top of page

Navigating Risk in 2026: Monitoring Under the COSO Internal Control Framework

Jul 30
4 min read

Updated: Sep 3


This article concludes our Navigating Risk in 2026 series with an examination of Monitoring Activities, the fifth component of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control—Integrated Framework.


The series has explored the other four components:

  • Control Environment establishes the foundation for effective internal control. It encompasses the role of the board and senior management, organizational strategy, policies, accountability structures and ethical standards. Together, these elements shape corporate culture and set the tone from the top.

  • Risk Assessment enables organizations to identify, analyze and evaluate uncertainties that may affect the achievement of strategic, operational, reporting and compliance objectives.

  • Control Activities are the policies, procedures and actions implemented to address identified risks and reduce residual risk to an acceptable level.

  • Information and Communication ensure that relevant, reliable and timely information is shared throughout the organization, supporting sound decision-making, effective execution and organizational alignment.


COSO Monitoring Activities

Monitoring Activities involve the ongoing evaluation of whether internal controls are designed appropriately, operating effectively and continuing to support the achievement of organizational objectives.


Effective monitoring enables management and the board to confirm that controls remain relevant as business priorities, operating models, technologies and risk exposures evolve. It also ensures that control deficiencies are identified, escalated and remediated on a timely basis.


Monitoring is not simply a compliance exercise. It is a critical management discipline that provides assurance that the internal control system remains effective over time.


Determining the Appropriate Frequency of Monitoring

Organizations may use a combination of ongoing evaluations and separate evaluations to assess the effectiveness of internal controls.


  • Ongoing evaluations are embedded within day-to-day business processes. They provide timely feedback and allow issues to be identified and addressed as they arise.

  • Separate evaluations are conducted periodically and independently, often by Internal Audit, Enterprise Risk Management or appropriately qualified external service providers.


The appropriate monitoring frequency should be risk-based. In determining the level and frequency of monitoring, organizations should consider:


  • The importance of the control in supporting strategic and operational objectives;

  • The likelihood and potential impact of the underlying risk materializing;

  • The effectiveness and maturity of existing controls;

  • Changes in the regulatory, business or technology environment; and

  • The level of residual risk that remains after controls have been applied.


A well-maintained risk register can support this assessment. It should capture:


  1. The identified risk;

  2. The inherent risk rating, or the level of risk before controls are applied;

  3. The control activities designed to mitigate the risk; and

  4. The residual risk rating, or the remaining level of risk after controls are implemented.

Areas with elevated residual risk should be prioritized for enhanced controls, more frequent assessment or continuous monitoring. Decisions should be informed by a clear cost-benefit analysis and aligned with the organization’s risk appetite.

For lower-risk areas, periodic monitoring may be sufficient.


Approaches to Monitoring

Organizations can use a range of methods to monitor internal controls. The most effective approach will typically combine management oversight, performance data, technology-enabled insight and independent assurance.


Management-Established Baselines and Metrics

Management should establish clear performance baselines, key performance indicators (KPIs), key risk indicators (KRIs) and acceptable tolerance thresholds. Exception reporting can then identify control processes that exceed defined limits or fall below expected performance standards. This enables management to investigate root causes, assign accountability and implement corrective action before issues become material.


Dashboards and Technology

Digital dashboards and monitoring tools can provide timely visibility into control performance, risk trends and emerging exceptions.

Where appropriate, automated monitoring can support near real-time oversight of high-volume or high-risk processes. This can improve the speed of issue detection, enhance management reporting and allow resources to be focused on areas requiring intervention.


Enterprise Risk Management and Internal Audit Reviews

Enterprise Risk Management and Internal Audit—typically the second and third lines of defense—each play important and complementary roles in monitoring internal controls.


  • Enterprise Risk Management can work proactively with the business to identify control gaps, emerging risks and areas requiring management attention.

  • Internal Audit provides independent assurance to the board and senior management on the effectiveness of governance, risk management and internal control processes.


While their responsibilities must remain appropriately distinct, coordinated planning and information-sharing between these functions can improve coverage, reduce duplication and strengthen the overall assurance framework.


Benefits of Effective Monitoring

A robust monitoring programme enables organizations to:

  • Prevent, detect and remediate control deficiencies before they develop into significant issues;

  • Strengthen compliance with applicable laws, regulations and internal policies;

  • Respond effectively to evolving risks, strategic priorities and business processes;

  • Improve accountability for control ownership and remediation;

  • Provide timely, decision-useful assurance to management and the board; and

  • Create a feedback loop that allows the COSO framework to be refined and scaled to the organization’s risk profile, operating environment and strategic objectives.


Closing Perspective

The effectiveness of an internal control framework depends not only on how controls are designed, but also on how consistently they are assessed, challenged and improved.


Monitoring provides the discipline that connects all five COSO components. It ensures that the control environment remains strong, risks are reassessed as circumstances change, control activities continue to operate as intended, and relevant information reaches the right decisionmakers at the right time.


Effective monitoring is therefore essential to sustaining organizational resilience, protecting value and supporting confident decision-making by senior management and the Board of Directors in an increasingly complex risk environment.


At Acumen, we assist financial institutions in monitoring the design and effectiveness of controls and processes implemented to support organizational strategies. Click the link below for more information.


 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page