Navigating Risk in 2026: COSO Control Activities
- Kesi Fields
- Jul 15
- 3 min read
Updated: 5 days ago

In this week’s Navigating Risk in 2026 series, we focus on Control Activities, a core component of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework.
Control activities are the policies, procedures, and mechanisms an organization establishes to manage risk within acceptable limits. They translate risk decisions into action and help ensure that exposures identified during the risk assessment process are addressed in a manner consistent with the expectations of the Board of Directors. The design, intensity, and frequency of these controls should align with:
the organization’s board-approved risk management strategy, and
its risk appetite.
Four Core Risk Treatment Strategies
Organizations generally respond to risk through one or more of four established strategies:
1. Risk Transfer
Risk transfer involves shifting exposure to a third party, most commonly through insurance or other contractual arrangements. This strategy is typically appropriate where the risk is material, but the underlying activity remains commercially important.
Example: An insurer may transfer portions of elevated underwriting risk through reinsurance while continuing to offer higher-margin products.
2. Risk Avoidance
Risk avoidance applies when an activity presents a level of exposure that exceeds the organization’s risk appetite. In these circumstances, the organization elects not to pursue the activity.
3. Risk Reduction
Risk reduction is the most common treatment strategy where exposure is necessary to support core operations. In these cases, organizations implement targeted control activities to reduce either the likelihood or the impact of the risk.
4. Risk Acceptance
Risk acceptance is appropriate where the residual risk is within tolerance and the cost of further mitigation outweighs the expected benefit.
From Risk Strategy to Control Execution
Once each risk has been assigned a treatment strategy, management should determine the control response required. Generally, risks categorized for reduction should be supported by clearly defined, well-documented, and proportionate controls. Effective control activities should not simply add process—they should strengthen resilience, improve decision-making, and support operational discipline.
Ten Executive Questions on Control Activities
For financial institutions, the following questions can help frame a more strategic review of the Control Activities component:
Have the most effective controls been identified and implemented to address key risks without creating unnecessary complexity?
Do existing controls reduce each exposure to an acceptable level? If not, what additional or compensating controls are required?
Are control types appropriately matched to the exposure and the institution’s approved risk appetite? Examples include preventive, detective, corrective, manual, semi-automated, and fully automated controls.
Are control activities documented in a way that is accessible, current, and usable by those responsible for execution and oversight?
Is ownership for each control clearly assigned to the appropriate business unit or function?
Where manual controls remain in place, are there viable opportunities to automate and reduce the risk of error, inconsistency, or fraud?
Does the control environment reflect an appropriate balance between cost and risk mitigation value?
Is segregation of duties adequately embedded across key processes and control responsibilities?
Have system roles and access templates been structured to reinforce effective segregation of duties?
Have critical controls been subject to independent validation to confirm they are operating as intended?
Closing Perspective
Strong control activities are not merely a compliance requirement. They are a practical expression of governance discipline, and strategic risk management. When properly designed, they enable the organization to operate with greater confidence, transparency, and resilience in an increasingly complex environment.
At Acumen, we assist financial institutions in validating the effective design and operation of control activities supporting significant business processes. Click the link below for more information.




Comments