Introduction
A well-designed internal control system is vital to organizations whose mission involves safeguarding resources, generating reliable financial reporting, adherence to laws and regulations, and pursuing their operations goals. In larger businesses informal mechanisms that relied on trust, personal supervision and personal knowledge may prove to be insufficient. Organizations must have a systematic method that can identify risks and put controls in place that can stop or reveal issues before they escalate into a problem. One of the most accepted methods for the design, implementation and evaluation of internal controls is the COSO Internal Control Framework. COSO was developed by the Committee of Sponsoring Organizations of the Treadway Commission to offer guidance, which may be relevant for small and medium-sized enterprises (SMEs), growing businesses, nonprofit organizations, and larger businesses looking for a common set of controls. The COSO Internal Control Framework guidance outlines the framework and its general application to internal control, and can be reviewed by organizations.
What is the COSO Internal Control Framework?
The COSO Internal Control Framework is a framework of structure that guides organizations in developing their internal control systems for their objectives, risks, processes, and responsibilities. COSO does not consider internal control to be a series of accounting procedures but rather a process that involves management, employees, the board, and others. The control environment, risk assessment, control activities, information and communication, and monitoring activities are the five interrelated components of the framework. The components are designed to give reasonable assurance that a company can accomplish objectives related to operations, reporting and compliance. This distinction is significant because it is important to understand that no internal control system is perfect enough to ensure that fraud, error or failure will not happen at all. Rather, a well-designed system minimizes risk to an acceptable level and assists in the management of identification and resolution of issues in a systematic and timely fashion.
1. Control Environment
The control environment is the bedrock of the entire internal control system as it sets the tone of the entire organization for its integrity, accountability, ethics and control. It is not just a policy manual, it is about what happens or doesn’t happen in the decision-making and actions of senior management and the board. Having sophisticated accounting systems and complex approvals processes doesn’t mean a company’s controls are effective if leaders condone dishonesty, overlook conflicts of interest and circumvent processes when it is convenient. A good control environment sets high standards for ethical behavior and helps staff appreciate that internal controls are integral to good business practice. Key factors to include are management’s integrity, organizational structures, reporting lines, staff competency, clear responsibilities and good management and governance oversight.
While it may seem like a large compliance department and high tech is necessary for building a robust control environment, for SMEs it is not. A small business can start by establishing a straightforward code of conduct, establishing employee duties, laying down critical procedures and guaranteeing that the proprietors and managers stick to the law of the land as other workers do. For instance, if workers have to provide receipts for business expenses, then a business owner should do the same, rather than approve personal business expenses without a receipt. Violations should also be uniformly addressed by management and qualifications should be established for the jobs held. Taking controls seriously by employees will make them more willing to follow procedures. Thus, the culture of an organization is established by the control environment, against which the other four COSO components are supposed to function.
2. Risk Assessment
Risk assessment means the process of identifying and analyzing events that may hinder an organization’s ability to accomplish its goals. The risks that every organization encounters vary in kind and magnitude based on such factors as industry, size, location, technology, customers, suppliers and business model. Financial risks could be cash-flow issues, payments made without authorization, accounting records kept inaccurately, or even theft, while operational risks might be a problem with staffing or equipment, poor quality products, or system failures. Failure to fulfill industry, contractual, regulatory and employment obligations, or tax obligations can create compliance threats. Strategic risks could be due to shifts in customer tastes, strong competitors, substandard investments, or business misjudgments. A robust risk assessment process can assist management in changing from a reactive to a proactive approach to risks that may result in significant losses.
Fraud risk should also be part of the risk assessment as fraud can be challenging to identify if organizations are not proactive in assessing their vulnerability. Management should consider how employees, customers, suppliers, contractors or outside parties might be able to take advantage of vulnerabilities in the organization’s processes. If one employee can create a supplier, approve an invoice and sign off on payment without needing to seek further approval, there could be a high concentration of control that could be exploited. SMEs can be smaller and have less staff and this can make it difficult to compartmentalize tasks, but does not mean they can have to live with uncontrolled risk. Using compensating controls to audit and reconcile transactions, such as owner review, independent bank reconciliation, transaction reports, surprise checks, or periodic external accounting reviews are methods that management can employ. The goal is to gain the understanding of the organization’s risks and identify those that need a higher level of control based on risk likelihood and impact.
3. Control Activities
Control activities refer to the specific actions, policies and procedures that are established to address specific risks identified and to aid in implementing management instructions. They are the “how” of internal control; they embody what happens in the day-to-day operation of business to make internal control a reality. Some examples of control activities are authorization requirements, approvals, reconciliations, segregation of duties, physical safeguards, access restrictions, documentation requirements, supervisory reviews, automated system controls and independent verification. In the case of a company, for instance, they may have two people prepare the payment, and then another approve it and then still another sign it, so that it’s not easy to make payments without anybody noticing. Likewise, monthly bank reconciliations could find that amounts listed on the bank statement do not match the accountant’s records and inventory counts can show that items are missing or damaged. Control activities should be targeted at risks and not be implemented because they are common business processes.
Advances in technology have also transformed how control activities are performed in today’s organizations. Accounting systems can limit access to users, have auditing abilities, have approval systems, flag odd transactions and not allow certain transactions to be processed without the necessary information. But, automation cannot take the place of human control. Poorly set up systems can produce many mistakes, and over extended system user privileges can lead to unauthorized transactions. It is therefore important for SMEs to identify the individuals that are able to create, approve, amend and destroy critical financial and operational data. There should also be appropriate controls in terms of the size and risk profile of the organization. As an expanding company grows, they can start by implementing simple approval workflows and start to automate the process as they grow, monitor transactions in greater detail, and roll out role-based access controls and more advanced monitoring in the future.
4. Information and Communication
Information and communication provide people the information they need to carry out their responsibilities and to effectively operate the internal control system. But, in the absence of employee awareness, managers with missing information, or significant issues not brought to the attention of the decision makers, internal controls will not be effective. Information that is relevant shall be identified, collected, manipulated and conveyed to the appropriate individual(s) in a timely fashion. For instance, finance staff might need a precise sales data for proper sales recording, whereas management may want cash-flow statements to gauge if the business can pay off the obligations it has. Staff should also be aware of the procedures for reporting frauds, failures of control, conflicts of interest or unusual transactions to prevent any action that may hinder them from reporting or result in repercussions.
Communication should not be unidirectional and from senior management to staff. There needs to be a clear downward communication of objectives, policies, responsibilities and expectations from management and a suitable upward communication of concerns from employees. There can also be a cross-departmental flow of information for the departments to coordinate effectively with finance, operations, HR, procurement and management. There is also external communication that can be of significance, customers, suppliers, regulators, auditors, banks and others may require information from the organization. For a small to medium business, good communication might just be happening at regular management meetings, taking the time to document procedures, put in place a financial reporting schedule, establish an approval process, or provide a confidential reporting system. It is important to ensure that the relevant information is delivered to the appropriate person at the appropriate time in a format that assists in making decisions.
5. Monitoring Activities
Monitoring activities help to ensure that internal controls are effective over time. But new products, processes, and management changes, as well as increased volume of transactions, changes in employee duties and technology, and changes in business conditions can all make well-designed controls ineffective. Monitoring is thus a continuous process that enables the detection of weaknesses and help to decide if corrective measures are needed. Continuous monitoring activities, which are performed as part of ongoing operations, can be employed, or separate evaluations can be conducted that investigate controls at regular intervals, or a mix of both can be used. These include Management reviews, internal audits, reconciliations, compliance checks, inventory checks, exception reports, customer complaints, and investigations. Monitoring should not be seen as a yearly audit task! It should be a continuous effort to assess if controls are still effective in mitigating the existing risks.
If a control deficiency is identified during monitoring, management should identify the cause of the control deficiency, determine the significance of the control deficiency, assign responsibility for taking corrective actions and set a reasonable timeframe for the action to be taken. For instance, when monthly items are continually highlighted as “unexplained differences,” management should do some investigation to determine the cause of differences rather than just reconcile them each month. Avoidable causes may be lack of employee training, system setup, unauthorized activity or an inadequate reconciliation procedure. This should then be documented and followed-up to see if the problem was solved. It establishes a learning cycle and feedback loop to continually improve the organization, rather than continually correct the same symptoms associated with control failures. Relevance of the internal control system in relation to change is also achieved through effective monitoring.

How the 5 COSO Components Interwork
The five components can be examined separately, but shouldn’t be considered as five distinct departments or checklists. These will be effective only when they interact. The culture and expectations are set within the control environment, the risks are identified within the control environment, control activities address the identified risks, relevant information is communicated to the right people within the control environment and monitoring determines if the controls continue to function. If any of the components is not working well, it does not affect the effectiveness of the others. For instance, a company may have very good payment approval systems in place but the management may routinely approve payments without providing justification, which may adversely impact control activities. Likewise, employees may not be notified about policy changes, or management may turn a blind eye to factors that could trigger a warning, which also could cause strong controls to be ineffective.
Especially for expansion-driven businesses, this holistic approach is crucial as growth and business expansion tend to bring in their own set of risks. This is where the initial invoice processing business might be able to handle it under direct supervision by the owner, but as the company grows and has multiple finance employees and processes hundreds of invoices each month, this might not be feasible. Growth might necessitate new access controls, segregation of duties, procedures, access control, documentation, and management reporting. COSO offers a way to consider changes in a systematic manner rather than adding controls when problems arise. Periodically, businesses can evaluate each of the five components and determine where any weaknesses exist, prioritize those risks that are the greatest in the business structure and enhance that structure as business functions become more complex.
Establishment of a COSO Based Control System in an SME
An SME can start to apply COSO principles by first stating their goals and determining the risks that stand in the way of accomplishing their goals. Management should then review the five components and see if the appropriate practice is in place in each of the components. The company can trace back who has cleared the transactions, kept records, managed cash, managed stock, administered systems and look at financial information. It should also put in place mechanisms for reconciling accounts, safeguarding assets, monitoring transactions that are atypical, handling user access and reporting issues. Smaller businesses will likely have fewer resources, so the controls should be considered as focusing in what areas failure to control could result in the most financial, operational, legal or reputational damage. The purpose is to establish sensible controls rather than unnecessary red tape that would give reasonable assurance and facilitate sound business operations.
An effective system based on COSO should be flexible enough to provide for adaptation to the organization. Management should review controls whenever a new technology is used, when the business enters a new market, a new supplier is used, when new employees are hired, when new products are added or when there are significant increases in transactions. Documentation is particularly useful because it cannot be relied upon to only be known by one employee. Training can be facilitated by written procedures, which can also help clear up responsibilities, aid management reviews, and serve as evidence in an audit. An organization that is audit ready is not just an organization with documents in place when the auditors come. It is an organization which can prove its controls are purposeful, executed regularly, recorded properly and assessed on a regular basis.
Conclusion
The COSO framework helps organizations establish a robust and resilient internal control system. The five components control environment, risk assessment, control activities, information and communication, and monitoring activities—can be used to assist organizations to manage risks, protect assets, enhance the reliability of their information and communication, enable compliance, and advance their objectives. All of this need not be copied by SMEs or growing businesses! Rather, management should define the most critical risks to the organization, and then create controls that are suitable for the size, resources and situations of the organization. Internal control is integrated into management activities and is not a burden because the weakness is monitored and corrected, the performance of controls is performed systematically, and information flows effectively as a result of leadership that demonstrates integrity. Therefore, a good COSO based system can provide more certainty for business leaders that the organization is resilient enough to address risk, adapt to change and be audit ready as it scales.
Get more well researched information about COSO Internal Control Framework here.



