COSO Internal Control—Integrated Framework
The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.
2013 · Committee of Sponsoring Organizations of the Treadway Commission
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
COSO Internal Control—Integrated Framework is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Purchase the 2013 framework and obtain COSO's software-incorporation and redistribution rights before using protected framework text in the product.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Control environment · Risk assessment · Control activities · Information and communication · Monitoring activities
- Applies to
- public companies · financial services · all sectors · US · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
03Version ledger
| 1992 | Superseded | date not published |
| 2013 | Current edition · supersedes 1992 | date not published |
06Related frameworks
- GAO Green Book2025 Revision
Commonly assessed together · The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification.
- Shared Assessments SIG2026 annual release
Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
- HITRUST CSFv11.8.0
Also applies to financial services · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- ISO 223012019 (Amd 1:2024)
Also applies to all sectors · The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.