Instiq
Chapter 4 · IT governance & internal control·v1.0.0·Updated 8/7/2026·~15 min

What's changed: Initial version

4.2The six components of internal control and COSO

Key points

Covers the six basic components of internal control (control environment, risk assessment and response, control activities, information and communication, monitoring, and response to IT) and their relationship to the COSO framework (which has five components—it does not include response to IT), building the judgment to diagnose which component's absence a control deficiency stems from.

When a systems auditor points out a control deficiency, merely saying "there is a weak spot" does not lead to improvement. Only by identifying which component of internal control's absence the deficiency stems from can the auditor make an effective recommendation to management. Japan's internal control reporting system (J-SOX) frames internal control in terms of six basic components, but its source, the U.S. COSO framework, has five components, with the important difference that only "response to IT" was added by Japan's implementation standards. Grounded in the role of each of the six components and their relationship to COSO, this section builds the viewpoint from which an auditor diagnoses where a deficiency lies.

4.2.1The six basic components of internal control

  • The control environment is the foundation—the organization's culture, integrity, ethics, and management policy—on which all other components rest. Risk assessment and response is the process of identifying, analyzing, and evaluating risks that impede goal achievement and deciding how to respond. Control activities are the policies and procedures (approval, segregation of duties, reconciliation, access control, etc.) that ensure management's directives are reliably carried out.
  • Information and communication is the mechanism by which necessary information is identified, captured, processed, and correctly conveyed to relevant parties inside and outside the organization. Monitoring is the process of continuously assessing whether internal control keeps functioning effectively (ongoing monitoring and separate evaluations). Response to IT is appropriately incorporating and responding to IT in operations, grounded in policies and procedures set in advance to achieve organizational goals (responding to the IT environment, and use and control of IT).

4.2.2Relationship to COSO (the difference between five and six components)

  • The COSO framework, published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) in the U.S., is the representative framework for internal control, framing it in five components (control environment, risk assessment, control activities, information and communication, monitoring). Widely referenced as a global standard, it is also the foundation of Japan's J-SOX.
  • Important: Japan's internal control reporting system (the implementation standards) added response to IT to COSO's five components, making six. This Japan-specific addition reflects the modern reality of IT deeply embedded in operations, and the contrast "COSO = five components; J-SOX/implementation standards = six components (adding response to IT)" is a frequently tested audit point. An auditor can organize IT-originated control deficiencies as the distinct component of "response to IT."
Exam point

Most-tested: "the six components of internal control = control environment, risk assessment and response, control activities, information and communication, monitoring, and response to IT", "COSO has five components (not including response to IT)", and "Japan's implementation standards added response to IT to make six". Do not answer "COSO also has six components"—it was Japan's implementation standards that added response to IT; the original COSO has five. Also frequently tested: the control environment is the foundation for all other components.

Suppose a systems auditor is diagnosing an internal-control deficiency. The event: "the accounting system's permission settings left a retiree's account untouched and unrevised for several months, leaving unauthorized journal-entry input possible." If the auditor immediately concludes "a deficiency in control activities (access control)," the recommendation tends to be superficial. A deeper diagnosis may reveal an operating deficiency: the procedure to delete a retiree's account was itself defined in the rules (i.e., the control activity was designed), but it was not actually operated and was left neglected. Digging further, it can be organized as a chain of multiple components—there was no monitoring mechanism to "periodically check whether permissions are appropriately maintained" in the first place, and the response to IT for organizationally controlling permission management in the IT environment was weak. The judgment the auditor should exercise here is to not force the deficiency into a single component, but diagnose where among the six components the root cause lies. If a procedure is defined but not followed, it is not a design but an operating deficiency; if the procedure is not defined at all, it is a design deficiency. In this case, an effective recommendation is not merely the corrective "periodically take inventory of access rights," but one that builds in monitoring (periodic permission review) and response to IT (control of the permission-management process). The trap is to be satisfied with pointing out only the visible control-activity deficiency and to miss the upstream components—the absence of monitoring or response to IT—that produced it. Not confusing the symptom (a crack in control activities) with the root cause (the absence of monitoring/response to IT) is where an auditor's skill shows.

ComponentRoleIn COSO (five components)?
Control environmentThe foundation for all other components (culture, ethics, policy)Included
Risk assessment and responseIdentifying, evaluating, and responding to risks that impede goalsIncluded
Control activitiesPolicies and procedures such as approval, segregation of duties, reconciliationIncluded
Information and communicationIdentifying, processing, and communicating necessary informationIncluded
MonitoringContinuously assessing whether control keeps functioning effectivelyIncluded
Response to ITAppropriately incorporating and controlling IT in operationsNot included (added by Japan's implementation standards)
Warning

Trap: "the COSO framework has six components" is wrong—COSO has five (control environment, risk assessment, control activities, information and communication, monitoring), and it was Japan's internal control reporting system (the implementation standards) that added "response to IT" to make six. Also wrong: "control is effective as long as a procedure exists in the rules"—if the defined procedure is not actually followed, it should be pointed out as an operating deficiency; the existence of a design and the existence of operation are evaluated separately.

COSO 5 vs. J-SOX 6 elements.
Note the differing element counts

4.2.3Section summary

  • The six components of internal control = control environment, risk assessment and response, control activities, information and communication, monitoring, and response to IT (the control environment is the foundation for the others)
  • The COSO framework has five components and does not include response to IT—Japan's implementation standards added response to IT to make six
  • An auditor does not force a deficiency into a single component but diagnoses by separating the symptom (a crack in control activities) from the root cause (the absence of monitoring/response to IT)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which statement correctly describes the relationship between the basic components of internal control under Japan's internal control reporting system and the components of the U.S. COSO framework?

Q2. In an accounting system, a retiree's account was left neglected for several months, making unauthorized journal-entry input possible. Investigation shows the procedure to delete a retiree's account was clearly written in the rules but was not actually carried out. Which classification of this deficiency is most appropriate?

Q3. Among the six basic components of internal control, which is positioned as the foundation on which all other components function effectively?

Check your understandingPractice questions for Chapter 4: IT governance & internal control

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.