The Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control Integrated Framework serves as the globally recognized standard for designing, implementing, and evaluating internal control environments. The framework defines internal control as a process effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.
The COSO architecture is structured across 5 integrated components supported by 17 explicit principles:
                  ┌────────────────────────────────────────┐
                  │        COSO INTEGRATED PYRAMID         │
                  └───────────────────┬────────────────────┘
                                      ▼
                  ┌────────────────────────────────────────┐
                  │ 1. CONTROL ENVIRONMENT (The Base)     │
                  │ 2. RISK ASSESSMENT (Objective Setting) │
                  │ 3. CONTROL ACTIVITIES (Hard Controls)  │
                  │ 4. INFORMATION & COMM. (Data Lineage) │
                  │ 5. MONITORING ACTIVITIES (Governance)  │
                  └────────────────────────────────────────┘

  1. Control Environment: The foundational set of standards, processes, and structures that establish the tone at the top regarding control importance. It covers corporate integrity, ethical values, board oversight independence, individual accountability, and talent retention strategies.
  2. Risk Assessment: An iterative process for identifying and assessing risks that could disrupt the achievement of organizational objectives. It requires defining clear risk thresholds, identifying potential process threats, and evaluating vulnerabilities to internal fraud.
  3. Control Activities: The policies, procedures, and system configurations implemented to ensure management directives to mitigate risks are executed. This component includes mechanisms like segregation of duties, physical security boundaries, and automated application validation checks.
  4. Information and Communication: The data pipelines required to capture, process, and share high-quality information to support the internal control framework, ensuring clear communication lines across all organizational levels.
  5. Monitoring Activities: Ongoing or separate evaluations used to verify that each of the five internal control components remains present and functioning reliably across daily business operations.