Independent research, paper 2 of 3

Governance review against COSO

An internal control gap analysis of an anonymised mid-sized company, mapped to the COSO framework, with the gaps ranked by the exposure they leave open rather than by how easy they are to close.

Framework
COSO Internal Control, Integrated Framework
Scope
5 components, 17 principles
Subject
Anonymised mid-sized company
Tests
Design and operating effectiveness
Output
Ranked gap register
Period
2025 – 2026

The question

Listing control weaknesses is not hard. Any reasonably careful reader can generate a long list of things an organisation isn't doing. The list is also close to useless on its own, because it gives management no way to decide what to fix first, and a remediation plan that treats every gap as equally urgent is a plan that gets abandoned.

The question I was actually interested in was the ordering: which gaps leave the most exposure open, as distinct from which gaps are the most conspicuous. Those are very often different gaps.

Why COSO

COSO is the framework most internal control work in the US is assessed against, including management's assessment under Sarbanes-Oxley Section 404. It breaks internal control into five components, which in turn resolve into seventeen principles. The value of using it here is that it forces coverage: it is much harder to overlook an entire category of control when you are walking a structured checklist than when you are reading a governance document looking for problems.

ComponentWhat it asksWhere gaps usually hide
Control environmentIs there a culture, structure and tone that makes control possible at all?Board independence, delegated authority that was never written down
Risk assessmentAre objectives clear enough that risks to them can be identified and sized?Fraud risk treated as a compliance formality; change not reassessed
Control activitiesAre the policies and procedures that address those risks actually in place?Segregation of duties in small teams; IT general controls
Information & communicationDoes relevant, quality information reach the people who need it, in time?Upward reporting of bad news; whistleblower routes that bypass the subject
Monitoring activitiesIs the system itself being evaluated, and are deficiencies escalated?Findings logged but never closed out; no follow-up on remediation

Method

  1. Map the existing structure onto the seventeen principles

    Every documented control is assigned to the principle it is meant to support. Principles with nothing mapped to them are the first finding: an uncovered principle is a gap by definition, before any testing happens.

  2. Separate design from operation

    A control can fail in two different ways, and conflating them produces bad remediation. If a control is badly designed, it would not catch the problem even if performed perfectly. If it is badly operated, the design is sound but it isn't being done consistently. The first needs a new control; the second needs supervision. Testing design first avoids the trap of tightening enforcement on a control that was never going to work.

  3. Classify severity

    Using the standard three-tier scale: a deficiency, a significant deficiency (serious enough to warrant attention by those overseeing financial reporting), and a material weakness (a reasonable possibility that a material misstatement would not be prevented or detected in time). The distinction is about the magnitude of what could go undetected, not about how careless the failure looks.

  4. Score residual risk, not inherent risk

    Inherent risk is the exposure before controls. Residual risk is what survives the controls that do exist, and it is residual risk that should drive the ordering. A frightening inherent risk with three overlapping compensating controls is a lower priority than a modest one sitting completely uncovered.

  5. Rank and sequence remediation

    Residual risk sets the priority; effort and dependency set the sequence. Some fixes unlock others: a documented delegation-of-authority matrix has to exist before approval thresholds can be tested against anything.

# the scoring that drives the ranking Inherent risk = likelihood × impact Residual risk = Inherent risk × (1 − control effectiveness) Priority = Residual risk ÷ remediation effort # highest first

The gap register

This is the deliverable. The ordering is the point of it: the rows are sorted by residual risk, not by component, so it reads as a work queue rather than as an audit checklist.

#ComponentGap identifiedDesign or operatingSeverityResidual riskRemediation
01Control activitiesOne role both initiates and approves vendor payments under the approval thresholdDesignMaterial weakness16.0Split initiation from approval; lower the threshold; require dual authorisation above it
02MonitoringPrior-period findings are logged, but no owner or closure date is assigned to any of themOperatingSignificant deficiency12.6Assign a named owner and due date per finding; standing review item at the audit committee
03Control environmentDelegation of authority is held by convention and never formally documentedDesignSignificant deficiency10.5Publish a delegation matrix; reconcile actual approvals against it quarterly
04Information & communicationThe whistleblower channel routes to the line manager, so a report about that manager has no pathDesignSignificant deficiency8.0Route to the audit committee; add an anonymous external intake
05Risk assessmentFraud risk assessed annually as a compliance exercise and never refreshed when processes changeOperatingDeficiency7.2Trigger reassessment on system, process or personnel change rather than on the calendar

Residual risk is scored on a 1–5 likelihood and impact scale, discounted by the effectiveness of whatever control does exist. The ordering it produces is the argument of this page: finding 01 ranks first not because it is the most egregious on paper but because nothing else in the structure compensates for it, while finding 05 sits last despite being a real deficiency because two adjacent controls partially cover the same exposure.

Coverage by component

ComponentPrinciples coveredGaps foundHighest severity
Control environment4 / 51Significant deficiency
Risk assessment3 / 41Deficiency
Control activities2 / 31Material weakness
Information & communication2 / 31Significant deficiency
Monitoring activities1 / 21Significant deficiency
Key finding

The gaps that scored highest were not the ones that looked worst on the page. Controls that were absent entirely were easy to spot and often low-exposure; the expensive ones were controls that existed, were documented, and were quietly not being performed, because everyone, including the people relying on them, believed they were.

Limitations

  • Documentation is not operation. Reviewing a control structure on paper tells you what should happen. Only testing a sample of transactions tells you what does.
  • Management override sits outside the framework. COSO explicitly acknowledges that a sufficiently senior person can circumvent almost any control. No gap register catches that.
  • Judgement in scoring. Likelihood and impact are assigned, not measured. Two competent reviewers will produce different orderings, and the ranking is only as defensible as the reasoning written beside it.
  • A point in time. Control environments drift. A review is a photograph, and the organisation keeps moving after the shutter closes.

Next iteration

I'd test a transaction sample rather than reviewing documentation alone; the single biggest weakness of the exercise is that it assesses design far more confidently than operation. I'd also map each gap to the specific financial statement assertion it threatens, which is what makes a register legible to an auditor rather than just to management.

All research  ·  Back to home