Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Internal Controls & Audit

COSO Cube

Also known as: COSO Internal Control Cube
Simply put

The COSO Cube is a three-dimensional diagram used to illustrate the COSO Internal Control-Integrated Framework, a widely recognized model for internal control developed by the Committee of Sponsoring Organizations (COSO). It is a visual aid that shows how the different parts of an organization's internal control system relate to and connect with one another. The cube helps people understand that effective internal control depends on several interconnected elements rather than a single measure.

Formal definition

The COSO Cube is a three-dimensional visual representation associated with the COSO Internal Control-Integrated Framework, developed by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). It is used to depict the interrelationship among the framework's components, the objectives an organization pursues, and the organizational structure or units to which internal control applies, thereby illustrating the interconnectedness of an internal control system. The model has become a widely accepted reference for designing, implementing, and evaluating internal control, and a comparable cube visualization has also been used in connection with COSO's enterprise risk management work. Note that framework language and supporting guidance evolve across editions, for example, COSO issued supplemental guidance in 2023 addressing internal control over sustainability reporting (ICSR), so specific components, terminology, and applicability should be verified against the current primary source, and use in any given organization or jurisdiction may vary.

Why it matters

Internal control failures rarely stem from the absence of a single safeguard; they more often arise from gaps in how control elements connect and reinforce one another. The COSO Cube matters because it gives governance professionals, auditors, and management a shared visual language for understanding that internal control is a system of interrelated parts rather than a checklist of isolated measures. By depicting components, objectives, and organizational units as three dimensions of a single structure, the cube encourages organizations to consider how a weakness in one area, such as the control environment, can undermine controls elsewhere.

The model's durability is itself significant. The COSO Internal Control-Integrated Framework has become a widely accepted reference for designing, implementing, and evaluating internal control, and the cube is one of the most recognized ways of communicating that framework. This shared reference point supports consistency across functions and helps management and boards discuss internal control expectations with a common vocabulary. It is worth emphasizing, however, that the cube is a communication and organizing aid; it illustrates relationships but does not by itself guarantee effective control, which depends on how the underlying framework is applied in a specific context.

Framework guidance also evolves, and organizations should treat the cube as a pointer to current primary sources rather than a fixed specification. For example, COSO issued supplemental guidance in 2023 addressing internal control over sustainability reporting (ICSR), reflecting how the framework is extended to new reporting areas over time. Terminology, components, and applicability can differ across editions and may vary by organization and jurisdiction, so professionals should verify specifics against the current authoritative version.

Who it's relevant to

Internal auditors
Internal auditors often use the COSO Cube as a reference model when assessing the design and operating effectiveness of internal control, using its structure to consider how components, objectives, and organizational units relate to one another rather than evaluating controls in isolation.
Compliance and controls professionals
Those responsible for designing and maintaining internal control systems can use the cube to communicate the interconnected nature of controls to stakeholders, though they should confirm specific components and terminology against the current edition of the COSO framework applicable to their context.
Boards and senior management
Directors and executives who oversee internal control can use the cube as a common visual vocabulary for discussing how the organization's control system fits together, recognizing that the diagram supports understanding but does not by itself ensure control effectiveness.
Risk management practitioners
Because a comparable cube visualization has been used in connection with COSO's enterprise risk management work, risk professionals may encounter the model when relating risk management activities to broader governance and control structures. Applicability and terminology should be verified against the relevant COSO source.
Sustainability and non-financial reporting teams
Given COSO's 2023 supplemental guidance addressing internal control over sustainability reporting (ICSR), teams extending internal control concepts to sustainability reporting may reference the framework the cube illustrates, while confirming current guidance and its applicability to their jurisdiction and sector.

Inside COSO Cube

Components (Control Objectives Layer)
The COSO Cube visually organizes the five interrelated components of internal control drawn from the COSO Internal Control Integrated Framework: the control environment, risk assessment, control activities, information and communication, and monitoring activities. These are typically depicted along one face of the cube and are intended to operate together rather than in isolation.
Objectives Categories
Along the top of the cube, the framework groups objectives into categories commonly described as operations, reporting, and compliance. These reflect the different aims a system of internal control is meant to support. Note that the labeling and scope of these categories has evolved across editions of the framework, so practitioners should confirm the terminology against the edition they are applying.
Organizational Structure / Entity Levels
The third dimension of the cube represents the organizational structure to which internal control applies, such as entity level, division, operating unit, and function. This dimension emphasizes that internal control is relevant across all levels of the organization, not only at the enterprise level.
Integrated Design
The cube form is a communication device intended to convey that objectives, components, and organizational levels intersect and must be considered together. It illustrates relationships rather than prescribing a rigid checklist, and it applies principally to internal control as distinct from the broader COSO Enterprise Risk Management framework, which uses its own representation.

Common questions

Answers to the questions practitioners most commonly ask about COSO Cube.

Is the COSO Cube the same thing as the COSO ERM framework?
Not exactly. The term 'COSO Cube' is most commonly associated with the COSO Internal Control-Integrated Framework, which depicts the relationship between control objectives, components, and organizational units as a three-dimensional matrix. COSO has also published a separate Enterprise Risk Management (ERM) framework, which has used its own visual representations across editions. Because both originate from COSO and both have been rendered as cubes at various points, the two are frequently conflated. When using the term, it is worth clarifying which framework and which edition you are referring to, since the components and terminology differ and framework language evolves across editions.
Do the components shown in the COSO Cube represent controls themselves?
No. The components depicted in the cube, such as the control environment, risk assessment, control activities, information and communication, and monitoring activities, are categories or dimensions of an internal control system, not individual controls. A control is a specific measure that modifies risk, whereas the cube's components describe the broader structure within which controls are designed and operated. Treating the components as a checklist of controls misreads the framework's intent, which is to show how objectives, components, and organizational levels interrelate rather than to enumerate specific control measures.
How do the three dimensions of the COSO Cube relate to one another in practice?
The cube is typically used to illustrate that each control objective (one dimension) is supported by each component (a second dimension) across each unit or level of the organization (a third dimension). In practice, this means that when assessing a given objective for a given business unit, an organization considers how each component applies. The visual is intended to reinforce that internal control is not achieved through a single component in isolation but through their combination across the entity. How rigorously each intersection is documented varies by organization size, sector, and internal methodology.
How is the COSO Cube commonly applied in SOX-related internal control assessments?
Organizations subject to internal control over financial reporting requirements often map their controls against the components represented in the cube to demonstrate coverage across the internal control system. This can help structure documentation, scoping, and evaluation of whether controls addressing financial reporting objectives are present and functioning. Note that the cube is a framework model rather than a prescribed regulatory format; the specific obligations, scoping thresholds, and attestation requirements derive from applicable law and regulatory guidance, which vary by jurisdiction and should be verified against primary sources and professional advice.
Can the COSO Cube be applied to objectives beyond financial reporting?
Yes. The objective dimension in the COSO Internal Control-Integrated Framework has typically encompassed categories such as operations, reporting, and compliance objectives, not financial reporting alone. This means the model can, in principle, be used to consider internal control over operational and compliance objectives as well. The breadth of application in any given organization depends on how it chooses to scope its control framework and on the relevant regulatory and business context.
What are the limitations of relying on the COSO Cube as an implementation tool?
The cube is a conceptual and communication model; it illustrates relationships but does not by itself prescribe specific controls, thresholds, or testing procedures. It does not eliminate risk, and mapping controls to its components does not guarantee compliance or an effective control environment. Its usefulness depends on the quality of the underlying control design, operating effectiveness, and monitoring. Organizations should treat it as a structuring aid to be supplemented by detailed methodology, and should confirm which framework edition they are applying, since terminology and components have changed over time.

Common misconceptions

The COSO Cube and the COSO ERM framework are the same thing.
The cube is most closely associated with the COSO Internal Control Integrated Framework, which addresses internal control. COSO's Enterprise Risk Management framework is a separate body of guidance with its own model and focus. While related and issued by the same sponsoring organizations, they should not be treated as interchangeable, and their components and terminology differ.
Completing all cells of the cube guarantees effective internal control or compliance.
The cube is a conceptual and communication aid, not a certification of effectiveness. No framework or model eliminates risk or guarantees compliance. Effectiveness depends on how well controls are designed and operating in the specific context, and it typically requires ongoing judgment, monitoring, and evidence rather than mapping alone.
The three objectives categories and five components are fixed and unchanging.
The framework has been revised across editions, and the labeling, emphasis, and articulation of objectives and components have evolved. Practitioners should verify which edition applies to their engagement rather than assuming a single static version.

Best practices

Confirm which edition of the COSO Internal Control Integrated Framework you are applying, since components, objectives categories, and terminology have evolved over time.
Use the cube to reinforce that the five components should operate together across all organizational levels, rather than treating any single component as sufficient on its own.
Keep internal control work distinct from enterprise risk management work, recognizing that the cube is oriented to internal control while COSO ERM is a separate framework with its own model.
Map controls and objectives to specific organizational levels, entity, division, unit, and function, to avoid gaps where controls exist at one level but not another.
Treat the cube as a communication and structuring aid, and support any conclusions about control effectiveness with evidence of design and operating effectiveness rather than mapping completeness alone.
Where objectives touch reporting or compliance obligations that carry legal consequences, verify specific requirements against the applicable primary sources and seek professional advice, as applicability varies by jurisdiction and sector.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide