Internal controls design and evaluation using the COSO 2013 framework. USE THIS SKILL when the user asks about SOX compliance, COSO framework, control design, internal controls, control environment, risk-control matrices, control deficiencies, material weakness, ITGCs, segregation of duties, control testing, or any engagement involving the design, documentation, or assessment of internal controls over financial reporting. Produces COSO-aligned control frameworks, risk-control matrices, testing plans, and deficiency remediation roadmaps.
Internal controls design and evaluation using the COSO 2013 framework. USE THIS SKILL when the user asks about SOX compliance, COSO framework, control design, internal controls, control environment, risk-control matrices, control deficiencies, material weakness, ITGCs, segregation of duties, control testing, or any engagement involving the design, documentation, or assessment of internal controls over financial reporting. Produces COSO-aligned control frameworks, risk-control matrices, testing plans, and deficiency remediation roadmaps.
Internal Controls Design & Evaluation
Required Inputs
Organization: Company name, industry, size (revenue, headcount), and public/private status
Scope: Full entity, specific process areas, or IT general controls
Reporting Framework: US GAAP, IFRS, or other applicable standards
Material Accounts: Key financial statement line items in scope
Known Issues (optional): Prior deficiencies, auditor findings, management concerns
Systems Environment: ERP, GL, and key financial applications in use
Execution Steps
1. COSO 2013 Internal Control Framework Assessment
Evaluate the organization against all 5 components and 17 principles of the COSO 2013 Integrated Framework. Each principle is scored as Present & Functioning (P), Present with Exceptions (E), or Not Present (N).
Component 1: Control Environment
#
Principle
Key Assessment Areas
Score
1
Commitment to integrity and ethical values
Code of conduct, ethics hotline, tone at the top, consequence management
Deficiency identification; classification; escalation to audit committee
P / E / N
COSO Assessment Summary: A component is effective only when ALL underlying principles are Present & Functioning. The system of internal control is effective only when ALL 5 components are effective.
2. Financial Statement Assertion Mapping
Map controls to the 5 financial statement assertions for each significant account:
Assertion
Abbreviation
Definition
Example Controls
Existence / Occurrence
E/O
Assets/liabilities exist; transactions occurred
Physical inventory counts; bank confirmations; transaction matching
Completeness
C
All transactions and balances are recorded
Sequence checks; 3-way match (PO-receipt-invoice); reconciliation to third party
Valuation / Allocation
V/A
Amounts are recorded at appropriate values
Reserve calculations; impairment testing; fair value models; aging analysis
Rights & Obligations
R/O
Entity holds rights to assets; liabilities are obligations
Title documents; contract review; lien searches; confirmation of terms
New hire authorization; pay rate changes approval; payroll register review; bank reconciliation
Treasury / Cash
Unauthorized transactions; incorrect cash balance
Bank reconciliation; dual signatures; wire transfer approval; investment authorization
Financial Close
Misstatement in financial statements
Close calendar; JE approval; account reconciliations; variance analysis; management review
Equity / Stock Comp
Incorrect fair value; unauthorized issuance
Board approval of grants; valuation model review; vesting schedule tracking; expense calculation review
IT General Controls (ITGCs):
ITGC Domain
Control Objective
Key Controls
Access Security
Only authorized users access systems and data
Access provisioning with approval; periodic access reviews (quarterly); privileged access monitoring; password policies; terminated user removal within 24 hours
Change Management
Changes are authorized, tested, and approved
Change request documentation; segregation of dev/test/prod; testing evidence; approval prior to migration; emergency change procedures
Computer Operations
Systems operate reliably and data is protected
Job scheduling and monitoring; backup procedures with offsite storage; backup restoration testing; incident management; disaster recovery planning
Program Development
New systems are properly designed and implemented
SDLC methodology; requirements documentation; user acceptance testing; data migration validation; post-implementation review
5. SOX Scoping Methodology
Step 1: Identify Material Accounts
A financial statement line item is material if a misstatement could reasonably influence economic decisions. Apply quantitative and qualitative materiality:
Quantitative: Typically 5% of pre-tax income (or alternative base: revenue, total assets)
Step 2: Map Material Accounts to Significant Processes
Material Account
Significant Process(es)
Location(s)
System(s)
[Account]
[Process]
[Entity/Location]
[Application]
Step 3: Identify Key Controls
For each significant process, identify key controls: the minimum set of controls that, if operating effectively, reduce the risk of material misstatement to an acceptably low level.
Key Control Criteria:
Addresses a meaningful risk of material misstatement
Operates at a sufficient level of precision
Appropriate evidence of performance is retained
IPE (information produced by the entity) used by the control is reliable
Step 4: Determine Testing Approach
Control Frequency
Minimum Sample Size (Design)
Minimum Sample Size (Operating)
Annual
1
1
Quarterly
1
2-4
Monthly
1
2-5
Weekly
1
5-15
Daily
1
20-25
Per transaction
1
25-60 (based on population size)
Operating Effectiveness Sample Sizes by Population:
Population Size
Sample Size (Low Risk)
Sample Size (High Risk)
< 50
5-10
10-20
50-250
15-20
25-40
250-1,000
20-25
40-60
> 1,000
25
45-60
6. Risk-Control Matrix (RCM) Design
Each significant process requires an RCM with the following structure:
Field
Description
Process
Business process name
Sub-process
Specific activity within the process
Risk ID
Unique identifier
Risk Description
What could go wrong (specific to financial reporting)
A control does not allow management or employees to prevent or detect misstatements on a timely basis in the normal course of performing their functions
Documented; tracked for remediation
Significant Deficiency
A deficiency, or combination of deficiencies, that is less severe than a material weakness yet important enough to merit attention by those charged with governance
Reported to audit committee; remediation plan required
Material Weakness
A deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis
Disclosed publicly (SOX); immediate remediation; auditor communication
Deficiency Evaluation Factors:
Likelihood of misstatement occurring
Magnitude of potential misstatement (quantitative)
Nature of financial statement accounts affected (qualitative)
Whether compensating controls exist
Whether the deficiency is systemic or isolated
8. Remediation Planning
Remediation Priority Matrix:
Priority
Criteria
Timeline
Immediate
Material weakness; regulatory deadline; active audit finding
0-30 days
High
Significant deficiency; multiple related deficiencies; fraud risk
30-90 days
Medium
Control deficiency with no compensating control; efficiency opportunity
90-180 days
Low
Control deficiency with compensating control; best practice enhancement
180-365 days
9. Management Testing vs. External Auditor Reliance
Factor
Management Testing
External Auditor Testing
Objective
Assess control effectiveness for management assertion (SOX 302/404a)
Form opinion on ICFR effectiveness (SOX 404b)
Scope
All key controls across all significant processes
Risk-based selection; may rely on management testing
Auditor Reliance Factors
N/A
Competence and objectivity of testers; scope and results of testing; risk of the area; nature of controls
Reliance Limits
N/A
Auditor cannot rely solely on management testing for high-risk areas or entity-level controls