COSO Internal Control — Integrated Framework (2013)

Framework for designing, implementing, and evaluating internal controls over operations, reporting, and compliance across five integrated components. Applies to organisations of all types and sizes.

5

Rules extracted

95

Obligations decomposed

19.0x

Avg obligations per rule

🌐 International

Jurisdiction

What AuditDSS covers

Source

1

Regulation

Extracted

5

Rules

Decomposed

95

Obligations

19.0x

Decomposition ratio

Each rule is decomposed into an average of 19.0 atomic obligations — the smallest testable units that can be independently violated.

Fully extracted & scored

All 95 obligations have been decomposed, titled, risk-scored, and embedded for semantic matching.

Risk scoring

Every obligation in COSO IC Framework 2013 is scored across independent risk dimensions:

W

Obligation Weight

How critical within the regulatory framework

L

Violation Likelihood

How often breached in practice

E

Enforcement Evidence

Regulator enforcement history and penalties

C

Cascade Dependency

How many obligations depend on this one

Regulatory details

Full title
COSO Internal Control — Integrated Framework (2013)
Regulatory body
Committee of Sponsoring Organizations of the Treadway Commission
Jurisdiction
🌐 International
Document type
standard
Effective date
May 14, 2013

Who this applies to

public companiesprivate companiesgovernment entitiesnot-for-profit organizationsinternal auditorsexternal auditorsboards of directors

Key requirements

  • 5 integrated components
  • 17 principles of effective internal control
  • 77 points of focus
  • control environment assessment
  • risk assessment including fraud risk
  • control activities over operations and technology
  • information and communication requirements
  • ongoing and separate monitoring evaluations
  • deficiency identification and communication

Frequently asked questions about COSO IC Framework 2013

What is COSO IC Framework 2013?

Framework for designing, implementing, and evaluating internal controls over operations, reporting, and compliance across five integrated components. Applies to organisations of all types and sizes.

Who does COSO IC Framework 2013 apply to?

COSO IC Framework 2013 applies to public companies, private companies, government entities, not-for-profit organizations, internal auditors, external auditors, boards of directors.

How many obligations does COSO IC Framework 2013 contain?

AuditDSS has decomposed COSO IC Framework 2013 into 95 atomic obligations from 5 rules. Each obligation is independently testable and risk-scored.

What are the key requirements of COSO IC Framework 2013?

The key requirements include: 5 integrated components, 17 principles of effective internal control, 77 points of focus, control environment assessment, risk assessment including fraud risk, control activities over operations and technology, information and communication requirements, ongoing and separate monitoring evaluations, deficiency identification and communication.

How can I assess my COSO IC Framework 2013 compliance?

Upload your compliance policy to AuditDSS. The platform maps your document against all 95 COSO IC Framework 2013 obligations using deterministic AI scoring — not checklists or LLM summaries. You get a risk-scored gap analysis showing exactly which obligations are covered, partially covered, or missing.

Which jurisdiction enforces COSO IC Framework 2013?

COSO IC Framework 2013 is enforced in International by Committee of Sponsoring Organizations of the Treadway Commission.

When did COSO IC Framework 2013 come into effect?

COSO IC Framework 2013 became effective on May 14, 2013.

What industry does COSO IC Framework 2013 apply to?

COSO IC Framework 2013 is primarily relevant to the Medical Devices & Diagnostics industry. AuditDSS covers 64 regulations in this industry sector.

Build a COSO IC Framework 2013 compliance pack

Don't have a compliance policy yet? AuditDSS generates a complete compliance pack for COSO IC Framework 2013 — alone or combined with other regulations your business needs. Every clause is mapped to specific obligations.

Policy

High-level commitments and governance framework covering COSO IC Framework 2013 requirements.

Procedures

Step-by-step operational procedures to implement each policy commitment.

Forms & checklists

Ready-to-use forms, registers, and checklists for day-to-day compliance operations.

Multi-regulation

Combine COSO IC Framework 2013 with other regulations into a single unified compliance pack for your business.

Already have a policy? Assess it against COSO IC Framework 2013

1

Upload your document

Upload your compliance policy, program manual, or operational document. AuditDSS accepts any text-based document.

2

AI maps against 95 obligations

Your document is scored against every obligation in COSO IC Framework 2013. Each claim is mapped to the obligation tree and evaluated for coverage.

3

Risk-scored gap report

Receive every gap ranked by risk priority with remediation guidance, enforcement evidence, and cascade impact analysis.

Related regulations in Medical Devices & Diagnostics

Assess your COSO IC Framework 2013 compliance

Upload your document and get a risk-scored gap analysis against 95 COSO IC Framework 2013 obligations in under 5 minutes.