top of page

Search Results

Search this site

44 results found with an empty search

  • Seeking New Board Chair | COSO

    Seeking New Board Chair Applications Are Being Accepted Through June 30, 2022 NEW YORK, May 18, 2022 – The Committee of Sponsoring Organizations of the Treadway Commission (COSO) is seeking applications for the position of Board Chair. The Chair is responsible for leading COSO in fulfilling its mission of providing thought leadership in the areas of internal control, enterprise risk management, governance, and fraud deterrence. Paul J. Sobel, the current COSO chairman, plans to step down after admirably serving in that capacity since 2018. The Institute of Internal Auditors (IIA), a sponsoring organization of COSO, is managing the application process. The elected position will commence on January 1, 2023, for a three-year term. The COSO board is seeking candidates with executive maturity and presence, deep knowledge and experience in internal controls, enterprise risk management, governance, and fraud deterrence, leadership skills, public speaking proficiency, and a commitment to ensuring the relevance and influence of COSO globally. Key responsibilities include board leadership; strategic relationships with other organizations that have a common interest with COSO’s mission; oversight of COSO-sponsored projects and other activities that align with its vision, mission, and strategic goals. “The COSO board greatly appreciates Paul’s service, and we look forward to enhancing COSO’s influence and relevance globally in a disruptive business environment with a chair who continues to exemplify executive maturity and presence, has experience leading boards, and is a credible voice in internal controls, risk management and corporate governance,” says Jeff Thomson, COSO Lead Director and CEO of the Institute of Management Accountants. Candidates may submit a letter of interest along with a current resume of qualifications to This Link by the position application close date June 30, 2022.

  • Guidance | COSO

    Guidance Fraud Deterrence Guide Summary Enterprise Risk Management Guide Summary ERM Guidance Documents EFFECTIVE ENTERPRISE RISK OVERSIGHT - THE ROLE OF THE BOARD OF DIRECTORS (2009) PDF File UNDERSTANDING AND COMMUNICATING RISK APPETITE (2012) PDF File DEVELOPING KEY RISK INDICATORS TO STRENGTHEN ENTERPRISE RISK MANAGEMENT (2010) PDF File CLOUD COMPUTING THOUGHT PAPER (2012) PDF File BOARD RISK OVERSIGHT - A PROGRESSS REPORT (2010) PDF File RISK ASSESSMENT IN PRACTICE (2012) PDF File PRACTICAL APPROACHES FOR GETTING STARTED (2011) PDF File ENHANCING BOARD OVERSIGHT (2012) PDF File 1 2 3 4 1 ... 1 2 3 4 ... 4 Internal Control Summary Guide Achieving Effective Internal Control Over Generative AI (2026) PDF File ACHIEVING EFFECTIVE INTERNAL CONTROL OVER ROBOTIC PROCESS AUTOMATION (2024) PDF File ACHIEVING EFFECTIVE INTERNAL CONTROL OVER SUSTAINABILITY REPORTING (ICSR) PDF File (SPANISH) COSO ICSR PDF File 1 2 3 4 1 ... 1 2 3 4 ... 4 The publication may be purchased from: Governance Corporate Governance: Guiding Principles for Board Oversight (2026) PDF File Improving Organizational Performance and Governance (2014) PDF File Enhancing Board Oversight (2012) PDF File

  • About Us | COSO

    About Us Mission The Committee of Sponsoring Organizations’ (COSO) mission is to help organizations improve performance by developing thought leadership that enhances internal control, risk management, governance and fraud deterrence. Vision COSO’s vision is to be globally recognized as an authority on internal control and a thought leader on risk management, governance and fraud deterrence. COSO ’s goal is to provide thought leadership dealing with three interrelated subjects: Enterprise Risk Management (ERM), Internal Control, Fraud Deterrence and Governance . Regarding Internal Control , in 1992, COSO published Internal Control — Integrated Framework. This framework was revised and reissued in May 2013. Over the years, COSO continued to issue other publications pertaining to internal controls, including thought leadership such as Internal Control over Financial Reporting — Guidance for Smaller Public Companies Guidance on Monitoring Internal Control Systems or most recently Internal Controls over Sustainability Reporting. For more information visit the Internal Control Guidance page. Regarding ERM , in 2004, COSO issued Enterprise Risk Management — Integrated Framework. This framework was updated with the release in 2017 of “Enterprise Risk Management–Integrating with Strategy and Performance,” which highlights the importance of considering risk in both the strategy-setting process and in driving performance. COSO has also published several thought papers beginning in 2009 relating to ERM, for more information visit the ERM Guidance page. In the area of Fraud Deterrence , COSO has published two research studies. The first study released in 1999 was titled Fraudulent Financial Reporting: 1987-1997. A continuation study called Fraudulent Financial Reporting: 1998-2007 was released in 2010. In the recent years, COSO issued its first Fraud Risk Management Guide in 2016, which was later updated to include more focus areas and republished in 2023. For more on fraud deterrence visit the Fraud Deterrence page. COSO’s most recent focus is on the development of a Corporate Governance Framework. Please review our News page for more information and our Other Guidance page for more thought leadership on Governance . Enterprise Risk Management Internal Control Fraud Deterrence COSO at 30 Years Audio File Summary COSO eBook Publications See More

  • Enterprise Risk Management | COSO

    Guidance Enterprise Risk Management In keeping with its overall mission, the COSO Board commissioned and published in 2004 Enterprise Risk Management—Integrated Framework. Over the past decade, that publication has gained broad acceptance by organizations in their efforts to manage risk. However, also through that period, the complexity of risk has changed, new risks have emerged, and both boards and executives have enhanced their awareness and oversight of enterprise risk management while asking for improved risk reporting. The updated 2017 publication (see below) addresses the evolution of enterprise risk management and the need for organizations to improve their approach to managing risk to meet the demands of an evolving business environment. Certification Free - Executive Summary Purchase eBook Purchase eBook Purchase Softcover ERM Guidance Documents FROM GUIDANCE TO ACTION: EXPLORING PRACTICAL ERM (2026) See More (JAPANESE) ENTERPRISE RISK MANAGEMENT FOR CLOUD COMPUTING (2021) See More (JAPANESE) COMPLIANCE RISK MANAGEMENT: APPLYING THE COSO ERM FRAMEWORK (2020) See More (JAPANESE) MANAGING CYBER RISK IN A DIGITAL AGE (2019) See More (SPANISH) ENTERPRISE RISK MANAGEMENT TO ENVIRONMENTAL, SOCIAL AND GOVERNANCE-RELATED RISK (2018) See More ENHANCING BOARD OVERSIGHT (2012) See More PRACTICAL APPROACHES FOR GETTING STARTED (2011) See More ALTERNATIVE DATA: THE COSO PERSPECTIVE (2024) See More REALIZE THE FULL POTENTIAL OF ARTIFICIAL INTELLIGENCE (2021) See More RISK APPETITECRITICAL TO SUCCESS (2020) See More MANAGING CYBER RISK IN A DIGITAL AGE (2019) See More (FULL) ENTERPRISE RISK MANAGEMENT TO ENVIRONMENTAL, SOCIAL AND GOVERNANCE-RELATED RISK (2018) See More RISK ASSESSMENT IN PRACTICE (2012) See More BOARD RISK OVERSIGHT - A PROGRESSS REPORT (2010) See More ENABLING ORGANIZATIONAL AGILITY IN AN AGE OF SPEED AND DISRUPTION (2022) See More (PORTUGUESE) REALIZE THE FULL POTENTIAL OF ARTIFICIAL INTELLIGENCE (2021) See More COMPLIANCE RISK MANAGEMENT: APPLYING THE COSO ERM FRAMEWORK (2020) See More (SUMMARY) ENTERPRISE RISK MANAGEMENT TO ENVIRONMENTAL, SOCIAL AND GOVERNANCE-RELATED RISK (2018) See More COSO IN THE CYBER AGE (2015) See More CLOUD COMPUTING THOUGHT PAPER (2012) See More DEVELOPING KEY RISK INDICATORS TO STRENGTHEN ENTERPRISE RISK MANAGEMENT (2010) See More ENTERPRISE RISK MANAGEMENT FOR CLOUD COMPUTING (2021) See More (JAPANESE) REALIZE THE FULL POTENTIAL OF ARTIFICIAL INTELLIGENCE (2021) See More CREATING AND PROTECTING VALUE (2020) See More (PORTUGUESE) ENTERPRISE RISK MANAGEMENT TO ENVIRONMENTAL, SOCIAL AND GOVERNANCE-RELATED (2018) See More DEMYSTIFYING SUSTAINABILITY RISK (2013) See More UNDERSTANDING AND COMMUNICATING RISK APPETITE (2012) See More EFFECTIVE ENTERPRISE RISK OVERSIGHT - THE ROLE OF THE BOARD OF DIRECTORS (2009) See More Integrating with Strategy and Performance: Compendium of Examples COSO issued a supplement with detailed examples for applying principles from the ERM Framework to day-to-day practices. This supplement, titled COSO Enterprise Risk Management - Integrating with Strategy and Performance: Compendium of Examples, was developed from industry practices identified through extensive research conducted when updating the Framework. Each example focuses on specific components covered in the Framework. Written as a collection of case studies, the Compendium offers real-world advice about how to put the ERM Framework to use. Each case describes how a specific entity scaled and adapted the principles, and sets out a relationship between an organization’s mission, vision, and core values; its strategic goals and directions; and approaches used in carrying out its strategy. Compendium of Examples COSO issued a supplement with detailed examples for applying principles from the ERM Framework to day-to-day practices. This supplement, titled COSO Enterprise Risk Management - Integrating with Strategy and Performance: Compendium of Examples, was developed from industry practices identified through extensive research conducted when updating the Framework. Each example focuses on specific components covered in the Framework. Written as a collection of case studies, the Compendium offers real-world advice about how to put the ERM Framework to use. Each case describes how a specific entity scaled and adapted the principles, and sets out a relationship between an organization’s mission, vision, and core values; its strategic goals and directions; and approaches used in carrying out its strategy.

  • Internal Control | COSO

    Guidance Internal Control - Integrated Framework Effective internal controls are good for business. This is perhaps an interesting way to introduce the purpose of this thought paper, but, as its authors, our collective knowledge is very straightforward in this regard. Internal controls have value beyond compliance and external financial reporting. Effective internal controls can help an organization articulate its purpose, set its objectives and strategy, and grow on a sustained basis with confidence and integrity in all types of information. The Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control—Integrated Framework, originally issued in 1992 and refreshed in 2013 (ICIF-2013 or Framework), was developed as guidance to help improve confidence in all types of data and information. In 2023 COSO issued supplemental guidance for organizations to achieve effective internal control over sustainability reporting (ICSR), using the globally recognized COSO Internal Control-Integrated Framework (ICIF). Purchase eBook Purchase eBook Purchase Softcover Internal Controls Documents Achieving Effective Internal Control Over Generative AI (2026) See More (SIMPLIFIED CHINESE) COSO ICSR See More GUIDANCE ON MONITORING INTERNAL CONTROL SYSTEMS (2009) See More (JAPANESE) BLOCKCHAIN AND INTERNAL CONTROL - THE COSO PERSPECTIVE See More ACHIEVING EFFECTIVE INTERNAL CONTROL OVER ROBOTIC PROCESS AUTOMATION (2024) See More (JAPANESE) COSO ICSR See More THE 2013 COSO FRAMEWORK & SOX COMPLIANCE See More BLOCKCHAIN AND INTERNAL CONTROL - THE COSO PERSPECTIVE See More ACHIEVING EFFECTIVE INTERNAL CONTROL OVER SUSTAINABILITY REPORTING (ICSR) See More (THAI) COSO ICSR See More LEVERAGING COSO ACROSS THE THREE LINES OF DEFENSE See More ITALIAN POSTER - INTEGRATED FRAMEWORK PRINCIPLES See More (SPANISH) COSO ICSR See More INTEGRATED FRAMEWORK EXECUTIVE SUMMARY See More IMPLEMENTATION GUIDE FOR THE HEALTHCARE PROVIDER INDUSTRTY See More POSTER - INTEGRATED FRAMEWORK PRINCIPLES See More Achieving Effective Internal Control Over Sustainability Reporting (ICSR) Building Trust and Confidence through the COSO Internal Control—Integrated Framework addresses the topic of how to support the implementation of sustainability throughout an organization. It is designed for organizations to achieve effective internal control over sustainability reporting (ICSR), using the globally recognized COSO Internal Control-Integrated Framework (ICIF). Its use is intended to build trust and confidence in ESG/sustainability reporting, public disclosures, and enterprise decision-making. New ICSR Guidance COSO - ICSR Report Appointment of Sub-Committees/Task Forces The 2013 Framework is expected to help organizations design and implement internal control in light of many changes in business and operating environments since the issuance of the original Framework, broaden the application of internal control in addressing operations and reporting objectives, and clarify the requirements for determining what constitutes effective internal control. COSO has also issued Illustrative Tools for Assessing Effectiveness of a System of Internal Control and the Internal Control over External Financial Reporting (ICEFR): A Compendium of Approaches and Examples. The Illustrative Tools are expected to assist users when assessing whether a system of internal control meets the requirements set forth in the updated Framework. The ICEFR Compendium is particularly relevant to those who prepare financial statements for external purposes based upon requirements set forth in the updated Framework. INTERNAL CONTROL FAQ'S See More INTEGRATED FRAMEWORK PRINCIPLES See More INTEGRATED FRAMEWORK EXECUTIVE SUMMARY See More ONE APPROACH TO EFFECTIVE TRANSITION See More Purchase Options Internal Control Bundle Internal Control Certificate Internal Control Framework Internal Control Bundle Internal Control Compendium The COSO Internal Control Certificate Program For multi-user licensing, please click the button below to reach us out. Email Reprint or Permission to Use For requests to reprint or use portions of the Internal Control — Integrated Framework, please complete the Copyright Permission Request Form and return it to the email provided below. Email Internal Control — Integrated Framework (1992) Produced after the release of the Treadway Commission’s recommendations, this document provides principles-based guidance for designing and implementing effective internal controls. COSO developed the framework in response to senior executives’ need for effective ways to better control their enterprises and to help ensure that organizational objectives related to operations, reporting, and compliance are achieved. This framework has become the most widely used internal control framework in the U.S. and has been adapted or adopted by numerous countries and businesses around the world. On December 15, 2014 this framework was superseded by the 2013 Internal Control — Integrated Framework. Guidance on Monitoring Internal Control Systems (2009) Effective monitoring of internal control is one of the five components of effective internal control delineated in COSO's Internal Control — Integrated Framework. COSO has developed detailed interpretative guidance that will help organizations monitor the quality of their internal control systems. Learn more about guidance on monitoring . Internal Control over Financial Reporting — Guidance for Smaller Public Companies (2006) This document contains guidance targeted towards smaller public companies, to help them apply concepts in the 1992 Internal Control — Integrated Framework. The guidance demonstrates the applicability of those concepts to help smaller public companies design and implement internal controls to support the achievement of financial reporting objectives. It highlights 20 key principles of the 1992 framework, providing a principles-based approach to internal control. While targeted toward smaller public companies, the 2006 guidance applies to entities of all sizes and types. On December 15, 2014, this guidance was superseded by the 2013 Internal Control — Integrated Framework, Internal Control Over External Financial Reporting: A Compendium of Approaches and Examples. Internal Control Issues in Derivatives Usage (1996) This guidance was issued in response to derivatives-related problems in recent years, many of which resulted from misunderstanding their risks and their use for risk management purposes. The document provided best-practice guidance for the development of internal controls related to derivative activities. This document was discontinued on December 15, 2014. Internal Control Implementation Guidance Blockchain and Internal Control: The COSO Perspective (2020) As blockchain becomes mainstream, it is appropriate to focus on how this technology intersects with an entity’s internal control. With careful implementation and integration, the distinctive capabilities of blockchain can be leveraged to create more robust controls for organizations. Blockchain-enhanced tools also have the potential to promote operational efficiency and effectiveness, improve reliability and responsiveness of financial and other reporting, and elevate compliance with laws and regulations. But blockchain also creates new risks and the need for new controls. This guidance provides perspectives for using Internal Control — Integrated Framework (2013) to evaluate risks related to the use of blockchain in the context of financial reporting and to design and implement controls to address such risks. It is intended to help inform decisions regarding oversight, risks, and internal control over financial reporting (ICFR). The paper also should be of value to the various stakeholders involved in financial reporting, within the context of their own environments. See More Implementation Guide for the Healthcare Provider Industry (2019) Amid heightened scrutiny and ever-increasing complexities in operations and regulation, healthcare organizations face unique challenges related to the design and operation of internal controls. In response, the Committee of Sponsoring Organizations of the Treadway Commission (COSO), in collaboration with Crowe LLP and CommonSpirit Health, has published new guidance: “2013 COSO Integrated Framework: An Implementation Guide for the Healthcare Provider Industry.” Healthcare organizations experience issues with system access and integrity, clinical documentation, coding, and billing, all of which may result in potential noncompliance with federal and state regulations – and costly mistakes. The guide introduces healthcare organizations to COSO’s widely used “Internal Control – Integrated Framework,” and provides a roadmap to implementation to help strengthen their overall governance and internal control structures. See More Internal Control Thought Papers Leveraging COSO Across the Three Lines of Defense In this paper, authors Douglas J. Anderson and Gina Eubanks make a strong case for using the Three Lines of Defense Model, which addresses how specific duties related to risk and control should be assigned and coordinated. See More The 2013 COSO Framework & SOX Compliance: One Approach to an Effective Transition (2013) COSO has issued an article aimed at assisting public companies comply with Section 404 of the U.S. Sarbanes-Oxley Act of 2002. The article outlines an example of one approach to transitioning to COSO’s 2013 Internal Control — Integrated Framework from the original framework published in 1992. See More

  • Frequently Asked Questions | COSO

    < Back Frequently Asked Questions This is placeholder text. To change this content, double-click on the element and click Change Content. This is placeholder text. To change this content, double-click on the element and click Change Content. Want to view and manage all your collections? Click on the Content Manager button in the Add panel on the left. Here, you can make changes to your content, add new fields, create dynamic pages and more. You can create as many collections as you need. Your collection is already set up for you with fields and content. Add your own, or import content from a CSV file. Add fields for any type of content you want to display, such as rich text, images, videos and more. You can also collect and store information from your site visitors using input elements like custom forms and fields. Be sure to click Sync after making changes in a collection, so visitors can see your newest content on your live site. Preview your site to check that all your elements are displaying content from the right collection fields. Previous Next

  • Exposure Draft - Corporate Governance Framework | COSO

    < Back Exposure Draft - Corporate Governance Framework This is placeholder text. To change this content, double-click on the element and click Change Content. This is placeholder text. To change this content, double-click on the element and click Change Content. Want to view and manage all your collections? Click on the Content Manager button in the Add panel on the left. Here, you can make changes to your content, add new fields, create dynamic pages and more. You can create as many collections as you need. Your collection is already set up for you with fields and content. Add your own, or import content from a CSV file. Add fields for any type of content you want to display, such as rich text, images, videos and more. You can also collect and store information from your site visitors using input elements like custom forms and fields. Be sure to click Sync after making changes in a collection, so visitors can see your newest content on your live site. Preview your site to check that all your elements are displaying content from the right collection fields. Previous Next

  • Press Release | COSO

    < Back Press Release This is placeholder text. To change this content, double-click on the element and click Change Content. This is placeholder text. To change this content, double-click on the element and click Change Content. Want to view and manage all your collections? Click on the Content Manager button in the Add panel on the left. Here, you can make changes to your content, add new fields, create dynamic pages and more. You can create as many collections as you need. Your collection is already set up for you with fields and content. Add your own, or import content from a CSV file. Add fields for any type of content you want to display, such as rich text, images, videos and more. You can also collect and store information from your site visitors using input elements like custom forms and fields. Be sure to click Sync after making changes in a collection, so visitors can see your newest content on your live site. Preview your site to check that all your elements are displaying content from the right collection fields. Previous Next

bottom of page