Internal control is a process designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.
COSO Internal Control Integrated Framework (2013)
The 2013 framework retains the core five components of internal control but formalizes them into 17 explicit principles to ensure all components are present and functioning. 
       +-------------------------------------------+

       |            Control Environment            |
       +-------------------------------------------+

       |              Risk Assessment              |
       +-------------------------------------------+

       |             Control Activities            |
       +-------------------------------------------+

       |         Information & Communication       |
       +-------------------------------------------+

       |            Monitoring Activities          |
       +-------------------------------------------+

A. Control Environment
The control environment is the set of standards, processes, and structures that provide the basis for carrying out internal control across the organization.
  • Principle 1: Demonstrates commitment to integrity and ethical values.
  • Principle 2: Exercises oversight responsibility (the board demonstrates independence from management).
  • Principle 3: Establishes structure, authority, and responsibility.
  • Principle 4: Demonstrates commitment to competence (attracting, developing, and retaining individuals).
  • Principle 5: Enforces accountability. 
B. Risk Assessment
Risk assessment involves a dynamic and iterative process for identifying and assessing risks to the achievement of objectives.
  • Principle 6: Specifies suitable objectives with sufficient clarity to enable identification and assessment of risks.
  • Principle 7: Identifies and analyzes risks across the entity to determine how they should be managed.
  • Principle 8: Considers the potential for fraud when assessing risks.
  • Principle 9: Identifies and assesses changes that could significantly impact the system of internal control. 
C. Control Activities
Control activities are the actions established through policies and procedures that help ensure that management’s directives to mitigate risks are carried out. 
  • Principle 10: Selects and develops control activities that contribute to the mitigation of risks to acceptable levels.
  • Principle 11: Selects and develops general control activities over technology.
  • Principle 12: Deploys control activities through policies that establish what is expected and procedures that put policies into action. 
D. Information and Communication
Information is necessary for the entity to carry out internal control responsibilities. Communication is the continual, iterative process of providing, sharing, and obtaining necessary information. 
  • Principle 13: Obtains or generates and uses relevant, quality information to support the functioning of internal control.
  • Principle 14: Internally communicates information, including objectives and responsibilities for internal control.
  • Principle 15: Communicates with external parties regarding matters affecting the functioning of internal control. 
E. Monitoring Activities
Monitoring activities are evaluations used to ascertain whether each of the five components of internal control is present and functioning. [1]
  • Principle 16: Conducts ongoing and/or separate evaluations.
  • Principle 17: Evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action. [1, 2, 3, 4, 5]

Â