Internal Control Models Comparison Guide
Internal Control Models Comparison Guide
Name COSO COCO CADBURY TURNBULL KING Thank you CoBit ITIL
Committee of Sponsoring Criteria of Control Cadbury Report King Report Standard Model of Control Objectives Information
Organizations of the Committee Internal Control for Information and Technology
Treadway related Technology Infrastructure Library
Internal Control - FrameworkControl Guide issued Committee report on Guide for Directors Report on Standard Model of Objectives of Library of
Integrated by the Criteria Committee Financial Aspects of about the Code Corporate Governance Internal Control for the Control for Infrastructure of
of Control Corporate Governance Combined in South Africa Colombian State Information and Technologies of
Technologies Information
Related
Country of Origin USA Canada United Kingdom United Kingdom South Africa Colombia International United Kingdom
Emitter Committee of Canadian Institute of Committee on Aspects The Institute of The Institute of Department ISACA or Central Association (CCTA)
Organizations Public Accountants. government finances Chartered Directors in South Administrative of the of Audit and Computing and
Sponsors of the corporate Accountants in Africa Public Function of the Telecommunications Systems Control
Treadway England & Wales Republic of Colombia of Information. Today's Agency (OGC)
Office of Commerce
Governmental
Emission 1992 1995 1992 1999 1994 2005 1996 1987
Update 2017 2005 2012 2014 2012 2007
Objective Provide a model of Concentrate the elements Improve the standards of Reflect the good ones Establish Principles Provide a Research, Promote adoption
control that allows the of internal control Corporate Governance and the practices of good practices structure that develop of processes, of
organizations and to their described in the model level of confidence in the business in the corporate for all specify the to advertise and so that they can
personal, develop and COSO to propose a financial reports and in the what is observed at type of necessary elements promote a adapt to
maintain, effective and simplest model and audit, through Internal Control organizations, that to build and framework fit so well into
efficiently, a framework comprehensible, accessible to clear components that immersed let them attend to the strengthen the Control Government System organizations
of internal control that all the staff, who delimit them in the processes of requirements of the Internal Control in the IT Governance large like in
promote the achievement provide a guide that responsibilities of all negocio; mantenerse Law No. 71, of the organizations authoritative small.
of the objectives allow to design, evaluate, those who are found relevant in a Companies, 2008" and obligated by the Law, to updated, and
institutional and s e change and improve the involved in the business environment the changes in the through a model Evolution
adapt to the changes in Internal Control operations of the in continuous trends of the that determines the Management accepted
the business environment organization, and what it is that evolution; and, allow Corporate Governance control parameters internationally
and the operations. This it is expected of them. to the organization in the field necessary for that to that is adopted by
Marco provides a apply this guide international. interior of the the companies and
broad scope on it considering the entities are Employee control in
what must be understood conditions establish actions, the day to day for the
as a System of policies, methods,
Name COSO COCO CADBURY TURNBULL KING Thank you CoBit ITIL
Effective Internal Control institutional procedures managers of
through Components particulars. mechanisms of business.
(5), Principles (17) and prevention, verification
Focus Areas (87) and evaluation in
search for the
continuous improvement
of the administration
public.
Approach Based on Based on the model Based on components of Based on Principles. Based on Principles. The organization must The IT requires The ITIL approach focuses on
Components, Principles COSO, change the application. The report is The approach of this This report is establish policies, provide based on the value of it
and Focus Points, which conceptualization of the centers on segregation of guide consists of the focuses on the Government actions, methods, information for what IT offers; no
they apply to all the model (cube) towards a functions, the delimitation of attention on the Corporate, with a procedures and achieve the objectivesthe tools, but instead
objectives (operational, of cycle of understanding the responsibilities and the Internal Control of leadership philosophy mechanisms of of the organization. the results.
reports and of basic control accountability of the Combined Code on sustainability and prevention, control Promote the They are a set of
compliance) and to the through 20 criteria different actors in the Corporate citizenship evaluation and approach and the best practices and
different levels, general, concentrated Corporate Governance, with a Governance. Includes corporate; likewise continuous improvement property of the standards in
operational units and in four groups: focus on attention to the the administration of contemplates an approach that allow to give processes. processes to make
functions of the purpose, commitment standards for reports risks and control of internal audit compliance with each Support the more efficient the
organization. In COSO, capacity, as well as financial and accountability internal as part based on risks. one of principles organization to design and
are proposed monitoring and learning; accounts integral part of the business; (Self-control, provide a framework administration of
tools for the with what it intends intends to provide to the Self-management and that ensures that: infrastructures of
evaluation of the System propose a model more organizations a Self-regulation), with the IT being aligned data.
of Internal Control, which sencillo que facilite el free design and purpose of structuring with the mission and
consist in supervising design, implementation application of its on Control System vision.
the presence and modification and evaluation government policies Interior that allows THE IT capacity and
harmonic operation of Internal Control by in the light of the to have a security maximize them
of its components and part of the staff of the principles of this reasonable in the benefits.
principles. This framework institution. guide and considering compliance with its IT resources
recognizes the importance the circumstances objectives. Likewise, they are used
growing of the environment of specific to the adopt the principles responsibly.
Technologies of the organization. of COSO The risks of IT
Information, as well as the they are managed
possibility of fraud appropriately.
Concept of It is the process carried out Those elements of N/A Understand the N/A A process carried out N/A N/A
Internal Control by the Council of an organization policies, processes, for the direction and the
Administration, the (including the resources, tasks rest of the staff from
management, and others systems, processes behaviors and an entity, designed
Name COSO COCO CADBURY TURNBULL KING THANK YOU CoBit ITIL
personal, designed for culture, structure and other aspects of the with the aim of
provide a tasks) that, organization that, provide a degree
reasonable security interrelated, taken in s u of security
about the achievement of support the staff in set, facilitate the reasonable in terms of
the operational objectives, the achievement of the effectiveness and efficiency the achievement of
of reports and of objectives of the operations, objectives.
compliance. organizational. promote the
trust in the
internal reports and
externals, and support
in compliance
legal and regulatory.
Categories of a) Effectiveness and efficiency a) Effectiveness and efficiency a) Raise the low level of a) Effectiveness and The
a) Effectiveness and efficiency Effectiveness and efficiency control of No owner
objectives operational operative trust, both in the operational efficiency operation of the IT Processesoperations.
In the public domain
b) Trust and b) Reliability in the financial information, such as b) Reliability in b) Reliability in the Reliability of the Set of best
opportunity for reports internal reports and in the auditors. the internal reports internal reports and information. What satisfy practices
internals and externals externals b) Review the structure, the and external externals Compliance with the Requirements of De Facto Standard
c) Compliance with c) Compliance with rights and functions of the c) Compliance with c) Compliance with laws, regulations and the Institution Approach to the
laws and regulation laws and regulation Board of Directors, leyes y regulación laws and regulation standards that are quality
applicable, and with the applicable, and with the Shareholders and auditors. applicable, and with the applicable. applicable. Being enabled
internal policies. internal policies. c ) Address various aspects internal policies. d) Sustainability for Schemes of
of the accounting profession and Control
formulate recommendations
appropriate, if I were and considers
necessary. Control Practices
d) Improve the level of management
business.
Components 1. Control Environment 1. Purpose 1. Review of the structure and 1. Evaluation of 1. Ethical leadership and Human Talent Plan and It is composed of
2. Risk Assessment Commitment responsibilities of the Risks (such as citizenship Addressing Organize five areas
3. Control Activities 3. Capacity Board of Directors, and element corporate. Strategic Acquire and main ones:
4. Information and 4. Supervision and recommendation about a complementary to 2. Roles and Administration of Implement 1. Strategy of
Communication Learning Code of Good Practices SCI) Risk Responsibilities (DS) Delivery and servicio, 2. Diseño de
5. Supervision Corporate. 2. Environment of Advice from Self-assessment Support service
2. Consider the role of the Control and Activities Administration. Institutional Monitoring 3. Transition from
auditors and addresses a series of Control 3. Roles and Internal Audit service, [Link]
recommendations to the 3. Information and Information Responsibilities of service, 5. Improvement
accounting profession. Communication Audit Committee. Communication service continues.
Name COSO COCO CADBURY TURNBULL KING THANK YOU CoBit ITIL
3.- It deals with rights and 4. Supervision 4. Governance of
responsibilities of the Risk.
shareholders. 5. Governance of the
Technologies of the
Information.
6. Compliance with
laws, regulations
codes and standards.
7. Roles and
Responsibilities of
the Function of
Internal Audit.
8. Governance of the
Relationships with
Shareholders.
9. Integrated Reports
and Revelations.