Skip to main content
Implement the COSO Internal Control–Integrated Framework.
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control–Integrated Framework is a widely used model for designing, implementing, and evaluating internal control. It is the foundation many organizations use to support financial reporting and SOX compliance.
COSO is frequently used as the control framework underpinning US SOX compliance and broader enterprise risk management.

Who needs COSO?

Public companies

Organizations using COSO as the basis for internal control over financial reporting.

Finance and audit teams

Teams designing and evaluating internal control environments.

Key components

Control environment

The foundation — integrity, ethical values, and governance structures.

Risk assessment

Identify and analyze risks to achieving objectives.

Control activities

Policies and procedures that mitigate risks.

Information & communication

Capture and share relevant information across the organization.

Monitoring activities

Ongoing and separate evaluations of control effectiveness.

How DSALTA helps with COSO

1

Activate COSO

Select COSO from the Frameworks page. DSALTA maps the five components and principles to controls.
2

Review control components

Review controls across the five COSO components and assign owners.
3

Collect evidence automatically

Connect integrations to gather control evidence.
4

Approve policies

Review and approve internal control policies.
5

Evaluate effectiveness

Monitor and document the effectiveness of internal controls.

Frequently asked questions

COSO is the most commonly used framework for evaluating internal control over financial reporting, which SOX requires public companies to assess.
COSO defines 17 principles spread across its five components, each representing a fundamental concept of effective internal control.