The COSO 17 principles are what turned the internal control framework from a concept into something you can assess. The 2013 revision codified them — five components, seventeen principles beneath them — and set a test: for internal control to be effective, each component and each relevant principle must be present and functioning, and the components must operate together.
This guide lists the seventeen as COSO frames them, explains the present-and-functioning test and what a major deficiency is, and covers where assessments go wrong.

The COSO 17 principles, by component
Control environment — principles 1 to 5
- The organization demonstrates a commitment to integrity and ethical values.
- The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
- Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
- The organization demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
- The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives.
Risk assessment — principles 6 to 9
- The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
- The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.
- The organization considers the potential for fraud in assessing risks to the achievement of objectives.
- The organization identifies and assesses changes that could significantly impact the system of internal control.
Control activities — principles 10 to 12
- The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
- The organization selects and develops general control activities over technology to support the achievement of objectives.
- The organization deploys control activities through policies that establish what is expected and in procedures that put policies into action.
Information and communication — principles 13 to 15
- The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.
- The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.
- The organization communicates with external parties about matters affecting the functioning of internal control.
Monitoring activities — principles 16 and 17
- The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
- The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.
The test the COSO 17 principles have to pass
The 2013 framework’s test has two halves. Present means the component and its relevant principles exist in the design and implementation of the system of internal control. Functioning means they continue to exist in the conduct of the system. Both, for every relevant principle, plus the components operating together in an integrated manner.
That is what makes a principle-level assessment unavoidable. A major deficiency is a deficiency, or combination of deficiencies, that severely reduces the likelihood that the entity can achieve its objectives — and it exists when management determines that a component and one or more relevant principles are not present and functioning, or that the components are not operating together. In other words, a single principle you cannot evidence is not a rounding error; it puts the effectiveness conclusion at risk.
COSO supports the judgment with points of focus — example characteristics for each of the COSO 17 principles. They are aids, not a checklist: you are not required to evidence every point of focus, and management can conclude a principle is present and functioning by other means. Treating them as mandatory line items is what turns a COSO assessment into a paperwork exercise.
Where COSO 17 principles assessments go wrong
Four patterns account for most of the rework in a COSO 17 principles assessment.
Mapping controls to components instead of principles. The components are too coarse to test. A control matrix that maps to “Control Environment” tells you nothing about whether principle 5 — accountability for internal control responsibilities — is functioning.
Ignoring principle 8. Fraud risk became its own principle in 2013, and assessments carried over from the 1992 framework frequently have no fraud risk assessment at the assertion or transaction level to point at.
Under-evidencing principle 11. General technology controls sit in their own principle, and in most organizations the evidence is held by IT rather than finance. If nobody has asked IT for access reviews, change management records and job monitoring, principle 11 is not evidenced.
Assuming every principle is relevant. COSO’s test is that each relevant principle is present and functioning. In rare circumstances a principle may not be relevant — but that determination has to be documented and supported, not assumed by omission.
Where the COSO 17 principles are used
The COSO 17 principles arrived with the 2013 refresh, and the framework is the reference point US issuers use when management assesses internal control over financial reporting. That is why the principles show up in SOX programmes: management’s assessment has to conclude on an effective system of internal control, and the framework defines what effective means. Our guide to SOX 404 covers who has to have that assessment attested by an auditor.
Outside the US the same structure gets used voluntarily as an internal control model, and it sits comfortably alongside management system standards — the risk assessment component in particular maps closely onto ISO 31000’s process. What COSO adds is the accountability layer: named principles a board can ask about, one at a time.
Frequently asked questions
How many COSO principles are there?
Seventeen, codified in the 2013 revision of the Internal Control–Integrated Framework and distributed across the five components: five, four, three, three and two.
What are the five components?
Control environment, risk assessment, control activities, information and communication, and monitoring activities.
Do all 17 principles have to be met?
Every relevant principle must be present and functioning, and the components must operate together. A component or relevant principle that is not present and functioning is a major deficiency.
Are points of focus mandatory?
No. They are example characteristics to help management judge whether a principle is present and functioning.
Is COSO the same as COSO ERM?
No. Internal Control–Integrated Framework and Enterprise Risk Management are two different COSO frameworks with different purposes. Our guide to the two COSO frameworks explains where each applies.
Where this leaves you
Assess at the principle level, because that is where the framework’s test bites. Map controls to the seventeen rather than to the five, treat points of focus as prompts rather than requirements, document any principle you judge not relevant, and pay particular attention to fraud risk and general technology controls — the two that most assessments inherit as gaps. A principle you cannot evidence is a major deficiency waiting to be found by somebody else.
References
- COSO — Internal Control–Integrated Framework — the 2013 framework, executive summary and supporting guidance.
- KPMG — COSO Internal Control–Integrated Framework (2013) — the seventeen principles as codified, with the present-and-functioning and major-deficiency definitions.
More on internal control
- The COSO 17 principles — you are here
- COSO: two frameworks, and the AI guidance
- SOX 404 and the auditor attestation
- Segregation of duties
Control matrices, assessment templates and deficiency logs are in the COSO ERM & Internal Control Toolkit, or start with the free ISO templates.