Back to Explore
🛡️

COSO Framework

Information & Communication Controls

Quality of information flows and reporting controls scored against the COSO I&C component.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why information and communication controls matter

COSO's information and communication component recognises that internal control depends on relevant, quality information flowing to the right people, a concern reinforced in South Africa by POPIA's requirements around information integrity and by the AGSA's scrutiny of reporting reliability. Scoring the quality of information flows and reporting controls reveals whether decisions and oversight rest on trustworthy data. AuditPro Core rates information and communication controls against the COSO component so management can identify where poor data or broken reporting undermines the wider control system.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Reporting controls

47

Data quality score

76%

▲ 5 pts

Timeliness breaches

9

Channels assessed

5

Score by information attribute (%)

Channel reliability

ChannelReliability %BreachesOwner
Management reports842Finance
Board packs881CoSec
Operational dashboards714Operations
Whistleblower hotline791Risk
Regulatory submissions751Compliance

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Information quality

Internal control depends on information that is accurate, complete, timely and accessible. Poor-quality information corrupts decisions and renders dependent controls ineffective regardless of their design.

Internal communication

Control responsibilities must be communicated so people understand their obligations and how their role affects others. Gaps here cause controls to fail not from design flaws but from people not knowing their part.

External communication

Institutions must communicate relevant information to external parties and receive it back, including from oversight bodies and the public. In the public sector this includes transparent reporting to citizens and regulators.

Reporting controls

Controls over the production of reports determine whether management and the governing body can rely on what they receive. Weak reporting controls quietly erode the value of every report they produce.

How AuditPro Core Bridges the Gap

  • Component scoring: information flows and reporting controls are rated against the COSO information and communication criteria.
  • Quality exception flags: information streams scoring poorly on accuracy or timeliness are surfaced for remediation.
  • Traceability to source: reporting controls link to the data sources and processes they depend on.
  • Audit-ready assessment: the component view exports to support reporting-reliability representations to AGSA.

Key Takeaways

  • Internal control depends on accurate, complete and timely information.
  • Communicating responsibilities prevents controls failing from confusion.
  • Public-sector communication extends to citizens and oversight bodies.
  • Weak reporting controls erode the reliability of every report produced.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.