Back to Explore
💵

COSO Framework

COSO Principles Coverage

Coverage status across the 17 COSO principles, grouped by component, showing present and functioning rates.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why principle-level coverage matters

COSO 2013 requires all 17 principles to be present and functioning for an institution to conclude that internal control is effective, and auditors will probe any principle assessed as absent or malfunctioning. Tracking coverage at principle level, grouped by component, gives a far more honest picture of control health than a component average alone. AuditPro Core maps each principle's present-and-functioning status so management can identify exactly which of the 17 needs attention rather than asserting blanket effectiveness.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Principles

17

Present & functioning

12

71%

Partially present

4

Absent

1

remediation due

Principle status by component

Coverage by component

ComponentPrinciplesPresentCoverage %
Control Environment5480
Risk Assessment4250
Control Activities33100
Information & Comms3267
Monitoring2150

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Present and functioning

COSO distinguishes a principle being present, meaning the relevant controls exist, from functioning, meaning they operate as intended. Both conditions must hold for the principle to support an effective-control conclusion.

The 17 principles

The principles decompose the five components into specific, assessable expectations such as commitment to integrity or selection of control activities. They make the framework concrete enough to test.

Major deficiency

Under COSO, a principle that is not present and functioning constitutes a major deficiency, which generally precludes concluding that internal control is effective. This raises the stakes on any gap.

Grouping by component

Organising principles under their parent component shows whether gaps cluster in one area or scatter across the system. Clustering points to a focused structural fix.

How AuditPro Core Bridges the Gap

  • Status mapping: each of the 17 principles is tracked as present, functioning, both or neither, grouped under its COSO component.
  • Deficiency flags: principles failing the present-and-functioning test are highlighted as major deficiencies requiring documented response.
  • Traceability to controls: every principle links to the controls and evidence supporting its status assessment.
  • Audit-ready coverage report: the full 17-principle matrix exports to support the institution's effectiveness conclusion and AGSA engagement.

Key Takeaways

  • All 17 principles must be present and functioning to assert effective control.
  • A single malfunctioning principle is a major deficiency under COSO.
  • Component averages can hide a failing principle; assess at principle level.
  • Clustered gaps signal a focused structural remediation opportunity.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.