COSO Framework
Information & Communication Controls
Quality of information flows and reporting controls scored against the COSO I&C component.
Why information and communication controls matter
COSO's information and communication component recognises that internal control depends on relevant, quality information flowing to the right people, a concern reinforced in South Africa by POPIA's requirements around information integrity and by the AGSA's scrutiny of reporting reliability. Scoring the quality of information flows and reporting controls reveals whether decisions and oversight rest on trustworthy data. AuditPro Core rates information and communication controls against the COSO component so management can identify where poor data or broken reporting undermines the wider control system.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Reporting controls
47
Data quality score
76%
▲ 5 pts
Timeliness breaches
9
Channels assessed
5
Score by information attribute (%)
Channel reliability
| Channel | Reliability % | Breaches | Owner |
|---|---|---|---|
| Management reports | 84 | 2 | Finance |
| Board packs | 88 | 1 | CoSec |
| Operational dashboards | 71 | 4 | Operations |
| Whistleblower hotline | 79 | 1 | Risk |
| Regulatory submissions | 75 | 1 | Compliance |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Information quality
Internal control depends on information that is accurate, complete, timely and accessible. Poor-quality information corrupts decisions and renders dependent controls ineffective regardless of their design.
Internal communication
Control responsibilities must be communicated so people understand their obligations and how their role affects others. Gaps here cause controls to fail not from design flaws but from people not knowing their part.
External communication
Institutions must communicate relevant information to external parties and receive it back, including from oversight bodies and the public. In the public sector this includes transparent reporting to citizens and regulators.
Reporting controls
Controls over the production of reports determine whether management and the governing body can rely on what they receive. Weak reporting controls quietly erode the value of every report they produce.
How AuditPro Core Bridges the Gap
- Component scoring: information flows and reporting controls are rated against the COSO information and communication criteria.
- Quality exception flags: information streams scoring poorly on accuracy or timeliness are surfaced for remediation.
- Traceability to source: reporting controls link to the data sources and processes they depend on.
- Audit-ready assessment: the component view exports to support reporting-reliability representations to AGSA.
Key Takeaways
- Internal control depends on accurate, complete and timely information.
- Communicating responsibilities prevents controls failing from confusion.
- Public-sector communication extends to citizens and oversight bodies.
- Weak reporting controls erode the reliability of every report produced.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
