How Mature Are Your Information and Communication Controls?
- John C. Blackshire, Jr.

- 2 hours ago
- 8 min read
Measuring Whether the Right Information Reaches the Right People at the Right Time
Organizations generate enormous amounts of information:
Financial reports.
Budgets.
Operational dashboards.
Risk reports.
Compliance reports.
Audit findings.
Cybersecurity alerts.
Customer complaints.
Performance measures.
Emails.
Policies.
Board packages.
Management presentations.
But having enormous amounts of information does not necessarily mean that an organization has effective Information and Communication controls.
The real questions are:
Is the information reliable?
Is it complete?
Is it timely?
Does it reach the people who need it?
Can bad news travel upward through the organization?
Does the Board receive the information necessary to fulfill its oversight responsibilities?
Can management distinguish useful information from organizational noise?
These questions take us directly into the fourth component of the COSO Internal Control—Integrated Framework: Information and Communication.
And just as we can assess the maturity of the Control Environment, Risk Assessment, and Control Activities, we can assess the maturity of an organization's Information and Communication controls.
Why Information and Communication Matter
Internal controls cannot function without information.
Consider a simple purchasing control.
A manager cannot meaningfully approve a purchase without reliable information concerning:
What is being purchased
Why it is needed
How much it costs
Whether funding is available
Who the vendor is
Whether competitive procurement requirements apply
Whether conflicts of interest exist
Whether the transaction exceeds the manager's authority
The approval may technically occur.
But if the information supplied to the approver is incomplete, inaccurate, misleading, or late, the approval control itself may be ineffective.
That leads to an important principle:
A control is only as good as the information supporting the control.
The Three COSO Principles
The Information and Communication component contains three principles.
Principle 13 — Use Relevant, Quality Information
The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.
Principle 14 — Communicate Internally
The organization internally communicates information—including objectives and responsibilities for internal control—necessary to support the functioning of internal control.
Principle 15 — Communicate Externally
The organization communicates with external parties regarding matters affecting the functioning of internal control.
These three principles provide an excellent structure for assessing Information and Communication maturity.
Principle 13: How Mature Is Your Information?
Start with something many organizations take for granted: Management reporting.
Management may receive a 75-page financial report every month.
That does not necessarily mean management is receiving quality information.
The maturity question is:
Does management systematically identify, obtain, validate, and use the information necessary to manage risks and achieve objectives?
Level 1 — Initial / Ad Hoc
Information processes are largely informal.
Typical characteristics include:
Heavy dependence on spreadsheets
Multiple versions of the same report
Manual data collection
Unclear data ownership
Inconsistent reporting
Limited validation
Reports generated because “we have always produced them”
Important information maintained by individual employees
Management discovering problems after they become significant
At this level, information frequently depends upon people rather than systems and processes.
Level 2 — Developing / Repeatable
Basic reporting processes have developed.
Management receives recurring:
Financial reports
Operational reports
Compliance reports
Budget reports
Performance reports
The information is generally useful and repeatable.
However, weaknesses may remain.
Different departments may define the same metric differently.
Reports may require substantial manual manipulation.
Data quality may not be formally measured.
Management may receive large amounts of information without clearly identifying which information is critical.
The organization has reporting—but not necessarily mature information governance.
Level 3 — Defined
Information requirements are formally established.
Management understands:
What information is required
Why it is required
Where it originates
Who owns the information
Who validates it
Who receives it
How frequently it is produced
How long it is retained
Critical reports have documented owners.
Important data elements have defined sources.
Management reports are linked to organizational objectives and risks.
t this level, the organization begins moving from producing reports to managing information.
Level 4 — Managed and Measured
Management begins measuring information quality.
Potential measures include:
Report accuracy
Report timeliness
Data completeness
Error rates
Reconciliation differences
Missing data
Manual adjustments
Report corrections
Data-quality exceptions
Late submissions
Management can identify where information quality is deteriorating.
This represents an important maturity transition.
The organization no longer assumes its information is reliable.
It measures reliability.
Level 5 — Optimized
Information management becomes increasingly integrated and automated.
The organization may use:
Automated dashboards
Data validation
Exception analytics
Integrated information systems
Automated reconciliations
Predictive analytics
Continuous reporting
AI-assisted analysis
Data-quality monitoring
Automated escalation
Management continually asks:
Are we collecting the right information—or simply collecting more information?
That distinction matters.
A mature organization does not necessarily produce more reports.
t produces better information.
Information Overload Is Not Information Maturity
There is a common misconception that more information means better internal control.
It doesn't.
Consider an Audit Committee receiving a 300-page meeting package.
Technically, management has provided considerable information.
But suppose the package fails to clearly identify:
Major financial risks
Significant control deficiencies
Cybersecurity incidents
Fraud investigations
Major litigation
Budget variances
Liquidity concerns
Regulatory violations
Overdue corrective actions
The Audit Committee has received more information but less insight.
A mature information system prioritizes information based upon: Risk and decision usefulness.
Principle 14: How Mature Is Internal Communication?
Information becomes valuable only when it reaches the right people.
COSO's internal communication principle therefore deserves a separate maturity assessment.
Level 1 — Initial / Ad Hoc
Communication is largely informal.
Employees learn through:
Conversations
Emails
Coworkers
Institutional knowledge
Informal management direction
Important information may remain within organizational silos.
Employees may not clearly understand their internal-control responsibilities.
Bad news may travel slowly—or not at all.
Level 2 — Developing / Repeatable
Formal communication channels begin developing.
These may include:
Staff meetings
Management meetings
Policies
Procedures
Email announcements
Training
Departmental reporting
Communication becomes more consistent, but remains heavily dependent upon organizational hierarchy.
Information generally flows downward.
It may not flow effectively upward or across departments.
Level 3 — Defined
Communication responsibilities and channels are formally established.
Employees understand:
Their control responsibilities
Their reporting responsibilities
Escalation requirements
Whom to contact when problems arise
How to report suspected misconduct
How significant issues reach senior management
Management establishes mechanisms such as:
Formal reporting structures
Hotline systems
Escalation protocols
Cross-functional committees
Internal-control training
Management dashboards
Issue-management systems
Communication becomes part of the control architecture.
Level 4 — Managed and Measured
Management begins evaluating whether communication actually works.
Potential measures include:
Hotline response times
Employee survey results
Escalation delays
Policy acknowledgments
Training completion
Unresolved complaints
Repeat communication failures
Management-reporting delays
Corrective-action aging
Management can identify communication breakdowns rather than simply assuming communication occurred.
Level 5 — Optimized
Communication becomes dynamic, multidirectional, and increasingly risk-based.
Information flows:
Down
Up
Across
Outside
Employees can escalate significant issues without inappropriate organizational barriers.
Senior management and the Board receive risk information rapidly.
Lessons learned in one business unit are communicated to others.
Communication channels evolve as technology, organizational structure, and risks change.
The organization's communication system becomes part of its early-warning capability.
Can Bad News Travel Upward?
This may be one of the most important maturity tests.
Ask employees:
“What happens when you tell management something management doesn't want to hear?”
The answer can reveal a great deal about both the Information and Communication component and the Control Environment.
In an immature organization:
Employees may remain silent.
Managers may suppress unfavorable information.
Reports may be softened before reaching executives.
Significant issues may be omitted from presentations.
Employees may fear retaliation.
Problems may be discussed informally but never documented.
In a mature organization:
Escalation expectations are defined.
Significant matters have reporting thresholds.
Employees have alternative reporting channels.
Whistleblower mechanisms exist.
Retaliation is prohibited.
Significant issues reach appropriate governance levels.
The quality of organizational communication is often best measured by how the organization handles uncomfortable information.
Principle 15: How Mature Is External Communication?
Organizations also exchange information with outside parties.
Depending upon the organization, these may include:
Shareholders
Customers
Vendors
Regulators
External auditors
Government agencies
Lenders
Bondholders
Citizens
Taxpayers
Grantors
Contractors
Business partners
External communication should therefore also be assessed for maturity.
Level 1 — Initial / Ad Hoc
External communication is reactive.
The organization responds when someone asks.
Responsibilities may be unclear.
Different departments may provide inconsistent information.
Level 2 — Developing / Repeatable
Basic responsibilities have been assigned.
Regular reports are submitted to regulators, customers, investors, or other stakeholders.
Processes are repeatable but may remain decentralized.
Level 3 — Defined
External communication requirements are formally documented.
Management identifies:
Required reports
Responsible owners
Approval requirements
Reporting deadlines
Regulatory requirements
Disclosure responsibilities
Escalation requirements
Significant external communications receive appropriate review.
Level 4 — Managed and Measured
Management measures external communication performance.
Examples include:
Regulatory reporting errors
Late filings
Restatements
Customer complaints
External audit adjustments
Disclosure corrections
Missed reporting deadlines
Regulatory inquiries
Management identifies trends and recurring weaknesses.
Level 5 — Optimized
External communication becomes integrated with enterprise risk management and governance.
Management monitors changing stakeholder expectations.
New regulatory requirements are incorporated quickly.
External feedback is systematically analyzed.
Information received from outside the organization becomes an input into:
Risk assessment
Control design
Strategic planning
Compliance
Monitoring
Communication is no longer simply outbound.
It becomes a two-way control mechanism.
A Practical Information and Communication Maturity Scorecard
Management and Internal Audit can combine the three COSO principles into a practical maturity assessment.
COSO Principle | Current | Target | Gap |
Principle 13 — Quality Information | 2.7 | 4.0 | 1.3 |
Principle 14 — Internal Communication | 2.4 | 4.0 | 1.6 |
Principle 15 — External Communication | 3.2 | 4.0 | 0.8 |
Information & Communication Component | 2.8 | 4.0 | 1.2 |
But don't stop with the numerical score.
Identify why the organization received that score.
For example: Principle 13 — Current Level 2.7
Major maturity gaps:
Excessive spreadsheet dependence
No formal data-quality standards
Inconsistent report ownership
Limited validation of management reports
No measurement of reporting errors
Principle 14 — Current Level 2.4
Major maturity gaps:
Weak upward communication
Inconsistent escalation requirements
Organizational silos
Limited tracking of significant issues
No measurement of communication effectiveness
Now management has something actionable.
Test the Information Behind the Control
Auditors should also reconsider how they test controls.
Suppose an auditor tests a management review control.
The auditor determines that:
The report was prepared.
The manager reviewed it.
The manager signed it.
The review occurred on time.
Excellent.
But what about the report itself?
Ask:
Was the information used by the control complete and accurate?
This is particularly important for controls relying upon:
System-generated reports
Spreadsheets
Data extracts
Dashboards
Exception reports
AI-generated information
Third-party information
A perfectly performed management review based upon unreliable information may still be a poorly functioning control.
Don't Forget Artificial Intelligence
Information maturity is becoming even more important as organizations adopt artificial intelligence.
Management may increasingly receive:
AI-generated summaries
Risk assessments
Exception analysis
Forecasts
Recommendations
Audit analytics
Compliance alerts
That raises new questions.
Where did the underlying data originate?
Is it complete?
Is it accurate?
Can the output be independently validated?
Could the model generate incorrect information?
Who reviews the output?
How is confidential information protected?
When is human judgment required?
The technology changes.
The COSO question does not:
Can management demonstrate that it is using relevant, quality information?
The Board and Audit Committee Should Be Part of the Assessment
Information and Communication maturity should not stop at senior management.
Boards and Audit Committees depend upon management for information.
They should periodically ask:
Are we receiving the information necessary for oversight?
Is information sufficiently timely?
Are significant issues clearly highlighted?
Are we receiving leading indicators or merely historical results?
Are significant control deficiencies reported?
Are disagreements with Internal Audit communicated?
Are significant fraud allegations reported?
Are cybersecurity incidents appropriately escalated?
Are corrective actions aging without resolution?
What information are we not receiving that we should receive?
The last question may be the most important.
A Mature Information System Tells the Truth Quickly
Ultimately, the maturity of Information and Communication can be reduced to a deceptively simple concept:
Does the organization get reliable information to the people who need it quickly enough for them to act?
At Level 1, information is fragmented and communication is largely informal.
At Level 2, reporting becomes repeatable.
At Level 3, information requirements and communication channels become defined.
At Level 4, quality and communication effectiveness are measured.
At Level 5, information becomes integrated, increasingly automated, risk-based, and continuously improved.
The objective is not simply better reporting.
The objective is better decision-making and better internal control.
The Question Internal Auditors Should Ask
Internal auditors traditionally ask:
“Was the information communicated?”
A maturity approach requires deeper questions:
Was it the right information?
Was it reliable?
Was it complete?
Did it reach the right person?
Did it arrive soon enough to matter?
Did management act upon it?
Could important information move upward when management didn't want to hear it?
Those questions tell us much more about the actual strength of the organization's internal-control system.
Because information sitting in a database has little control value.
A report nobody understands has little control value.
And critical information reaching management three months too late has little control value.
A mature Information and Communication system provides:
The right information, to the right people, in the right form, at the right time—so they can make the right decision.
That is the capability organizations should be measuring.
Comments