Screenata

Beyond SOC 2

What is the COSO framework?

August 18, 20262 min read

What is the COSO framework?

The COSO framework is the Internal Control Integrated Framework, published by the Committee of Sponsoring Organizations of the Treadway Commission. It defines internal control through five components and seventeen principles, and it is the framework US public companies use to assess internal control over financial reporting under SOX 404. A separate COSO publication covers enterprise risk management, and the two are routinely conflated.

The five components

ComponentWhat it covers
Control EnvironmentTone at the top, integrity, board oversight, accountability structures
Risk AssessmentObjectives, identifying and analysing risks to meeting them, fraud risk
Control ActivitiesThe controls themselves, including over technology
Information and CommunicationRelevant information, communicated internally and externally
Monitoring ActivitiesOngoing and separate evaluations, and reporting deficiencies

The 2013 update added seventeen principles distributed across those five. That is the change that made COSO assessable: a principle can be present and functioning, or not, whereas a component alone is too broad to test.

COSO Internal Control and COSO ERM

Two frameworks, one body, different jobs.

Internal ControlERM
Full nameInternal Control Integrated FrameworkEnterprise Risk Management: Integrating with Strategy and Performance
ScopeInternal control, principally financial reportingRisk across the enterprise, tied to strategy
Structure5 components, 17 principles5 components, 20 principles
Used forSOX 404 assessmentEnterprise risk programmes

If someone says "the COSO framework" without qualification, they almost always mean Internal Control.

Why a SaaS company doing SOC 2 should care

Because SOC 2's Common Criteria are built on COSO's seventeen principles. CC1 through CC5 map directly onto the five components:

  • CC1 → Control Environment
  • CC2 → Information and Communication
  • CC3 → Risk Assessment
  • CC4 → Monitoring Activities
  • CC5 → Control Activities

This is why a SOC 2 audit asks about board oversight, organisational structure, and how you communicate policy, when a team expecting a purely technical audit finds those questions surprising. They are COSO questions inherited wholesale.

The practical consequence: CC1 through CC5 are the criteria least amenable to automation, because they are about governance rather than configuration. Evidence there is org charts, board minutes, policy acknowledgements, and role definitions. See what are the 4 components of GRC for the adjacent model.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.