COSO's Internal Control Framework
Select a company, small or large, whose practices you will review. You may alternatively use a company you would like to start.In a paper of 4–5 pages:
Evaluate the company's practices against COSO's internal control frameworks. If you chose a company that you would like to start, then you are going to establish the COSO internal controls based on your selection of the company's operations.
Identify at least one possible risk in the current practice/potential practice that could limit the effectiveness of COSO's internal control framework. How would you discover and fix this issue?
Use three sources to support your writing. Choose sources that are credible, relevant, and appropriate. Cite each source listed on your source slide at least one time within your assignment. For help with research, writing, and citation, access the library or review library guides.
An internal control framework is a system of processes designed to ensure that an organization's objectives are met in an efficient and effective manner. It is also designed to provide reasonable assurance that assets are protected, liabilities are recorded and exist, transactions are recorded accurately, and operations are conducted in accordance with management's authorization.
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) is a private-sector organization that develops frameworks and guidance on enterprise risk management, internal control, and fraud deterrence. COSO's Internal Control Framework is one of the most widely used frameworks for internal control.
The COSO Internal Control Framework consists of five components:
- Control environment: The control environment is the foundation of an effective internal control system. It includes the tone at the top, the organization's commitment to integrity and ethical values, and the organizational structure.
- Risk assessment: Risk assessment is the process of identifying, assessing, and managing risks to the organization.
- Control activities: Control activities are the policies and procedures that help to mitigate risks to the organization.
- Information and communication: Information and communication is the process of collecting, processing, and communicating information needed to support the effective operation of internal control.
- Monitoring: Monitoring is the process of assessing the effectiveness of internal control over time.
- Improved efficiency and effectiveness of operations
- Increased protection of assets
- Reduced risk of fraud
- Improved compliance with laws and regulations
- Enhanced decision-making
- Improved financial reporting
- Increased shareholder value
- The cost of implementation
- The time commitment required for implementation
- The need for buy-in from management and employees
- The need to continuously monitor and improve the internal control system