The COSO Financial Controls Framework: 1992 version

This page describes the original, 1992 COSO Financial Controls Framework. See also the
2004 Enterprise Risk Management (ERM) COSO Framework

The original COSO framework is outlined in a document: 1992 COSO Report: Internal
Control – An Integrated Framework.
This document identifies what the commission believed to be the fundamental and
essential objectives of any business or government entity:

• economy and efficiency of operations, including safeguarding of assets and
achievement of desired outcomes;
• reliability of financial and management reports; and
• compliance with laws and regulations.

Describes a unified approach for evaluation of the internal control systems that
management has designed to:

• provide reasonable assurance of achieving corporate mission, objectives, goals
and desired outcome,
• while adhering to laws and regulations
• allow the company to accurately report successes and outcomes to the public and
interested third parties.

• serves as a common basis for managements, directors, regulators, academics and
others to better understand enterprise risk management, its benefits and
limitations, and to effectively communicate about enterprise risk management

Control Components
The COSO Cube
The original COSO framework contains five control components needed to help assure
sound business objectives. The control components are:

• Control Environment.
• Risk Assessment.
• Control Activities.
• Information and Communication.
• Monitoring.

More specifically, the thought process behind these five components was that they would
work together to support efforts to achieve an organization's mission, strategies and
related business objectives. All five components would need to be in place to achieve an
"effective" internal control system.

FAQs Have questions? Click here to get answers to the following Frequently Asked Questions: FAQs for COSO's Enterprise Risk Management — Integrated Framework A. risk tolerance.essential enterprise risk management components. Control activities 7. Objective setting 3. Internal control environment 2. What is the framework and how do I get it? 1. discusses key ERM principles and concepts. What is in the framework? 2. Click here to view the Executive Summary of the 2004 COSO Document: Enterprise Risk Management (ERM) COSO Framework. and provides clear direction and guidance for enterprise risk management. Event identification 4. Is there such a thing as being overly conscientious about risk? C. Risk assessment 5. The guidance introduces an enterprise-wide approach to risk management as well as concepts such as: risk appetite. Monitoring. Information and communication 8. How might the framework assist organizations in structuring their entities to best manage exposure to risk? 3. Risk response 6. suggests a common ERM language. The new COSO framework consists of eight components: 1. View the New COSO Cube Overview The new Enterprise Risk Management (ERM) COSO framework emphasizes the importance of identifying and managing risks across the enterprise. The three new components of the COSO framework are Objective setting. Where can I find the framework? B. portfolio view. Why is this a framework that organizations should support? 1. Event identification. What are some of the key concepts established in this framework? . and Risk response. This framework is now being used by organizations around the world to design and implement effective ERM processes. What limitations of existing enterprise risk management models prompted creation of a new framework? 2.

Are you replacing the Internal Control Framework with the Enterprise Risk Management Framework? 2. and developing mechanisms to manage related risks. What is the role of internal auditors in enterprise risk management? How will this framework help them? 4. What is the relationship between effective enterprise risk management and improved financial reporting and transparency? 4. How do people in an organization intersect with this framework? 1. How might organizations view the framework in the context of their Sarbanes-Oxley 404 compliance process? 1.1. . What does the new framework offer clients that are focusing on internal control? E. If you have good internal control. and efficiently and effectively deploys resources in pursuit of the entity’s objectives. How does an organization determine the right amount of risk for the value it is trying to create for stakeholders and how should it communicate its risk policy to stakeholders? 3. With the significant amount of implementation efforts companies are currently undertaking for Sarbanes-Oxley compliance and adoption of new accounting standards. What is the role of the board in enterprise risk management? How does this framework help them? 2. Who are the potential implementers of the framework? Why the focus on Enterprise Risk Management? Here's what COSO says: Value is maximized when management sets strategy and objectives to strike an optimal balance between growth and return goals and related risks. How does this framework relate to COSO's Internal Control Framework? 1. setting related objectives. isn’t that a way of managing risk? 4. What makes this different from the internal control framework? How does it relate to Sarbanes-Oxley reporting? F. What is the role of the CFO and others in the financial management organization in enterprise risk management? How will this framework help them? 3. Enterprise risk management encompasses: • Aligning risk appetite and strategy – Management considers the entity’s risk appetite in evaluating strategic alternatives. Is this intended for private organizations? Is there any organization this is not intended for? D. What is the relationship between technology controls and effective enterprise risk management? 3. What is the difference between risk appetite and risk tolerance? 2. why should companies be motivated to implement enterprise risk management? 2.

These capabilities inherent in enterprise risk management help management achieve the entity’s performance and profitability targets and prevent loss of resources. and enterprise risk management facilitates effective response to the interrelated impacts. reduction. • Reducing operational surprises and losses – Entities gain enhanced capability to identify potential events and establish responses. • Seizing opportunities – By considering a full range of potential events. • Enhancing risk response decisions – Enterprise risk management provides the rigor to identify and select among alternative risk responses – risk avoidance. reducing surprises and associated costs or losses. In sum. . sharing. Enterprise risk management helps ensure effective reporting and compliance with laws and regulations. management is positioned to identify and proactively realize opportunities. and helps avoid damage to the entity’s reputation and associated consequences. enterprise risk management helps an entity get to where it wants to go and avoid pitfalls and surprises along the way. • Identifying and managing multiple and cross-enterprise risks – Every enterprise faces a myriad of risks affecting different parts of the organization. • Improving deployment of capital – Obtaining robust risk information allows management to effectively assess overall capital needs and enhance capital allocation. and acceptance. and integrated responses to multiple risks.

