.png)
.png)
.png)
COSO (Committee of Sponsoring Organizations)
Framework Name
COSO Internal Control – Integrated Framework (2013) and COSO Enterprise Risk Management Framework (2017)
Type
Voluntary, though functionally near-mandatory for US public companies (explained below)
Region / Jurisdiction
Global (originated in the US)
Enforcing Body / Certifying Party
Committee of Sponsoring Organizations of the Treadway Commission (COSO), a joint initiative of five professional accounting and auditing organizations. There is no certification against COSO, external auditors assess a company's internal controls using it as the reference framework
Penalty / Consequence of Non-Compliance
No penalty tied to COSO itself, since it's not a law. But COSO is the framework nearly every US public company uses to satisfy its actual legal obligation under Sarbanes-Oxley Section 404, so the real consequence flows through SOX: failing to maintain effective internal controls can mean restated financials, SEC enforcement action, and reputational damage
What It Is & Why It Matters
COSO actually refers to two related frameworks. The Internal Control – Integrated Framework defines what a well-controlled organization looks like, built around five components and 17 principles covering things like control environment, risk assessment, and monitoring. The separate Enterprise Risk Management framework, updated in 2017, goes further, integrating risk management directly into how a company sets and pursues strategy, rather than treating risk as a parallel, disconnected process.
The Internal Control Framework matters because of its close relationship with SOX. Sarbanes-Oxley requires public companies to assess and report on the effectiveness of their internal controls over financial reporting, but the law itself doesn't specify which framework to use. COSO became the de facto answer almost immediately, and today it's used by the overwhelming majority of public companies for exactly that purpose. So while adopting COSO is technically a choice, in practice it's the choice nearly everyone makes because it's what auditors expect to see. The separate ERM framework has a broader audience, used well beyond public companies by any organization wanting to connect risk management to actual business strategy rather than treat it as a compliance checkbox.
Who Needs It
- You are a US public company that needs a recognized framework to satisfy SOX Section 404 internal control reporting requirements
- Your external auditor is assessing your internal controls and expects them mapped against a standard framework
- You want to build or mature an enterprise risk management program that connects risk directly to strategy and performance, not just controls
- You are outside the US but operate in a market where regulators increasingly point to COSO as the international standard, as some have begun doing explicitly