Skip to main content
The state of ai impact assessment
Category: Internal Controls & Audit

Seventeen Principles

Also known as: 17 Principles, COSO 17 Principles, COSO Principles of Internal Control
Simply put

In a governance, risk, and compliance context, the 'Seventeen Principles' most commonly refers to the set of principles articulated in the COSO Internal Control-Integrated Framework, which organizations use to design and evaluate their systems of internal control. These principles are grouped under the framework's five components of internal control and describe the fundamental concepts an organization is generally expected to have in place for its internal control system to be considered effective. The term is a widely used shorthand among compliance and audit professionals, though the exact wording and interpretation of each principle should be verified against the current COSO source.

Formal definition

Within GRC practice, 'Seventeen Principles' typically denotes the seventeen principles set out in the COSO Internal Control-Integrated Framework, which map to the framework's five interrelated components: control environment, risk assessment, control activities, information and communication, and monitoring activities. In many applications of the framework, these principles are treated as representing the fundamental concepts associated with each component, and their presence and functioning are considered relevant to concluding that a system of internal control is effective. The framework is a voluntary, widely adopted leading-practice reference rather than a law in itself, although it is frequently used to support internal control over financial reporting in connection with regulatory regimes such as SOX; applicability, specific principle wording, and mapping to components should be confirmed against the current edition of the COSO Framework, and practitioners should note that framework language evolves across editions. This entry addresses the COSO usage; identically numbered lists of 'seventeen principles' exist in unrelated non-GRC contexts (e.g., personal-development literature) and fall outside the scope of this definition.

Why it matters

The Seventeen Principles give internal control a common vocabulary and a structured basis for evaluation. Rather than treating internal control as an abstract or subjective judgment, the COSO Internal Control-Integrated Framework breaks it into discrete, testable concepts grouped under five components. This matters to practitioners because it allows a board, management, or an auditor to reason systematically about whether a system of internal control is designed and operating effectively, and to pinpoint where specific weaknesses lie rather than concluding only that 'something is wrong.'

Who it's relevant to

Internal Auditors
Internal audit functions frequently use the seventeen principles as a benchmark for evaluating the design and operating effectiveness of internal control, structuring findings and gap analyses around the principles and their associated components. The principles offer a defensible, widely recognized reference for scoping audits and reporting conclusions.
Compliance Officers
Compliance professionals draw on the principles to demonstrate that internal control expectations, particularly those tied to internal control over financial reporting and regimes such as SOX, are systematically addressed. The framework provides common language for coordinating with auditors and articulating control expectations to management.
Financial Reporting and Controllership Teams
Teams responsible for internal control over financial reporting often use the COSO Framework, including its seventeen principles, as the recognized criteria for assessing and reporting on control effectiveness. They map financial reporting controls to the relevant principles to support their assessments, verifying details against the current COSO source.
Audit Committees and Boards
Boards and audit committees exercising oversight responsibility rely on the principles as a structured basis for challenging management's assertions about internal control effectiveness and for understanding where control gaps exist. Several principles speak directly to governance and oversight roles.
External Auditors
External auditors commonly expect internal control to be described and evaluated against a recognized framework such as COSO, and the seventeen principles inform how they assess the presence and functioning of controls relevant to their audit conclusions.

Inside Seventeen Principles

Origin in the COSO Internal Control-Integrated Framework
The phrase 'Seventeen Principles' is the commonly accepted label for the 17 principles articulated in the COSO Internal Control-Integrated Framework, introduced in its 2013 refreshed edition and generally regarded as current. These principles operationalize the framework's five interrelated components of internal control and are widely cited in governance and compliance practice, including in relation to internal control over financial reporting.
Control Environment (Principles 1-5)
The five principles associated with the Control Environment component typically address the organization's commitment to integrity and ethical values; the board's independence from management and its oversight responsibility; the establishment of structures, reporting lines, and appropriate authorities and responsibilities; the commitment to attract, develop, and retain competent individuals; and the enforcement of accountability for internal control responsibilities. This component concerns the tone, structures, and decision rights by which control is directed, overlapping the governance pillar.
Risk Assessment (Principles 6-9)
The four principles associated with the Risk Assessment component typically address specifying objectives with sufficient clarity to enable identification and assessment of related risks; identifying and analyzing risks to the achievement of objectives; considering the potential for fraud; and identifying and assessing significant changes that could affect the system of internal control. This component reflects the risk management pillar as applied within an internal control context.
Control Activities (Principles 10-12)
The three principles associated with the Control Activities component typically address selecting and developing control activities that contribute to the mitigation of risks; selecting and developing general controls over technology; and deploying control activities through policies and procedures. Control activities are measures that modify risk and should be distinguished from the risks they address.
Information and Communication (Principles 13-15)
The three principles associated with the Information and Communication component typically address obtaining or generating and using relevant, quality information; communicating internally the information necessary to support internal control; and communicating with external parties on matters affecting internal control.
Monitoring Activities (Principles 16-17)
The two principles associated with the Monitoring Activities component typically address selecting, developing, and performing ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning; and evaluating and communicating internal control deficiencies in a timely manner to parties responsible for corrective action.
Relationship to components and points of focus
The 17 principles map to the framework's five components, and COSO further associates each principle with illustrative 'points of focus' intended to aid application. In the framework's design, effective internal control generally requires each relevant component and principle to be present and functioning, and the components to operate together in an integrated manner, subject to management judgment about relevance in a given entity's circumstances.

Common questions

Answers to the questions practitioners most commonly ask about Seventeen Principles.

Is "Seventeen Principles" a meaningful GRC term, or just a generic phrase?
It is a meaningful and widely used term. In a GRC context, the "Seventeen Principles" is the commonly accepted label for the 17 principles articulated in the COSO Internal Control-Integrated Framework, introduced in the 2013 refreshed edition and generally still referenced as current. Each principle is associated with one of the framework's five components of internal control. Practitioners should treat it as a defined COSO concept rather than a generic phrase, though the label is a convention rather than COSO's own formal title for the set.
Does the absence of the term in a given source mean there is no established definition?
No. The lack of a reference in any particular document does not indicate that the concept is undefined. The 17 principles are a well-established, widely cited element of the COSO Internal Control-Integrated Framework. When a specific source does not mention them, that reflects the scope of that source rather than any ambiguity in the underlying concept. Readers should verify wording and any edition-specific details against COSO's primary publications.
How do the seventeen principles relate to the five components of internal control?
In the COSO Internal Control-Integrated Framework, the 17 principles are distributed across the five components of internal control, typically described as the control environment, risk assessment, control activities, information and communication, and monitoring activities. Each principle supports one component, and the framework generally expects all relevant principles to be present and functioning for internal control to be considered effective. Organizations should consult the framework directly to confirm how each principle maps to its component.
How can an organization use the seventeen principles when assessing internal control effectiveness?
Many organizations use the principles as a structured basis for evaluating whether internal control is present and functioning. This often involves assessing each principle for design and operating effectiveness, documenting supporting points of focus where relevant, and identifying deficiencies. The framework typically treats a major deficiency in a relevant principle as an indication that a component is not effective. The applicability and rigor of such assessments vary by organization size, sector, and any regulatory expectations, and professional judgment is required.
Are all seventeen principles required to be applied in every organization?
The framework generally presumes that all principles are relevant, but it also allows that a principle may not apply in rare circumstances, which the organization would be expected to support with rationale. Applicability can depend on entity size, structure, and industry. Because interpretation of relevance and any related regulatory expectations can be context-dependent, organizations should document their reasoning and, where obligations are involved, seek appropriate professional advice.
How do the seventeen principles connect to compliance obligations such as those under SOX?
The COSO Internal Control-Integrated Framework is commonly used as the control framework underlying internal control over financial reporting, including in contexts where management and auditors evaluate such controls. The 17 principles often serve as reference points in that evaluation. However, COSO is a voluntary framework rather than a law, and the specific compliance requirements applicable to an organization depend on jurisdiction, sector, and the relevant regulatory regime. Specifics should be verified against the governing rules and primary sources.

Common misconceptions

'Seventeen Principles' is a vague or non-standard phrase without an established GRC meaning.
It is a widely used shorthand for the 17 principles in the COSO Internal Control-Integrated Framework (2013 refreshed edition), a well-established and frequently cited reference in internal control, governance, and compliance practice.
The 17 principles are a binding legal or regulatory requirement that organizations must adopt.
COSO's framework is voluntary guidance and leading practice rather than a law. However, it is commonly used as a recognized framework for assessing internal control over financial reporting in connection with regulatory regimes such as SOX in the United States. Applicability and the manner of adoption vary by jurisdiction, sector, and organization; specific obligations should be verified against the relevant primary sources and, where needed, professional advice.
Documenting or 'having' the 17 principles guarantees effective internal control or eliminates risk.
In the framework's design, principles must not only be present but also functioning and operating together, and even then internal control provides only reasonable, not absolute, assurance. No set of principles or controls eliminates risk or guarantees compliance; limitations such as human judgment, error, and management override persist.

Best practices

Attribute the term precisely to the COSO Internal Control-Integrated Framework (2013 refreshed edition) and verify current wording and any 'points of focus' against the primary COSO source rather than secondary summaries, since framework language can evolve across editions.
Map each of the 17 principles to its associated component and to the organization's specific objectives, and assess whether each relevant principle is both present and functioning rather than merely documented.
Distinguish the risks being addressed from the control activities that modify them, and keep this distinction clear when applying the Risk Assessment and Control Activities principles.
Where the framework is used for internal control over financial reporting, confirm how its use aligns with the applicable regulatory regime in your jurisdiction (for example, SOX-related requirements in the United States) and obtain professional advice on legal interpretation where needed.
Exercise and document management judgment about the relevance of a given principle to the entity's size, structure, and circumstances, noting that COSO allows for consideration of relevance rather than mechanical application.
Communicate identified deficiencies in a timely manner to those responsible for corrective action, and avoid representing the presence of the 17 principles as a guarantee of effectiveness or as the elimination of risk.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps