top of page

Search Results

44 results found with an empty search

  • Healthcare Providers | COSO

    Guidance for Healthcare Providers Guidance for Healthcare Providers Amid heightened scrutiny and ever-increasing complexities in operations and regulation, healthcare organizations face unique challenges related to the design and operation of internal controls. In response, the Committee of Sponsoring Organizations of the Treadway Commission (COSO), in collaboration with Crowe LLP and CommonSpirit Health, has published new guidance: “2013 COSO Integrated Framework: An Implementation Guide for the Healthcare Provider Industry.” Healthcare organizations experience issues with system access and integrity, clinical documentation, coding, and billing, all of which may result in potential noncompliance with federal and state regulations – and costly mistakes. The guide introduces healthcare organizations to COSO’s widely used “Internal Control – Integrated Framework,” and provides a roadmap to implementation to help strengthen their overall governance and internal control structures. PDF File Press Release

  • Governance | COSO

    Governance Other Guidance Documents Corporate Governance: Guiding Principles for Board Oversight (2026) See More Improving Organizational Performance and Governance (2014) See More Enhancing Board Oversight (2012) See More

  • Enterprise Risk Management | COSO

    Guidance Enterprise Risk Management In keeping with its overall mission, the COSO Board commissioned and published in 2004 Enterprise Risk Management—Integrated Framework. Over the past decade, that publication has gained broad acceptance by organizations in their efforts to manage risk. However, also through that period, the complexity of risk has changed, new risks have emerged, and both boards and executives have enhanced their awareness and oversight of enterprise risk management while asking for improved risk reporting. The updated 2017 publication (see below) addresses the evolution of enterprise risk management and the need for organizations to improve their approach to managing risk to meet the demands of an evolving business environment. Certification Free - Executive Summary Purchase eBook Purchase eBook Purchase Softcover ERM Guidance Documents FROM GUIDANCE TO ACTION: EXPLORING PRACTICAL ERM (2026) See More (JAPANESE) ENTERPRISE RISK MANAGEMENT FOR CLOUD COMPUTING (2021) See More (JAPANESE) COMPLIANCE RISK MANAGEMENT: APPLYING THE COSO ERM FRAMEWORK (2020) See More (JAPANESE) MANAGING CYBER RISK IN A DIGITAL AGE (2019) See More (SPANISH) ENTERPRISE RISK MANAGEMENT TO ENVIRONMENTAL, SOCIAL AND GOVERNANCE-RELATED RISK (2018) See More ENHANCING BOARD OVERSIGHT (2012) See More PRACTICAL APPROACHES FOR GETTING STARTED (2011) See More ALTERNATIVE DATA: THE COSO PERSPECTIVE (2024) See More REALIZE THE FULL POTENTIAL OF ARTIFICIAL INTELLIGENCE (2021) See More RISK APPETITECRITICAL TO SUCCESS (2020) See More MANAGING CYBER RISK IN A DIGITAL AGE (2019) See More (FULL) ENTERPRISE RISK MANAGEMENT TO ENVIRONMENTAL, SOCIAL AND GOVERNANCE-RELATED RISK (2018) See More RISK ASSESSMENT IN PRACTICE (2012) See More BOARD RISK OVERSIGHT - A PROGRESSS REPORT (2010) See More ENABLING ORGANIZATIONAL AGILITY IN AN AGE OF SPEED AND DISRUPTION (2022) See More (PORTUGUESE) REALIZE THE FULL POTENTIAL OF ARTIFICIAL INTELLIGENCE (2021) See More COMPLIANCE RISK MANAGEMENT: APPLYING THE COSO ERM FRAMEWORK (2020) See More (SUMMARY) ENTERPRISE RISK MANAGEMENT TO ENVIRONMENTAL, SOCIAL AND GOVERNANCE-RELATED RISK (2018) See More COSO IN THE CYBER AGE (2015) See More CLOUD COMPUTING THOUGHT PAPER (2012) See More DEVELOPING KEY RISK INDICATORS TO STRENGTHEN ENTERPRISE RISK MANAGEMENT (2010) See More ENTERPRISE RISK MANAGEMENT FOR CLOUD COMPUTING (2021) See More (JAPANESE) REALIZE THE FULL POTENTIAL OF ARTIFICIAL INTELLIGENCE (2021) See More CREATING AND PROTECTING VALUE (2020) See More (PORTUGUESE) ENTERPRISE RISK MANAGEMENT TO ENVIRONMENTAL, SOCIAL AND GOVERNANCE-RELATED (2018) See More DEMYSTIFYING SUSTAINABILITY RISK (2013) See More UNDERSTANDING AND COMMUNICATING RISK APPETITE (2012) See More EFFECTIVE ENTERPRISE RISK OVERSIGHT - THE ROLE OF THE BOARD OF DIRECTORS (2009) See More Integrating with Strategy and Performance: Compendium of Examples COSO issued a supplement with detailed examples for applying principles from the ERM Framework to day-to-day practices. This supplement, titled COSO Enterprise Risk Management - Integrating with Strategy and Performance: Compendium of Examples, was developed from industry practices identified through extensive research conducted when updating the Framework. Each example focuses on specific components covered in the Framework. Written as a collection of case studies, the Compendium offers real-world advice about how to put the ERM Framework to use. Each case describes how a specific entity scaled and adapted the principles, and sets out a relationship between an organization’s mission, vision, and core values; its strategic goals and directions; and approaches used in carrying out its strategy. Compendium of Examples COSO issued a supplement with detailed examples for applying principles from the ERM Framework to day-to-day practices. This supplement, titled COSO Enterprise Risk Management - Integrating with Strategy and Performance: Compendium of Examples, was developed from industry practices identified through extensive research conducted when updating the Framework. Each example focuses on specific components covered in the Framework. Written as a collection of case studies, the Compendium offers real-world advice about how to put the ERM Framework to use. Each case describes how a specific entity scaled and adapted the principles, and sets out a relationship between an organization’s mission, vision, and core values; its strategic goals and directions; and approaches used in carrying out its strategy.

  • Enterprise Risk Management | COSO

    Enterprise Risk Management Integrating with Strategy and Performance In keeping with its overall mission, the COSO Board commissioned and published in 2004 the Enterprise Risk Management—Integrated Framework. Over the past decade, that publication has gained broad acceptance by organizations in their efforts to manage risk. However, also through that period, the complexity of risk has changed, new risks have emerged, and both boards and executives have enhanced their awareness and oversight of enterprise risk management while asking for improved risk reporting. This update to the 2004 publication addresses the evolution of enterprise risk management and the need for organizations to improve their approach to managing risk to meet the demands of an evolving business environment. The updated document, titled Enterprise Risk Management—Integrating with Strategy and Performance, highlights the importance of considering risk in both the strategy-setting process and in driving performance. Certification COSO Materials COSO issued a supplement with detailed examples for applying principles from the ERM Framework to day-to-day practices. This supplement, titled COSO Enterprise Risk Management - Integrating with Strategy and Performance: Compendium of Examples, was developed from industry practices identified through extensive research conducted when updating the Framework. Each example focuses on specific components covered in the Framework. Written as a collection of case studies, the Compendium offers real-world advice about how to put the ERM Framework to use. Each case describes how a specific entity scaled and adapted the principles, and sets out a relationship between an organization’s mission, vision, and core values; its strategic goals and directions; and approaches used in carrying out its strategy. University Professor/Student Discounts For information on discounts available to qualified university professors and their students, please contact Joanna Dabrowska. Email Integrating with Strategy and Performance: Compendium of Examples COSO issued a supplement with detailed examples for applying principles from the ERM Framework to day-to-day practices. This supplement, titled COSO Enterprise Risk Management - Integrating with Strategy and Performance: Compendium of Examples, was developed from industry practices identified through extensive research conducted when updating the Framework. Each example focuses on specific components covered in the Framework. Written as a collection of case studies, the Compendium offers real-world advice about how to put the ERM Framework to use. Each case describes how a specific entity scaled and adapted the principles, and sets out a relationship between an organization’s mission, vision, and core values; its strategic goals and directions; and approaches used in carrying out its strategy. The Compendium may be purchased from the following organizations: Purchase Purchase

  • Monitoring Internal Control Systems | COSO

    Monitoring Internal Control Systems This guidance is designed to help organizations monitor the quality of their internal control systems. Guidance

  • Blockchain and Internal Control | COSO

    Blockchain and Internal Control Blockchain and Internal Control: The COSO Perspective COSO releases a new paper, sponsored by Deloitte, providing perspectives for using the COSO Internal Control – Integrated Framework (2013) to evaluate risks related to the use of blockchain in the context of financial reporting and to design and implement controls to address such risks. It is intended to help inform decisions regarding oversight, risks, and internal control over financial reporting (ICFR) in a blockchain environment. Executive Summary News Release

  • Internal Control | COSO

    Guidance Internal Control - Integrated Framework Effective internal controls are good for business. This is perhaps an interesting way to introduce the purpose of this thought paper, but, as its authors, our collective knowledge is very straightforward in this regard. Internal controls have value beyond compliance and external financial reporting. Effective internal controls can help an organization articulate its purpose, set its objectives and strategy, and grow on a sustained basis with confidence and integrity in all types of information. The Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control—Integrated Framework, originally issued in 1992 and refreshed in 2013 (ICIF-2013 or Framework), was developed as guidance to help improve confidence in all types of data and information. In 2023 COSO issued supplemental guidance for organizations to achieve effective internal control over sustainability reporting (ICSR), using the globally recognized COSO Internal Control-Integrated Framework (ICIF). Purchase eBook Purchase eBook Purchase Softcover Internal Controls Documents Achieving Effective Internal Control Over Generative AI (2026) See More (SIMPLIFIED CHINESE) COSO ICSR See More GUIDANCE ON MONITORING INTERNAL CONTROL SYSTEMS (2009) See More (JAPANESE) BLOCKCHAIN AND INTERNAL CONTROL - THE COSO PERSPECTIVE See More ACHIEVING EFFECTIVE INTERNAL CONTROL OVER ROBOTIC PROCESS AUTOMATION (2024) See More (JAPANESE) COSO ICSR See More THE 2013 COSO FRAMEWORK & SOX COMPLIANCE See More BLOCKCHAIN AND INTERNAL CONTROL - THE COSO PERSPECTIVE See More ACHIEVING EFFECTIVE INTERNAL CONTROL OVER SUSTAINABILITY REPORTING (ICSR) See More (THAI) COSO ICSR See More LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE See More ITALIAN POSTER - INTEGRATED FRAMEWORK PRINCIPLES See More (SPANISH) COSO ICSR See More INTEGRATED FRAMEWORK EXECUTIVE SUMMARY See More IMPLEMENTATION GUIDE FOR THE HEALTHCARE PROVIDER INDUSTRTY See More POSTER - INTEGRATED FRAMEWORK PRINCIPLES See More Achieving Effective Internal Control Over Sustainability Reporting (ICSR) Building Trust and Confidence through the COSO Internal Control—Integrated Framework addresses the topic of how to support the implementation of sustainability throughout an organization. It is designed for organizations to achieve effective internal control over sustainability reporting (ICSR), using the globally recognized COSO Internal Control-Integrated Framework (ICIF). Its use is intended to build trust and confidence in ESG/sustainability reporting, public disclosures, and enterprise decision-making. New ICSR Guidance COSO - ICSR Report Appointment of Sub-Committees/Task Forces The 2013 Framework is expected to help organizations design and implement internal control in light of many changes in business and operating environments since the issuance of the original Framework, broaden the application of internal control in addressing operations and reporting objectives, and clarify the requirements for determining what constitutes effective internal control. COSO has also issued Illustrative Tools for Assessing Effectiveness of a System of Internal Control and the Internal Control over External Financial Reporting (ICEFR): A Compendium of Approaches and Examples. The Illustrative Tools are expected to assist users when assessing whether a system of internal control meets the requirements set forth in the updated Framework. The ICEFR Compendium is particularly relevant to those who prepare financial statements for external purposes based upon requirements set forth in the updated Framework. INTERNAL CONTROL FAQ'S See More INTEGRATED FRAMEWORK PRINCIPLES See More INTEGRATED FRAMEWORK EXECUTIVE SUMMARY See More ONE APPROACH TO EFFECTIVE TRANSITION See More Purchase Options Internal Control Bundle Internal Control Certificate Internal Control Framework Internal Control Bundle Internal Control Compendium The COSO Internal Control Certificate Program For multi-user licensing, please click the button below to reach us out. Email Reprint or Permission to Use For requests to reprint or use portions of the Internal Control — Integrated Framework, please complete the Copyright Permission Request Form and return it to the email provided below. Email Internal Control — Integrated Framework (1992) Produced after the release of the Treadway Commission’s recommendations, this document provides principles-based guidance for designing and implementing effective internal controls. COSO developed the framework in response to senior executives’ need for effective ways to better control their enterprises and to help ensure that organizational objectives related to operations, reporting, and compliance are achieved. This framework has become the most widely used internal control framework in the U.S. and has been adapted or adopted by numerous countries and businesses around the world. On December 15, 2014 this framework was superseded by the 2013 Internal Control — Integrated Framework. Guidance on Monitoring Internal Control Systems (2009) Effective monitoring of internal control is one of the five components of effective internal control delineated in COSO's Internal Control — Integrated Framework. COSO has developed detailed interpretative guidance that will help organizations monitor the quality of their internal control systems. Learn more about guidance on monitoring . Internal Control over Financial Reporting — Guidance for Smaller Public Companies (2006) This document contains guidance targeted towards smaller public companies, to help them apply concepts in the 1992 Internal Control — Integrated Framework. The guidance demonstrates the applicability of those concepts to help smaller public companies design and implement internal controls to support the achievement of financial reporting objectives. It highlights 20 key principles of the 1992 framework, providing a principles-based approach to internal control. While targeted toward smaller public companies, the 2006 guidance applies to entities of all sizes and types. On December 15, 2014, this guidance was superseded by the 2013 Internal Control — Integrated Framework, Internal Control Over External Financial Reporting: A Compendium of Approaches and Examples. Internal Control Issues in Derivatives Usage (1996) This guidance was issued in response to derivatives-related problems in recent years, many of which resulted from misunderstanding their risks and their use for risk management purposes. The document provided best-practice guidance for the development of internal controls related to derivative activities. This document was discontinued on December 15, 2014. Internal Control Implementation Guidance Blockchain and Internal Control: The COSO Perspective (2020) As blockchain becomes mainstream, it is appropriate to focus on how this technology intersects with an entity’s internal control. With careful implementation and integration, the distinctive capabilities of blockchain can be leveraged to create more robust controls for organizations. Blockchain-enhanced tools also have the potential to promote operational efficiency and effectiveness, improve reliability and responsiveness of financial and other reporting, and elevate compliance with laws and regulations. But blockchain also creates new risks and the need for new controls. This guidance provides perspectives for using Internal Control — Integrated Framework (2013) to evaluate risks related to the use of blockchain in the context of financial reporting and to design and implement controls to address such risks. It is intended to help inform decisions regarding oversight, risks, and internal control over financial reporting (ICFR). The paper also should be of value to the various stakeholders involved in financial reporting, within the context of their own environments. See More Implementation Guide for the Healthcare Provider Industry (2019) Amid heightened scrutiny and ever-increasing complexities in operations and regulation, healthcare organizations face unique challenges related to the design and operation of internal controls. In response, the Committee of Sponsoring Organizations of the Treadway Commission (COSO), in collaboration with Crowe LLP and CommonSpirit Health, has published new guidance: “2013 COSO Integrated Framework: An Implementation Guide for the Healthcare Provider Industry.” Healthcare organizations experience issues with system access and integrity, clinical documentation, coding, and billing, all of which may result in potential noncompliance with federal and state regulations – and costly mistakes. The guide introduces healthcare organizations to COSO’s widely used “Internal Control – Integrated Framework,” and provides a roadmap to implementation to help strengthen their overall governance and internal control structures. See More Internal Control Thought Papers Leveraging COSO Across the Three Lines of Defense In this paper, authors Douglas J. Anderson and Gina Eubanks make a strong case for using the Three Lines of Defense Model, which addresses how specific duties related to risk and control should be assigned and coordinated. See More The 2013 COSO Framework & SOX Compliance: One Approach to an Effective Transition (2013) COSO has issued an article aimed at assisting public companies comply with Section 404 of the U.S. Sarbanes-Oxley Act of 2002. The article outlines an example of one approach to transitioning to COSO’s 2013 Internal Control — Integrated Framework from the original framework published in 1992. See More

  • GenAI | COSO

    Achieving Effective Internal Control Over Generative AI COSO Releases Practical Roadmap for Managing Generative AI Risks and Controls New publication translates COSO’s Internal Control–Integrated Framework into practical, audit‑ready guidance for governing GenAI The Committee of Sponsoring Organizations of the Treadway Commission (COSO), today released a new publication, Achieving Effective Internal Control Over Generative AI (GenAI) , offering organizations a practical, COSO‑aligned approach to managing the risks and opportunities introduced by rapidly advancing generative AI technologies. Generative AI is moving into boardrooms and day‑to‑day operations far faster than traditional governance models anticipated. Organizations are already using AI‑enabled tools to automate reconciliations, accelerate analysis, and support decision‑making at a scale that compresses timelines and reshapes workflows. Such rapid adoption brings a new class of risks — from heightened cyber exposure and prompt‑based manipulation to opaque reasoning, model drift, and frequent configuration changes — that can jeopardize the integrity of operations, reporting, and compliance if not addressed with robust internal controls. Publication Press Release

  • Artificial Intelligence | COSO

    Artificial Intelligence Realize the Full Potential of Artificial Intelligence Recognizing the accelerating need to identify and manage the risks of Artificial Intelligence (AI) effectively, the Committee of Sponsoring Organizations of the Treadway Commission (COSO), in collaboration with Deloitte, has issued “Realize the Full Potential of Artificial Intelligence.” This new guidance leverages the principles from COSO’s Enterprise Risk Management (ERM) – Integrating with Strategy and Performance Framework (2017), and serves as a guide to help organizations align risk management with strategy and execution of their AI initiatives. The project, commissioned by COSO and co-authored by Deloitte, focuses on the need for organizations to design and implement governance, risk management, and oversight strategies and structures to realize the potential of humans collaborating with AI. Executive Summary News Release

  • Fraud Deterrence | COSO

    Guidance Fraud Deterrence The Fraud Risk Management Guide, originally published in 2016, was intended to be supportive of and consistent with the COSO 2013 IC Framework and to serve as guidance for organizations to follow in addressing this specific fraud risk assessment principle. The Guide’s executive summary provides a high-level overview intended for the board of directors, senior management, and chief audit executives. It is designed to explain the benefits of establishing strong anti-fraud policies and controls. On the 2nd of May, 2023, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) and the Association of Certified Fraud Examiners (ACFE) announced the release of the Fraud Risk Management Guide: Second Edition, a new publication that offers a blueprint for helping organizations establish an overall Fraud Risk Management Program. Executive Summary 2016 The Fraud Risk Management Guide: 2nd Edition It offers a blueprint for helping organizations establish an overall Fraud Risk Management Program. An update to the original version released in 2016, the 2nd Edition addresses more recent anti-fraud developments, revises terminology, and adds important information related to technology developments - specifically data analytics. It is intended to give organizations of all sizes across all industries the information necessary to design a plan specific to the risks for that entity. There is no “one size fits all approach” to managing fraud risk. But with the right approach, an organization can create a custom-fitted program tailored to its specific needs. Press Release Executive Summary 2023 This publication may be purchased from the following organizations: Purchase Purchase Purchase Leading practices for anti-fraud professionals and organizations intent on deterring fraud NEW YORK, May 2, 2023 – The Committee of Sponsoring Organizations of the Treadway Commission (COSO) and the Association of Certified Fraud Examiners (ACFE) announced today the release of the Fraud Risk Management Guide: Second Edition, a new publication that offers a blueprint for helping organizations establish an overall Fraud Risk Management Program. The Guide updates the first edition of the Fraud Risk Management Guide published in 2016. It also draws from a 2008 publication published and sponsored by the American Institute of CPAs (AICPA), Institute of Internal Auditors (IIA), and the ACFE. Updates reflect recent anti-fraud developments, revise terminology, and add important information related to technology developments - specifically data analytics. Since its inception, COSO has provided landmark thought leadership on internal control, enterprise risk management, and fraud deterrence. This Guide will be familiar to COSO Framework users - - it contains principles and points of focus, aligned with the internal control framework and principles outlined in COSO’s 2013 Internal Control – Integrated Framework (2013 ICIF). “The 2016 Fraud Risk Management Guide became recognized as containing a widely accepted set of leading practices for anti-fraud professionals and organizations intent on deterring fraud,” said Paul Sobel, past COSO Chair who oversaw this project. “Fraud is not static. Accordingly, COSO and the ACFE initiated an update process that included reaching out to a broad range of users for recommendations on where the Guide can be improved, and assembled a team to take a refreshed look at the Guide and assess how and where it should be updated.” Media Contacts Cecile Fradkin S&C Public Relations Inc. (646) 941-9139 Email Christopher Almonte The Institute of Internal Auditors (407) 937-1349 Email Stefanie Hallgren The Association of Certified Fraud Examiners (512) 276-8167 Email Key updates in the Second Edition includes: Fraud risk management and deterrence - Explains how fraud risk management relates to and supports fraud deterrence — a key theme in COSO’s mission. Relationships among COSO’s two frameworks and fraud risk management - Explains how the COSO 2013 Internal Control — Integrated Framework, the COSO 2017 Enterprise Risk Management — Integrating with Strategy and Performance Framework and the Fraud Risk Management Guide are related and support each other. Expanded information on data analytics - Includes expanded and updated information on data analytics, while continuing to emphasize the importance of interviewing and whistleblower systems. Internal control and fraud risk management - Explains how internal control and fraud risk management are related and support each other but are different in some important respects. Changes in the legal and regulatory environment - Includes updated information with respect to recent legal and regulatory developments in the U.S. pertaining to fraud and fraud risk management. “It is impossible to eliminate all fraud in all organizations. However, effective leaders address fraud risk as they do any risk — they manage it,” said ACFE President and CEO Bruce Dorris, “The Fraud Risk Management Guide gives organizations, whether large or small, government or private, profit or non-profit, the information necessary to design a plan specific to the risks for that entity. There is no ‘one size fits all approach’ to managing fraud risk, but by applying the guidance in the updated Guide, an organization can create a custom-fitted program tailored to its specific needs.” The Guide includes examples of key program components and resources that organizations can use to develop a fraud risk-management program effectively and efficiently. In addition, it contains references to other sources of guidance for tailoring a fraud risk-management program to a specific industry. “COSO’s mission is to help organizations improve performance by developing thought leadership that enhances internal control, risk management, governance and fraud deterrence. The Fraud Risk Management Guide is a key tool for furthering this mission, mainly with respect to fraud deterrence, particularly through the principled alignment supported by COSOs existing 2013 ICIF,” added Lucia Wind, COSO Chair. For more information, or to request a copy of the report, please visit: See More

  • COSO and NACD Award PwC US RFP for Devel | COSO

    COSO and NACD Award PwC US RFP for Development of Corporate Governance Framework COSO and NACD Issue Request for Proposal to Develop Corporate Governance Framework and Application Guidance The Committee of Sponsoring Organizations of the Treadway Commission (COSO), in collaboration with the National Association of Corporate Directors (NACD), has awarded PwC US a Professional Services Agreement to assist COSO in developing a Corporate Governance Framework (CGF). PwC US was selected after a thorough and competitive RFP process involving numerous respected and knowledgeable organizations, within and outside of the US. ..see more Press Release

bottom of page