<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What is the COSO framework?"
title: "What Is the COSO Framework"
seoTitle: "What Is the COSO Framework? 5 Components, 17 Principles"
summary: "The COSO framework is the Internal Control Integrated Framework published by the Committee of Sponsoring Organizations of the Treadway Commission. It defines internal control through five components and seventeen principles, and it is the standard US public companies use to assess internal control over financial reporting under SOX. A separate COSO publication, the ERM framework, covers enterprise risk management."
publishedAt: "2026-08-18"
keywords:
  - "COSO framework"
  - "COSO enterprise risk management"
  - "ERM COSO framework"
  - "internal control framework"
  - "COSO 5 components"
pillar: "Beyond SOC 2"
faqs:
  - question: "What are the five components of the COSO framework?"
    answer: "Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities. The 2013 update added seventeen principles distributed across those five, which is what made the framework assessable rather than merely descriptive."
  - question: "What is the difference between COSO Internal Control and COSO ERM?"
    answer: "They are two separate frameworks from the same body. Internal Control Integrated Framework covers internal control, principally over financial reporting, and underpins SOX 404. Enterprise Risk Management Integrating with Strategy and Performance covers risk across the organisation and is structured around five components and twenty principles."
  - question: "Does SOC 2 use COSO?"
    answer: "Yes, more than most people realise. The SOC 2 Common Criteria are organised around the seventeen COSO principles. CC1 through CC5 map directly onto the five COSO components, which is why SOC 2 asks about governance and tone at the top rather than only about technical controls."
---

## What is the COSO framework?

The COSO framework is the **Internal Control Integrated Framework**, published by the Committee of Sponsoring Organizations of the Treadway Commission. It defines internal control through **five components and seventeen principles**, and it is the framework US public companies use to assess internal control over financial reporting under SOX 404. A separate COSO publication covers enterprise risk management, and the two are routinely conflated.

### The five components

| Component | What it covers |
|---|---|
| **Control Environment** | Tone at the top, integrity, board oversight, accountability structures |
| **Risk Assessment** | Objectives, identifying and analysing risks to meeting them, fraud risk |
| **Control Activities** | The controls themselves, including over technology |
| **Information and Communication** | Relevant information, communicated internally and externally |
| **Monitoring Activities** | Ongoing and separate evaluations, and reporting deficiencies |

The **2013 update** added seventeen principles distributed across those five. That is the change that made COSO assessable: a principle can be present and functioning, or not, whereas a component alone is too broad to test.

## COSO Internal Control and COSO ERM

Two frameworks, one body, different jobs.

| | Internal Control | ERM |
|---|---|---|
| Full name | Internal Control Integrated Framework | Enterprise Risk Management: Integrating with Strategy and Performance |
| Scope | Internal control, principally financial reporting | Risk across the enterprise, tied to strategy |
| Structure | 5 components, 17 principles | 5 components, 20 principles |
| Used for | SOX 404 assessment | Enterprise risk programmes |

If someone says "the COSO framework" without qualification, they almost always mean Internal Control.

## Why a SaaS company doing SOC 2 should care

Because **SOC 2's Common Criteria are built on COSO's seventeen principles.** CC1 through CC5 map directly onto the five components:

- CC1 → Control Environment
- CC2 → Information and Communication
- CC3 → Risk Assessment
- CC4 → Monitoring Activities
- CC5 → Control Activities

This is why a SOC 2 audit asks about board oversight, organisational structure, and how you communicate policy, when a team expecting a purely technical audit finds those questions surprising. They are COSO questions inherited wholesale.

The practical consequence: CC1 through CC5 are the criteria least amenable to automation, because they are about governance rather than configuration. Evidence there is org charts, board minutes, policy acknowledgements, and role definitions. See [what are the 4 components of GRC](/resources/answers/what-are-the-4-components-of-grc) for the adjacent model.
