CPA (BAR) • BUDGETING, PLANNING, AND CONTROL

Evaluate Internal Control Components

A comprehensive framework for assessing the five interrelated components of internal control under the COSO model.

Historical Context & Motivation

The evaluation of internal control components sits at the intersection of corporate governance, risk management, and financial reporting integrity. Long before formal frameworks existed, organizations relied on ad hoc checks and balances—segregation of duties within counting houses, dual-key safes, and supervisory review—to safeguard assets and ensure the reliability of records. The explosive growth of publicly traded corporations in the twentieth century, however, exposed the inadequacy of informal arrangements. A series of high-profile frauds and financial collapses underscored that without a systematic method for evaluating controls, stakeholders could not rely on financial statements, and boards could not fulfill their oversight responsibilities.

1977
Foreign Corrupt Practices Act (FCPA)
The U.S. Congress enacted the FCPA, which for the first time required public companies to maintain adequate systems of internal accounting controls, marking the beginning of legally mandated internal control evaluation.
1992
COSO Internal Control — Integrated Framework
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) published its landmark framework, defining five interrelated components of internal control that remain the global standard for evaluation.
2002
Sarbanes-Oxley Act (SOX)
In the wake of the Enron and WorldCom scandals, SOX Section 404 required management and external auditors to formally evaluate and report on the effectiveness of internal controls over financial reporting.
2013
COSO Framework Update
COSO updated its 1992 framework to include 17 explicit principles mapped across the five components, providing granular guidance for evaluating whether each component is present and functioning.
2023–Present
Technology-Driven Controls
Organizations increasingly embed automated controls, continuous monitoring, and data analytics into their internal control systems, requiring evaluators to assess both manual and IT-dependent controls within the COSO framework.

The central question this lesson addresses is deceptively straightforward: How does a CPA systematically evaluate whether each of the five COSO internal control components is properly designed, implemented, and operating effectively? Answering this question requires understanding both the conceptual architecture of the COSO framework and the practical procedures that auditors and management employ to assess control effectiveness across complex organizations.

Core Principles & Definitions

Under the COSO Internal Control — Integrated Framework, internal control is defined as a process effected by an entity's board of directors, management, and other personnel that is designed to provide reasonable assurance regarding the achievement of objectives in three categories: effectiveness and efficiency of operations, reliability of financial reporting, and compliance with applicable laws and regulations. The framework decomposes this process into five interrelated components, each of which must be both present (properly designed and implemented) and functioning (operating as intended) for the overall system of internal control to be judged effective.

1

Control Environment

The set of standards, processes, and structures that provide the basis for carrying out internal control across the organization. It encompasses the tone at the top, ethical values, board oversight, organizational structure, and human resource policies.
2

Risk Assessment

The dynamic process by which management identifies and analyzes risks to the achievement of objectives, forming the basis for determining how risks should be managed. This includes assessing the likelihood of fraud.
3

Control Activities

The actions established through policies and procedures that help ensure management's directives to mitigate risks are carried out. Examples include approvals, authorizations, reconciliations, and segregation of duties.
4

Information & Communication

The processes that support the identification, capture, and exchange of information in a form and timeframe that enable people to carry out their internal control responsibilities—both internally and with external parties.
5

Monitoring Activities

Ongoing evaluations, separate evaluations, or some combination of both, used to ascertain whether each of the five components is present and functioning. Deficiencies are communicated timely to parties responsible for corrective action.
KEY TAKEAWAY
Think of internal control like the structural integrity of a building. The control environment is the foundation; risk assessment is the engineering analysis that identifies stresses; control activities are the steel beams and reinforcements; information and communication is the electrical and plumbing network that connects every floor; and monitoring is the regular inspection process. Remove or weaken any one element, and the entire structure is compromised—even if the other four appear sound.

Visual Explanation — The COSO Cube & Evaluation Flow

The diagram above illustrates the COSO framework's architecture. The Control Environment sits at the foundation, supporting the three operational components (Risk Assessment, Control Activities, and Information & Communication), while Monitoring Activities spans across all components to ensure ongoing effectiveness.

The visual representation reinforces a critical evaluation principle: the five components do not operate in isolation. The control environment permeates and influences every other component, much as a building's foundation determines the integrity of every story above it. When evaluating internal controls, a CPA must assess not only whether each component independently satisfies its associated principles but also whether the components interact cohesively. A robust set of control activities, for instance, cannot compensate for a dysfunctional control environment characterized by management override and indifference to ethical standards. Similarly, monitoring activities must be calibrated to the risks identified in the risk assessment process, creating a feedback loop that enables continuous improvement.

How the Evaluation Works — The 17-Principle Framework

The 2013 COSO update introduced 17 principles that codify the fundamental concepts associated with each component. These principles serve as the operational criteria against which evaluators determine whether a component is present and functioning. Each principle, in turn, is supported by points of focus—illustrative characteristics that guide the evaluator in assessing whether a principle is met. While points of focus are not themselves required, they provide concrete attributes that evidence the presence and functioning of a principle. The evaluation methodology proceeds through a structured sequence: identify relevant principles for each component, gather evidence that each principle is both designed into the system and operating as intended, identify deficiencies where principles are not satisfied, and aggregate deficiencies to determine whether a component-level or system-level weakness exists.

Mapping of COSO's 17 Principles to the Five Internal Control Components
ComponentPrinciples (Numbers)Key Evaluation Focus Areas
Control Environment1 – 5Integrity & ethical values; board independence & oversight; management structure; competence standards; accountability mechanisms
Risk Assessment6 – 9Suitable objectives specification; risk identification & analysis; fraud risk assessment; significant change identification
Control Activities10 – 12Selection & development of controls; technology general controls; deployment through policies & procedures
Information & Communication13 – 15Relevant quality information generation; internal communication channels; external communication with stakeholders
Monitoring Activities16 – 17Ongoing and/or separate evaluations; evaluation & communication of deficiencies to appropriate parties

The Dual Assessment: Present & Functioning

The evaluation framework requires a dual assessment for each principle. First, the evaluator determines whether the principle is present—meaning the control has been designed and implemented in the system. A control that exists only in a policy manual but has never been put into practice is not present. Second, the evaluator assesses whether the principle is functioning—meaning it continues to operate as designed over the evaluation period. A bank reconciliation procedure that was performed in January but abandoned by March fails the functioning test. Both conditions must be satisfied for the principle to be considered effective, and all relevant principles within a component must be effective for the component itself to be judged effective.

⚠️ CPA Exam Alert
On the BAR section of the CPA exam, you may encounter scenarios requiring you to determine whether a specific control deficiency constitutes a deficiency, a significant deficiency, or a material weakness. Remember that severity is assessed based on the magnitude and likelihood of potential misstatement, not just on the type of principle affected.

Detailed Evaluation Process & Deficiency Classification

This flowchart traces the evaluation process from principle selection through evidence gathering, the present-and-functioning assessment, deficiency identification, severity classification, and ultimately the aggregation into a component-level and system-level conclusion. Note how deficiencies are classified into three tiers based on the magnitude and likelihood of potential misstatement.

Deficiency Severity Classification

When an evaluator determines that a principle is not satisfied, the resulting gap is classified according to its severity. A control deficiency exists when the design or operation of a control does not allow management or employees, in the normal course of performing their assigned functions, to prevent or detect misstatements on a timely basis. A significant deficiency is a deficiency, or combination of deficiencies, that is less severe than a material weakness yet important enough to merit attention by those charged with governance. A material weakness is a deficiency, or combination of deficiencies, in internal control such that there is a reasonable possibility that a material misstatement of the entity's financial statements will not be prevented or detected on a timely basis. The presence of even one material weakness means that the internal control system, taken as a whole, cannot be assessed as effective.

Deficiency Severity Spectrum
Deficiency
Significant Deficiency
Material Weakness
Less SevereMost Severe

Worked Example — Evaluating Controls at Apex Manufacturing

Consider a mid-size manufacturing company, Apex Manufacturing Inc., with $250 million in annual revenue. You are the CPA performing the annual internal control evaluation under COSO. During your fieldwork, you have identified the following conditions across the five components. Walk through the evaluation systematically.

Evaluating Apex Manufacturing's Internal Controls
1
Step 1 — Evaluate the Control Environment (Principles 1–5)You review board minutes, the code of conduct, and HR policies. The board has an independent audit committee that meets quarterly (Principle 2 satisfied). Management has a written code of ethics distributed to all employees, and ethics hotline reports show consistent follow-up (Principle 1 satisfied). However, you observe that the CFO has been performing accounts payable functions due to staff shortages, creating a segregation of duties violation. This raises concerns about Principle 3 (management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities). You note this as a potential deficiency affecting the control environment.
Potential deficiency identified: CFO performing incompatible duties (Principle 3)
2
Step 2 — Evaluate Risk Assessment (Principles 6–9)Apex has a documented risk assessment process that is updated annually and specifically addresses fraud risk, including management override scenarios (Principles 6–9). However, you discover that Apex recently acquired a small subsidiary six months ago, and management did not update its risk assessment to incorporate the new entity's operations, systems, or regulatory environment. This represents a failure of Principle 9 (the organization identifies and assesses changes that could significantly impact the system of internal control).
Deficiency: Risk assessment not updated for significant acquisition (Principle 9)
3
Step 3 — Evaluate Control Activities (Principles 10–12)You test 30 purchase transactions for proper authorization and three-way matching (purchase order, receiving report, vendor invoice). You find that 28 of 30 transactions were properly authorized and matched, and the two exceptions involved immaterial amounts with subsequent correction. The general IT controls for the ERP system show appropriate access controls, change management, and backup procedures (Principle 11). Policies and procedures are documented in the company's internal wiki and updated semi-annually (Principle 12).
Control activities: Operating effectively; minor exceptions noted but not indicative of systemic failure
4
Step 4 — Evaluate Information & Communication and Monitoring (Principles 13–17)The information system produces timely financial reports, and communication channels between departments appear functional (Principles 13–15). For monitoring, Apex's internal audit department conducts quarterly reviews and reports directly to the audit committee (Principle 16). However, you note that the internal audit department has not been staffed to cover the newly acquired subsidiary. Identified deficiencies from the prior year have documented remediation plans, though two items remain outstanding beyond their target dates (Principle 17).
Monitoring partially effective: Internal audit does not yet cover the new subsidiary; remediation delays noted
5
Step 5 — Aggregate and Classify DeficienciesYou now aggregate the identified deficiencies: (1) CFO performing AP duties—this impairs the segregation of duties at a senior management level, creating a reasonable possibility that a material misstatement could occur and not be detected. Given the CFO's position and ability to override controls, this alone could constitute a material weakness. (2) Failure to update risk assessment for the acquisition—a significant deficiency because the unassessed risks of the subsidiary could lead to material errors, though the subsidiary is relatively small. (3) Incomplete monitoring coverage and remediation delays—a deficiency that compounds the other issues but is not independently at the material weakness level.
Conclusion: Internal control over financial reporting is NOT effective due to the material weakness in the control environment. Additional significant deficiency and deficiency are reported to those charged with governance.

Strengths & Limitations of the COSO Evaluation Framework

Comparison of strengths and limitations of the COSO Internal Control Framework as an evaluation tool
StrengthsLimitations
Provides a universally recognized, structured methodology accepted by the SEC, PCAOB, and international standard-settersInherently limited to providing only reasonable (not absolute) assurance due to human judgment, collusion, and management override
The 17-principle structure provides granular, actionable criteria that reduce subjectivity in the evaluationEvaluating 'soft' components like control environment and tone at the top involves significant professional judgment and can be subjective
Scalable across entities of varying size and complexity, from small private companies to multinational corporationsSmaller entities may lack the resources and personnel to fully implement all 17 principles without adaptation
Integrates risk assessment and fraud considerations directly into the evaluation, promoting a risk-based approachPoint-in-time evaluations may not capture emerging risks or controls that deteriorate between assessment periods
Encourages a holistic view—deficiencies are aggregated across components to determine system-level effectivenessThe framework does not prescribe specific controls, leaving design choices to management, which can lead to inconsistent implementation
KEY TAKEAWAY
The COSO framework is to internal control evaluation what a diagnostic protocol is to medicine: it provides a systematic, evidence-based methodology for identifying problems, but the ultimate diagnosis still depends on the practitioner's professional judgment. Just as two physicians examining the same patient might weigh symptoms differently, two CPAs might classify the same deficiency at different severity levels. The framework constrains—but does not eliminate—this variability, which is why professional skepticism and thorough documentation of the evaluator's rationale are essential.

Connection to Enterprise Risk Management & Integrated Auditing

The COSO Internal Control — Integrated Framework is one layer within a broader governance architecture. In 2004 (updated 2017), COSO published the Enterprise Risk Management (ERM) — Integrating with Strategy and Performance framework, which extends the internal control model into strategic planning and performance management. While the internal control framework focuses on reasonable assurance regarding operations, reporting, and compliance objectives, ERM addresses how an entity creates, preserves, and realizes value across its full spectrum of strategic risks. Understanding how internal control evaluation fits within ERM is critical for CPAs who advise management on governance maturity.

Comparison of COSO Internal Control and Enterprise Risk Management frameworks
DimensionInternal Control (COSO IC)Enterprise Risk Management (COSO ERM)
Primary FocusReliability of financial reporting, compliance, operational effectivenessStrategy setting, performance management, and enterprise-wide risk
Components5 components, 17 principles5 interrelated components with 20 principles
ScopeNarrower—controls over specific assertions and processesBroader—risk appetite, strategy alignment, portfolio risk view
Assurance LevelReasonable assurance on three objective categoriesIntegrates risk considerations into value creation and preservation
CPA RoleEvaluate and report on ICFR effectiveness (SOX 404)Advisory role; no mandatory reporting requirement under SOX

As organizations evolve, the distinction between internal control evaluation and ERM assessment may continue to narrow. Integrated auditing approaches—where the external auditor simultaneously evaluates financial statement assertions and internal controls—already reflect this convergence. For CPA candidates, the critical forward-looking insight is that mastering the evaluation of internal control components today provides the conceptual foundation for the broader risk and governance advisory services that define the modern accounting profession.

Practice Problems

PROBLEM 1CONCEPTUAL
Under the COSO Internal Control — Integrated Framework, what does it mean for a principle to be both 'present' and 'functioning'? Why must both conditions be met for the associated component to be deemed effective?
PROBLEM 2BASIC CALCULATION
An auditor tests a sample of 50 cash disbursement transactions to determine whether proper authorization controls are functioning. The auditor identifies 8 transactions that lacked the required approval signature. Assuming the materiality threshold for this assertion is $500,000 and the total dollar value of unauthorized transactions is $420,000, classify this deficiency and explain your reasoning.
PROBLEM 3INTERMEDIATE
TechStar Corporation recently transitioned its financial reporting system from an on-premises ERP to a cloud-based SaaS platform. During the COSO evaluation, you discover the following: (a) IT general controls for the new system have not been formally documented; (b) user access reviews have not been conducted since migration; (c) management updated its risk assessment to acknowledge the system change. Which COSO components and principles are affected? How would you assess the deficiencies?
PROBLEM 4APPLIED
You are evaluating internal controls at a regional hospital network with $800 million in annual revenue. During your evaluation of the Control Environment, you learn: (1) the CEO publicly pressured the CFO to 'make the numbers work' during an all-hands meeting; (2) the board of directors lacks an independent audit committee—three of four audit committee members are hospital system executives; (3) the entity has a formal code of conduct but has not enforced it in three documented cases of ethics violations. Apply Principles 1–3 to evaluate the Control Environment component.
PROBLEM 5CRITICAL THINKING
A small private company with 35 employees argues that it cannot fully implement all five COSO components because it lacks the personnel for complete segregation of duties, a formal internal audit function, and an independent board of directors. Does the COSO framework accommodate smaller entities? How should a CPA evaluate internal controls in this environment, and what compensating controls might substitute for the missing structural elements? Discuss the tension between framework rigor and practical scalability.

Lesson Summary

Evaluating internal control components requires a systematic application of the COSO Internal Control — Integrated Framework, which decomposes internal control into five interrelated components: Control Environment (the foundational tone and structure), Risk Assessment (identifying and analyzing threats to objectives), Control Activities (the policies and procedures that mitigate risks), Information & Communication (the flow of relevant data internally and externally), and Monitoring Activities (the ongoing and separate evaluations that ensure the other four components continue to function). The 2013 framework's 17 principles provide the granular criteria for assessment, requiring each to be both present and functioning.

Deficiencies are classified by severity into control deficiencies, significant deficiencies, and material weaknesses, based on the magnitude and likelihood of potential misstatement. A single material weakness renders the entire internal control system ineffective. The evaluation process integrates with SOX Section 404 requirements for public companies and scales to accommodate entities of all sizes through compensating controls and alternative implementation methods. Mastering this framework equips CPA candidates with the structured analytical approach needed for both the BAR exam and professional practice in audit, advisory, and governance roles.

Varsity Tutors • CPA (BAR) • Evaluate Internal Control Components