Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Internal Controls & Audit

Information and Communication

Simply put

Information and Communication refers to how an organization obtains, generates, and shares the information people need to carry out their responsibilities. It covers both the flow of relevant information within the organization and the exchange of information with outside parties. The aim is to ensure that the right people receive accurate and timely information to support decisions and duties.

Formal definition

In internal control and enterprise risk management frameworks, Information and Communication is commonly treated as a component addressing the identification, capture, and exchange of information, both internally across levels and functions and externally with stakeholders such as regulators, customers, and business partners, in a form and timeframe that enables personnel to fulfill their governance, risk, and compliance responsibilities. It is important to distinguish this component-level concept from 'information and communications technology' (ICT), which the provided evidence describes as the technologies used for gathering, storing, transmitting, retrieving, or processing information; ICT may support the information and communication function but is not synonymous with it. The precise scope, terminology, and placement of this component vary across framework editions and standards, so definitions should be verified against the applicable primary source, and the evidence packet supplied here addresses ICT rather than the internal-control component directly.

Why it matters

Information and Communication is foundational to how an organization directs and controls itself, because governance, risk management, and compliance responsibilities cannot be discharged by people who lack the information they need to act. When relevant information does not reach decision-makers in an accurate and timely form, controls can fail silently, risks can go unreported, and compliance obligations can be missed, not through absence of policy but through breakdowns in how information flows across levels, functions, and organizational boundaries. This component addresses both the internal flow of information and the exchange of information with external parties such as regulators, customers, and business partners.

Who it's relevant to

Compliance Officers
Compliance functions depend on information reaching the right people in an accurate and timely form to support adherence to laws, regulations, and internal policies. This component is relevant to how obligations, changes, and potential breaches are communicated internally and to external regulators.
Risk Managers
Effective risk identification, assessment, and treatment relies on relevant information flowing across levels and functions. Where communication breaks down, risks may go unreported or unaddressed, so risk managers have a direct interest in how information is captured and shared.
Internal Auditors
Auditors evaluating internal control and enterprise risk management frameworks often assess whether information and communication components function as intended. They should confirm the component's scope against the applicable framework edition, since terminology and placement vary.
General Counsel and Governance Professionals
Those responsible for how an organization is directed and controlled rely on sound information flows to support decisions and demonstrate that responsibilities were adequately supported. Clear internal and external communication is central to defensible governance.
IT and ICT Leaders
Because ICT tools and platforms often support the information and communication function without being synonymous with it, technology leaders should understand the distinction between deploying systems and ensuring the right information reaches the right people in a usable form and timeframe.

Inside Information and Communication

Information
The relevant, quality data an organization obtains, generates, and uses to support the functioning of governance, risk, and control activities. In many internal control frameworks, information is expected to be relevant, timely, accurate, accessible, and reliable enough to support informed decision-making and the achievement of objectives.
Communication
The continual, iterative process of providing, sharing, and obtaining information among people within and outside the organization. It enables individuals to understand and carry out their responsibilities for internal control, risk management, and compliance.
Internal communication
The flow of information within the organization, including downward from leadership on objectives and expectations, upward on emerging issues or control deficiencies, and across functions. Clear reporting lines and channels for personnel to raise concerns, sometimes including confidential or whistleblowing mechanisms, are often described as part of this element.
External communication
The exchange of information with parties outside the organization, such as regulators, customers, suppliers, shareholders, and other stakeholders. This includes both inbound information (for example, external expectations or regulatory changes) and outbound reporting or disclosures.
Information quality attributes
Characteristics commonly associated with useful information in control and risk contexts, such as relevance, timeliness, accuracy, completeness, accessibility, and verifiability. Frameworks often emphasize that information should be fit for its intended purpose.
Relationship to other control components
In frameworks such as the COSO Internal Control Integrated Framework, information and communication is typically treated as one of several interrelated components that support the control environment, risk assessment, control activities, and monitoring. It is generally described as pervasive rather than standing alone.

Common questions

Answers to the questions practitioners most commonly ask about Information and Communication.

Is "Information and Communication" just about having an IT system or reporting software in place?
No. While technology often supports it, this component addresses the broader need for relevant, quality information to be identified, captured, and communicated in a form and timeframe that enables people to carry out their responsibilities. Information and Communication in frameworks such as the COSO Internal Control Integrated Framework typically encompasses both the information itself and the internal and external communication channels through which it flows, not merely the tooling. A system can be present while the underlying information remains incomplete, untimely, or poorly directed, so the presence of software should not be treated as evidence that this component is operating effectively.
Does effective communication only mean pushing information down from management to staff?
Not in most framework treatments. Communication is generally understood to be multidirectional: downward so that responsibilities and expectations are understood, upward so that issues, exceptions, and emerging concerns reach those who can act, and lateral across functions. Many frameworks also emphasize external communication with parties such as regulators, customers, and other stakeholders. Treating communication as a one-way, top-down flow tends to overlook the upward and external channels that often surface control breakdowns and risk information.
How can an organization determine what information is relevant to support its objectives and controls?
A common starting point is to work backward from objectives and the responsibilities assigned to carry them out, then identify the information each role needs to perform and to demonstrate its duties. Considerations often include the source of the information, its expected quality attributes, and how it will be used. Because relevance is context-dependent, what qualifies typically varies by organization, sector, and the specific objectives in scope, so this determination is usually an ongoing exercise rather than a one-time mapping.
What attributes are typically used to assess whether information is of sufficient quality?
Framework discussions commonly reference attributes such as whether information is accessible, accurate, complete, current, protected, retained where required, sufficient, timely, and valid. The appropriate emphasis among these attributes often depends on how the information is used and the decisions it supports. Because these are qualitative characteristics rather than fixed thresholds, organizations generally define what is adequate in the context of their own objectives and applicable requirements, and specifics should be confirmed against the primary framework text.
How should external communication channels be structured?
Approaches vary, but organizations often establish channels appropriate to the parties involved, such as customers, suppliers, regulators, and other external stakeholders. A recurring consideration is providing a means for external parties to communicate relevant information inward, including a route for reporting concerns. The design of any such channel is frequently shaped by applicable legal and regulatory obligations, which differ by jurisdiction and sector, so channels intended to satisfy specific requirements should be validated against the governing rules and, where needed, professional advice.
What role does communication play in enabling whistleblowing or reporting of control issues?
Many frameworks contemplate separate communication lines that allow information to reach appropriate parties when normal channels are inoperative or compromised, which can support the reporting of suspected wrongdoing or control failures. The existence of such a mechanism is often treated as an element of an effective Information and Communication component. Where specific reporting protections or requirements apply, these are typically governed by jurisdiction-specific law, and their design and operation should be verified against those requirements rather than assumed from the framework alone.

Common misconceptions

Information and communication is primarily an IT or systems concern.
While technology often supports the capture and flow of information, this component in most frameworks addresses a broader organizational process. It encompasses how people obtain, share, and act on information across governance, risk, and compliance activities, not only the underlying systems.
More information automatically means better control.
The value of information typically depends on its quality and relevance, not its volume. Excessive or poorly targeted information can obscure important signals. Many frameworks emphasize that information should be fit for its intended purpose and support decision-making rather than simply be abundant.
Communication flows only from leadership downward.
Effective communication is generally described as multidirectional, downward, upward, and across the organization, as well as with external parties. Upward channels that allow personnel to report concerns or control deficiencies are often considered an important part of this component.

Best practices

Define information requirements against objectives first, then identify the sources and systems needed to produce information that is relevant, timely, and reliable enough to support decisions.
Establish clear reporting lines and channels that enable information to flow downward, upward, and across functions, so that responsibilities for control, risk, and compliance can be understood and carried out.
Provide accessible mechanisms, potentially including confidential or whistleblowing channels, for personnel to raise concerns or report suspected control deficiencies, and communicate how such reports are handled.
Assess and monitor information quality attributes such as accuracy, completeness, and timeliness, recognizing that additional volume does not necessarily improve control.
Coordinate external communication with regulators, customers, suppliers, and other stakeholders so that both inbound expectations and outbound disclosures are captured and acted upon appropriately, noting that specific disclosure obligations vary by jurisdiction and sector.
Treat information and communication as interconnected with other control components, periodically reviewing whether communication supports the control environment, risk assessment, control activities, and monitoring rather than operating in isolation.
Promotional banner for the Penetration Report Template Kit