Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The COSO internal control and enterprise risk management frameworks

COSO: Two Frameworks, and the New Generative AI Guidance

COSO publishes two different frameworks, and a great deal of confusion comes from people using the name as though it meant one thing.

The Internal Control — Integrated Framework and the Enterprise Risk Management framework answer different questions, are used by different people, and are cited in different places. Knowing which one someone means is the first step in any COSO conversation.

The two COSO frameworks

The Internal Control — Integrated Framework was originally issued in 1992 by the Committee of Sponsoring Organizations of the Treadway Commission and refreshed in 2013. It is built on five components and seventeen principles, and it is the framework the overwhelming majority of US public companies use to support their Sarbanes-Oxley section 404 assertions.

Two supersessions are worth recording, because old material still circulates: the 1992 framework and the 2006 guidance for smaller public companies were both superseded on 15 December 2014.

The Enterprise Risk Management frameworkIntegrating with Strategy and Performance, 2017 — is the other one. Its central argument is that risk belongs in strategy-setting and performance management rather than in a parallel process that produces a register. If your ERM function reports risks that never change a strategic decision, that framework is diagnosing you.

COSO frames internal control as having value beyond compliance and external financial reporting — helping an organisation articulate its purpose, set objectives and strategy, and grow with confidence and integrity in all types of information. That is a deliberately broader claim than “controls exist to satisfy the auditor”.

The supplemental guidance

The COSO frameworks and their supplemental guidance publications

The frameworks are stable; the guidance around them is where COSO responds to change. Three recent additions matter.

Internal control over sustainability reporting (2023). Supplemental guidance for achieving effective ICSR using the Internal Control — Integrated Framework, aimed at building trust in ESG and sustainability disclosures and in the decisions made from them.

This is the practical answer to a question ESG reporting raises and rarely resolves: sustainability numbers get published with none of the control discipline financial numbers receive. ICSR closes that gap using machinery finance teams already run.

Robotic process automation (2024). Internal control where a process is executed by a bot rather than a person — which breaks several assumptions baked into conventional control design, starting with segregation of duties.

Generative AI (2026). The newest publication, on achieving effective internal control over generative AI. If your organisation has deployed AI into processes that feed reporting, this is the current COSO position on controlling it.

Alongside these sit the Illustrative Tools for assessing whether a system of internal control meets the framework’s requirements, the ICEFR compendium for external financial reporting, and monitoring guidance dating from 2009.

Why COSO matters even outside the US

Two reasons, and neither is regulatory.

It is the assumed vocabulary. Auditors, investors and acquirers describe control environments in COSO’s terms — control environment, risk assessment, control activities, information and communication, monitoring. An organisation using its own taxonomy has to translate at every conversation.

It is principles-based, so it travels. The framework does not prescribe controls; it states principles a control system must achieve. That is why it has been adopted and adapted well beyond the jurisdiction it was written for.

What it is not is a certification. Nobody certifies you to COSO. You assert, and your auditor tests, that your internal control system is effective — using COSO as the criteria.

How COSO relates to other frameworks

Framework Relationship
SOX Section 404 requires management to assess internal control over financial reporting against a suitable framework. In practice that framework is COSO 2013, and COSO publishes transition guidance specifically for SOX compliance
ISO 31000 The international risk management standard. ISO 31000 is sector-neutral guidance; COSO ERM is written around strategy and performance and is more common in US financial reporting contexts. Running both means picking one as the method and the other as the vocabulary
COBIT 2019 IT governance specifically. COBIT’s monitor, evaluate and assess domain maps closely onto COSO’s monitoring component
ISO 37301 A certifiable compliance management system — the thing COSO deliberately is not. They coexist well: COSO as criteria, ISO 37301 as the auditable system

Where implementations go wrong

  • Confusing the two frameworks. An ERM programme built on the internal control framework produces controls where it needed strategic risk conversation, and vice versa.
  • Using superseded material. The 1992 framework and the 2006 smaller-company guidance both ended in December 2014, yet templates derived from them are still in circulation.
  • Treating the seventeen principles as a checklist. They are principles a system must achieve, and the evidence is what the system does, not that the principle is named in a document.
  • Leaving sustainability reporting outside internal control. ICSR exists precisely because that gap became visible.
  • Ignoring automation. RPA and generative AI change who performs a control; the 2024 and 2026 guidance exists because the old design assumptions do not hold.

Where to start

  1. Decide which framework you are using — internal control, ERM, or both for different purposes — and say so in writing.
  2. Check your source material is post-2013, and post-2014 for anything derived from the smaller-company guidance.
  3. Map the five components and seventeen principles to what you actually do, then look for the principles nothing supports.
  4. Use the Illustrative Tools for the effectiveness assessment rather than inventing a scoring scheme.
  5. Bring sustainability reporting into scope via ICSR if you publish ESG data.
  6. Read the generative AI guidance before your first AI-executed control, not after.

This guide reflects coso.org at 15 August 2026, on which the 2013 Internal Control — Integrated Framework and the 2017 ERM framework are current, with generative AI guidance published in 2026.

The COSO ERM & Internal Control Toolkit provides editable templates covering the control environment documentation, the principle-by-principle assessment, the risk and control matrices, the ERM artefacts and the effectiveness evaluation records.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.