top of page

Navigating Risk in 2026: The Role of Information and Communication in Financial Institutions According to COSO

Jul 23
4 min read

Updated: Aug 28



Today, we continue our Navigating Risk in 2026 series through the lens of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) Enterprise Risk Management Framework.


In earlier articles, we highlighted the COSO framework as an internationally recognized model built on five interrelated components of effective internal control. Each component is designed to help organizations manage risk more effectively. To date, we have explored three of these components: Control Environment, Risk Assessment, and Control Activities. In this article, we turn to the fourth component: Information and Communication.


Information and Communication as Strategic Enablers


In an era shaped by social media, digital acceleration, and artificial intelligence, information and communication have become indispensable to organizational performance. Together, they underpin productivity, collaboration, decision-making, and problem-solving. More importantly, they enable leadership to respond to risk with speed, clarity, and confidence.


For financial institutions, effective management of information is no longer simply an operational necessity; it is a strategic imperative.


Why Information and Communication Matter in Financial Institutions


For the purposes of this discussion, data and information are used interchangeably. Within financial institutions, high-quality data is essential to:


  • Support sound decision-making.

  • Identify opportunities for growth.

  • Strengthen risk oversight.

  • Improve the customer experience.


When data is accurate, accessible, and well-governed, it becomes a competitive asset. Conversely, when it is fragmented, unreliable, or poorly communicated, it can quickly become a source of operational inefficiency, compliance exposure, and reputational risk. Despite its importance, many financial institutions continue to face barriers that limit their ability to fully leverage data and communicate effectively across the enterprise.


Common Challenges


Inadequate Resources


Legacy systems, outdated technology, and skills gaps can leave data disorganized, incomplete, or difficult to access.


Siloed Systems


Information often resides across fragmented systems, departments, and third-party platforms. This fragmentation makes it difficult to generate a single, reliable view of the organization.


Weak Data Quality Controls


The absence of relationship-level data and inconsistent data governance practices can undermine the accuracy, completeness, and reliability of key information.


Increasing Technological Complexity


Rapid advancements in data and analytics capabilities create both opportunities and complexities. Institutions must continually adapt their operating models and skill sets to keep pace.


The Communication Challenge


Effective communication is equally critical. It enables the coordination of activities, strengthens accountability, fosters trust, and contributes to a more cohesive and productive organization.


Yet, many institutions still struggle in this area—not because communication is undervalued, but because formal processes for sharing relevant information with the right stakeholders, at the right time, are often underdeveloped or inconsistently applied. Under the COSO framework, strong information and communication practices help ensure that management, staff, regulators, and other stakeholders receive the information necessary to fulfill their responsibilities effectively.


Twelve Questions Financial Institutions Should Consider


The following questions can help financial institutions assess and strengthen the Information and Communication component of the COSO framework:


  1. What are the critical organizational documents, information artifacts, and communication cadences required to support effective operations and the achievement of strategic objectives?

  2. Which communication channels are approved and appropriate for sharing information across the organization?

  3. Has the institution established a document and policy management framework that clearly identifies key policies, materiality thresholds, review and approval requirements, and the location of standards and guidelines?

  4. Is there a formal Communication Plan that guides engagement with internal and external stakeholders—including regulators, law enforcement, customers, and the public—during significant events such as natural disasters, cyber incidents, or data breaches?

  5. Has data been formally classified according to sensitivity and criticality—for example, Public, Internal, Confidential, and Restricted—and is this supported by an approved policy?

  6. Is the institution’s approach to internal information sharing aligned with information security best practices and tailored to the organization’s specific operational needs?

  7. Are formal processes in place for user access provisioning, modification, and decommissioning to ensure that sensitive information remains appropriately restricted?

  8. Has a data dictionary been established to define the nature, meaning, and source of data used in key systems and reports?

  9. Have accountable information owners been assigned to critical or sensitive data assets, with appropriate approval requirements for granting access?

10. What processes support the periodic recertification of user access to help preserve data confidentiality, integrity, and accountability?

11. Are physical access controls over data centers, servers, and supporting infrastructure sufficiently robust, and is the environment resilient enough to support continuity of operations and data processing?

12.What assurance has the institution obtained regarding the integrity, completeness, and reliability of data within its systems?


The Importance of Information Governance


Strong information governance is essential for financial institutions. It ensures that data is not only accurate but also secure. By implementing robust data management practices, institutions can enhance their decision-making capabilities. This, in turn, leads to improved risk management and operational efficiency.


Building a Culture of Communication


Fostering a culture of open communication is vital. It encourages collaboration and innovation. When employees feel empowered to share information, organizations can respond more effectively to challenges. This culture also enhances trust among stakeholders, which is crucial for long-term success.


Closing Perspective


Within the COSO framework, Information and Communication is far more than a supporting function. It is a foundational capability that enables sound governance, effective internal control, and timely risk response.


For financial institutions, the ability to generate reliable information and communicate it effectively across the enterprise is essential to maintaining operational resilience, regulatory confidence, and strategic agility. Institutions that invest in strong information governance and disciplined communication practices are better positioned not only to manage risk but to compete and grow in an increasingly complex environment.


In conclusion, as we reflect on the importance of information and communication, we recognize that these elements are critical to achieving long-term success. By addressing the challenges and implementing best practices, financial institutions can navigate the complexities of today's landscape with confidence.

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page