Beyond SOC 2
What is the COSO framework?
What is the COSO framework?
The COSO framework is the Internal Control Integrated Framework, published by the Committee of Sponsoring Organizations of the Treadway Commission. It defines internal control through five components and seventeen principles, and it is the framework US public companies use to assess internal control over financial reporting under SOX 404. A separate COSO publication covers enterprise risk management, and the two are routinely conflated.
The five components
| Component | What it covers |
|---|---|
| Control Environment | Tone at the top, integrity, board oversight, accountability structures |
| Risk Assessment | Objectives, identifying and analysing risks to meeting them, fraud risk |
| Control Activities | The controls themselves, including over technology |
| Information and Communication | Relevant information, communicated internally and externally |
| Monitoring Activities | Ongoing and separate evaluations, and reporting deficiencies |
The 2013 update added seventeen principles distributed across those five. That is the change that made COSO assessable: a principle can be present and functioning, or not, whereas a component alone is too broad to test.
COSO Internal Control and COSO ERM
Two frameworks, one body, different jobs.
| Internal Control | ERM | |
|---|---|---|
| Full name | Internal Control Integrated Framework | Enterprise Risk Management: Integrating with Strategy and Performance |
| Scope | Internal control, principally financial reporting | Risk across the enterprise, tied to strategy |
| Structure | 5 components, 17 principles | 5 components, 20 principles |
| Used for | SOX 404 assessment | Enterprise risk programmes |
If someone says "the COSO framework" without qualification, they almost always mean Internal Control.
Why a SaaS company doing SOC 2 should care
Because SOC 2's Common Criteria are built on COSO's seventeen principles. CC1 through CC5 map directly onto the five components:
- CC1 → Control Environment
- CC2 → Information and Communication
- CC3 → Risk Assessment
- CC4 → Monitoring Activities
- CC5 → Control Activities
This is why a SOC 2 audit asks about board oversight, organisational structure, and how you communicate policy, when a team expecting a purely technical audit finds those questions surprising. They are COSO questions inherited wholesale.
The practical consequence: CC1 through CC5 are the criteria least amenable to automation, because they are about governance rather than configuration. Evidence there is org charts, board minutes, policy acknowledgements, and role definitions. See what are the 4 components of GRC for the adjacent model.