in addition to your textbook. The UC Library is a great place to find resources.

• Be clearly and well-written, concise, and logical, using excellent grammar and style techniques. You are being graded in part on the quality of your writing.

Running head: COSO FRAMEWORK


COSO Framework


COSO Framework

The Committee Of Sponsoring Organizations Of The Treadway commission is a joint
initiative that divides control objectives into three classes. The following are the three categories
that the COSO framework is divided into; compliance, operations and reporting. In compliance,
it mainly shows internal control goals that major on law and regulation adherence that must be
followed by the organization. Procedures such as performance goals and securing the company's
assets against theft, focusing on general business operations' efficiency. In reporting objectives,
both financial and non-financial reports should be the critical aspect. This relates to the
transparency and reliability of the company's reporting procedures.
The following are the components of the COSO framework. The first component is the
control environment. It entails the set of standards and structures that give the basis of
undertaking internal control in the organizations (Orakzai, 2014). The senior management comes
up with the tone at the top regarding internal control and the expected code of conduct.
Generally, communications about ethical behaviour with all personnel and overall values of the
company; the key aspects that help the board of management carry out its governance
The control environment has five principles relating to it. First, the institution shows a
commitment to ethical values and integrity. Secondly, the managing body sets up structures,
reporting lines, responsibilities and relevant authorities in the run for objectives. Thirdly, the
board of management shows independence from governing and enforces oversight of internal
processes' performance. The commitment to lure, retain and grow competent personnel comes
fourth. Finally, the institution holds individuals accountable for their responsibilities and actions
in the firm.



Risk assessment is the second component of the COSO framework. Risk assessment
assists the organization in identifying and analyzing the risks that the organization can be faced
with. It shows how the organization can assess risks so that the organization can determine the
barriers to objectives achievement. In this component, after the process of risk identification is
done, the risks are analyzed thoroughly. The management then selects the appropriate risk
response actions. Procedures and policies are then implemented to ensure that the responses to
the threats are carried out effectively.
Control activities are the third component in the COSO framework. The control activities
generally aid the management by ensuring that the risk mitigation measures are achieved fully.
The control activities can be a detective or preventive. The preventive or detective nature mainly
encompasses some manual or automated tasks like verification,...

