Established model
COSO Internal Control — Integrated Framework
Committee of Sponsoring Organizations of the Treadway Commission · 1992
Also known as COSO framework, COSO cube
A shared definition of internal control, broken into the components that all have to be present and working.
Its place in the frameworkBusiness Core›Compliance
What it does
It treats control as a process run by people, not a set of documents: an environment that sets the tone, an assessment of risk, the control activities themselves, the information and communication that make them visible, and monitoring to see whether they still work. Its main contribution was a common language, which is why auditors and regulators across many countries use it.
- Reach for it when
- When controls exist on paper and nobody can say whether they work, and when an auditor, a regulator and management each mean something different by control.
- Where it stops
- It describes what a sound system of control contains, not which controls a particular business needs. Applied mechanically it produces documentation rather than assurance.
Committee of Sponsoring Organizations of the Treadway Commission, Internal Control — Integrated Framework, 1992; updated 2013. COSO is named here only to refer to its published work.
Why it sits at Compliance
The obligations the organisation has no choice about — legal, regulatory, contractual and financial, environmental law included — and the controls that keep them met.
A model is only useful when you reach for it at the right moment. This one answers a question that arises here — so it is filed here, and nowhere else. These are the working areas it serves:
- Regulatory mappingCompliance management practice on obligation registers, which underpin everything downstream.
- ControlsInternal control frameworks such as COSO, and the preventive-detective-corrective distinction.
- MonitoringInternal audit practice on control testing, and the three-lines model separating operation, oversight and assurance.
- Incident responseIncident response practice, including statutory notification windows such as the seventy-two hours required under GDPR.
What it touches elsewhere
Nothing in a business is decided on its own. A conclusion reached with this model at Compliance lands in these other cores, whether or not anyone follows it there.
- Business CoreControls live inside operational systems; obligations often flow through partners and the supply chain.
- Data CoreData governance is where much of modern compliance actually sits.
- Brand CoreA compliance failure is a brand event before it is a legal one.
- ResponsibilityVoluntary commitments, sustainability targets and ethics above the legal minimum are owned there; this object keeps what the organisation has no choice about.
- GovernanceThe enterprise risk register is held there; compliance risks are entered in it, not kept in a register of their own.
Filed at the same place
These answer questions that arise at Compliance too. Where they disagree with this one, the disagreement is the useful part.
- ISO 37301 compliance management systemsA standard for running compliance as a managed system rather than a series of reactions to the last incident.
Elsewhere in Business Core
- Tuckman’s stages of group development
- Belbin Team Roles
- Herzberg’s two-factor theory
- Jobs to be done
- The Kano model
- The value proposition canvas
- The business model canvas
- The Van Westendorp price sensitivity meter
- Value-based pricing
- Core competence
- VRIO
- The resource-based view
- The theory of constraints
- Lean thinking
- Co-opetition and the value net
- Transaction cost economics
- Stakeholder theory
- The power–interest grid
- DuPont analysis
- Break-even and cost–volume–profit analysis
- Unit economics
- The Kraljic Matrix
- The bullwhip effect
- The SCOR Model
- On-time in-full
- Overall equipment effectiveness
- Value stream mapping
- The three lines model
- ISO 31000 risk management
- Maslow’s hierarchy of needs
- Kotter’s eight-step change model
- Situational leadership
- The Lean Startup
- Design thinking
- Porter’s value chain
- The McKinsey 7S framework
- Six Sigma and DMAIC
- Stage-gate
- Beyond budgeting
- Dynamic capabilities
- Intangible assets
- The four S’s of intangible investment
- Net present value and discounted cash flow
- The Modigliani–Miller theorem
- The pecking order theory
- COSO Enterprise Risk Management
- Agency theory
- Mintzberg’s organisational configurations
- The Star Model
- Lewin’s change model
- The ADKAR model
- Effectuation
- Open innovation
- The technology acceptance model
- The NIST Cybersecurity Framework
- The TOGAF Standard
- Wardley mapping
- Failure mode and effects analysis
These are other people’s models, named here so you can go to the source and use them properly. The Omnigoal is not affiliated with their authors and is not endorsed by them; nothing of theirs is reproduced here — no canvas, no diagram, no wording. Each is described in our own words, with the originator credited, because the framework is a place to put thinking, not a replacement for the people who did it. Model names and trademarks belong to their respective owners and are used here only to refer to the work itself.
All 166 models