Framework
COSO IC 2013
COSO Internal Control – Integrated Framework (2013)
17 requirements · 16 connected unified controls
Open COSO IC 2013 in the mapRequirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
Control Environment
Risk Assessment
Control Activities
| Requirement | Unified control and mapping |
|---|---|
| P10The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels. | UC-ACCESS-15 — Design control activities over technology accessPartial Remaining requirement: principle applies across all control domains, not only access |
| P11The organization selects and develops general control activities over technology to support the achievement of objectives. | UC-ACCESS-15 — Design control activities over technology accessPartial Remaining requirement: principle applies across all technology domains, not only access |
| P12The organization deploys control activities through policies that establish what is expected and procedures that put policies into action. | UC-CONFIG-09 — Document configuration management policy, plan, and proceduresPartial Remaining requirement: COSO expects policies and procedures deploying all control activities, not only CM |
Information & Communication
| Requirement | Unified control and mapping |
|---|---|
| P13The organization obtains or generates and uses relevant, quality information to support the functioning of internal control. | UC-ASSET-02 — Inventory data and document processing activities and flowsPartial Remaining requirement: COSO expects quality information supporting all internal control components |
| P14The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control. | |
| P15The organization communicates with external parties regarding matters affecting the functioning of internal control. | UC-AUDIT-18 — Communicate with stakeholders on assurance mattersPartial Remaining requirement: entity-wide external channels (whistleblower, customers, suppliers) beyond assurance stakeholders |
Monitoring Activities
| Requirement | Unified control and mapping |
|---|---|
| P16The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. | |
| P17The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate. | UC-IR-10 — Learn from incidents and communicate corrective actionsPartial Remaining requirement: covers all internal-control deficiencies, beyond incident-derived lessons |