> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# COSO

> Implement the COSO Internal Control–Integrated Framework.

> Implement the COSO Internal Control–Integrated Framework.

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control–Integrated Framework is a widely used model for designing, implementing, and evaluating internal control. It is the foundation many organizations use to support financial reporting and SOX compliance.

<Note>
  COSO is frequently used as the control framework underpinning US SOX compliance and broader enterprise risk management.
</Note>

## Who needs COSO?

<CardGroup cols={2}>
  <Card title="Public companies" icon="building-columns">
    Organizations using COSO as the basis for internal control over financial reporting.
  </Card>

  <Card title="Finance and audit teams" icon="calculator">
    Teams designing and evaluating internal control environments.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Control environment" icon="sitemap">
    The foundation — integrity, ethical values, and governance structures.
  </Card>

  <Card title="Risk assessment" icon="triangle-exclamation">
    Identify and analyze risks to achieving objectives.
  </Card>

  <Card title="Control activities" icon="list-check">
    Policies and procedures that mitigate risks.
  </Card>

  <Card title="Information & communication" icon="tower-broadcast">
    Capture and share relevant information across the organization.
  </Card>

  <Card title="Monitoring activities" icon="gauge">
    Ongoing and separate evaluations of control effectiveness.
  </Card>
</CardGroup>

## How DSALTA helps with COSO

<Steps>
  <Step title="Activate COSO">
    Select COSO from the Frameworks page. DSALTA maps the five components and principles to controls.
  </Step>

  <Step title="Review control components">
    Review controls across the five COSO components and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to gather control evidence.
  </Step>

  <Step title="Approve policies">
    Review and approve internal control policies.
  </Step>

  <Step title="Evaluate effectiveness">
    Monitor and document the effectiveness of internal controls.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="How does COSO relate to SOX?" icon="arrows-left-right">
    COSO is the most commonly used framework for evaluating internal control over financial reporting, which SOX requires public companies to assess.
  </Accordion>

  <Accordion title="What are the 17 principles?" icon="list-ol">
    COSO defines 17 principles spread across its five components, each representing a fundamental concept of effective internal control.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
