top of page
Search

How Mature Are Your Information and Communication Controls?


Measuring Whether the Right Information Reaches the Right People at the Right Time


Organizations generate enormous amounts of information:

  • Financial reports.

  • Budgets.

  • Operational dashboards.

  • Risk reports.

  • Compliance reports.

  • Audit findings.

  • Cybersecurity alerts.

  • Customer complaints.

  • Performance measures.

  • Emails.

  • Policies.

  • Board packages.

  • Management presentations.

But having enormous amounts of information does not necessarily mean that an organization has effective Information and Communication controls.


The real questions are:

Is the information reliable?
Is it complete?
Is it timely?
Does it reach the people who need it?
Can bad news travel upward through the organization?
Does the Board receive the information necessary to fulfill its oversight responsibilities?
Can management distinguish useful information from organizational noise?

These questions take us directly into the fourth component of the COSO Internal Control—Integrated Framework: Information and Communication.


And just as we can assess the maturity of the Control Environment, Risk Assessment, and Control Activities, we can assess the maturity of an organization's Information and Communication controls.


Why Information and Communication Matter

Internal controls cannot function without information.


Consider a simple purchasing control.


A manager cannot meaningfully approve a purchase without reliable information concerning:

  • What is being purchased

  • Why it is needed

  • How much it costs

  • Whether funding is available

  • Who the vendor is

  • Whether competitive procurement requirements apply

  • Whether conflicts of interest exist

  • Whether the transaction exceeds the manager's authority


The approval may technically occur.


But if the information supplied to the approver is incomplete, inaccurate, misleading, or late, the approval control itself may be ineffective.


That leads to an important principle:

A control is only as good as the information supporting the control.

The Three COSO Principles

The Information and Communication component contains three principles.


Principle 13 — Use Relevant, Quality Information

The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.


Principle 14 — Communicate Internally

The organization internally communicates information—including objectives and responsibilities for internal control—necessary to support the functioning of internal control.


Principle 15 — Communicate Externally

The organization communicates with external parties regarding matters affecting the functioning of internal control.


These three principles provide an excellent structure for assessing Information and Communication maturity.


Principle 13: How Mature Is Your Information?

Start with something many organizations take for granted: Management reporting.


Management may receive a 75-page financial report every month.


That does not necessarily mean management is receiving quality information.


The maturity question is:

Does management systematically identify, obtain, validate, and use the information necessary to manage risks and achieve objectives?

Level 1 — Initial / Ad Hoc

Information processes are largely informal.


Typical characteristics include:

  • Heavy dependence on spreadsheets

  • Multiple versions of the same report

  • Manual data collection

  • Unclear data ownership

  • Inconsistent reporting

  • Limited validation

  • Reports generated because “we have always produced them”

  • Important information maintained by individual employees

  • Management discovering problems after they become significant


At this level, information frequently depends upon people rather than systems and processes.


Level 2 — Developing / Repeatable

Basic reporting processes have developed.


Management receives recurring:

  • Financial reports

  • Operational reports

  • Compliance reports

  • Budget reports

  • Performance reports


The information is generally useful and repeatable.


However, weaknesses may remain.


Different departments may define the same metric differently.


Reports may require substantial manual manipulation.


Data quality may not be formally measured.


Management may receive large amounts of information without clearly identifying which information is critical.


The organization has reporting—but not necessarily mature information governance.


Level 3 — Defined

Information requirements are formally established.


Management understands:

  • What information is required

  • Why it is required

  • Where it originates

  • Who owns the information

  • Who validates it

  • Who receives it

  • How frequently it is produced

  • How long it is retained


Critical reports have documented owners.


Important data elements have defined sources.


Management reports are linked to organizational objectives and risks.


t this level, the organization begins moving from producing reports to managing information.


Level 4 — Managed and Measured

Management begins measuring information quality.


Potential measures include:

  • Report accuracy

  • Report timeliness

  • Data completeness

  • Error rates

  • Reconciliation differences

  • Missing data

  • Manual adjustments

  • Report corrections

  • Data-quality exceptions

  • Late submissions


Management can identify where information quality is deteriorating.


This represents an important maturity transition.


The organization no longer assumes its information is reliable.


It measures reliability.


Level 5 — Optimized

Information management becomes increasingly integrated and automated.


The organization may use:

  • Automated dashboards

  • Data validation

  • Exception analytics

  • Integrated information systems

  • Automated reconciliations

  • Predictive analytics

  • Continuous reporting

  • AI-assisted analysis

  • Data-quality monitoring

  • Automated escalation


Management continually asks:

Are we collecting the right information—or simply collecting more information?

That distinction matters.


A mature organization does not necessarily produce more reports.


t produces better information.


Information Overload Is Not Information Maturity

There is a common misconception that more information means better internal control.


It doesn't.


Consider an Audit Committee receiving a 300-page meeting package.


Technically, management has provided considerable information.


But suppose the package fails to clearly identify:

  • Major financial risks

  • Significant control deficiencies

  • Cybersecurity incidents

  • Fraud investigations

  • Major litigation

  • Budget variances

  • Liquidity concerns

  • Regulatory violations

  • Overdue corrective actions


The Audit Committee has received more information but less insight.


A mature information system prioritizes information based upon: Risk and decision usefulness.


Principle 14: How Mature Is Internal Communication?

Information becomes valuable only when it reaches the right people.


COSO's internal communication principle therefore deserves a separate maturity assessment.


Level 1 — Initial / Ad Hoc

Communication is largely informal.


Employees learn through:

  • Conversations

  • Emails

  • Coworkers

  • Institutional knowledge

  • Informal management direction


Important information may remain within organizational silos.


Employees may not clearly understand their internal-control responsibilities.


Bad news may travel slowly—or not at all.


Level 2 — Developing / Repeatable

Formal communication channels begin developing.


These may include:

  • Staff meetings

  • Management meetings

  • Policies

  • Procedures

  • Email announcements

  • Training

  • Departmental reporting


Communication becomes more consistent, but remains heavily dependent upon organizational hierarchy.


Information generally flows downward.


It may not flow effectively upward or across departments.


Level 3 — Defined

Communication responsibilities and channels are formally established.


Employees understand:

  • Their control responsibilities

  • Their reporting responsibilities

  • Escalation requirements

  • Whom to contact when problems arise

  • How to report suspected misconduct

  • How significant issues reach senior management


Management establishes mechanisms such as:

  • Formal reporting structures

  • Hotline systems

  • Escalation protocols

  • Cross-functional committees

  • Internal-control training

  • Management dashboards

  • Issue-management systems


Communication becomes part of the control architecture.


Level 4 — Managed and Measured

Management begins evaluating whether communication actually works.


Potential measures include:

  • Hotline response times

  • Employee survey results

  • Escalation delays

  • Policy acknowledgments

  • Training completion

  • Unresolved complaints

  • Repeat communication failures

  • Management-reporting delays

  • Corrective-action aging


Management can identify communication breakdowns rather than simply assuming communication occurred.


Level 5 — Optimized

Communication becomes dynamic, multidirectional, and increasingly risk-based.


Information flows:

  • Down

  • Up

  • Across

  • Outside


Employees can escalate significant issues without inappropriate organizational barriers.


Senior management and the Board receive risk information rapidly.


Lessons learned in one business unit are communicated to others.


Communication channels evolve as technology, organizational structure, and risks change.


The organization's communication system becomes part of its early-warning capability.


Can Bad News Travel Upward?

This may be one of the most important maturity tests.


Ask employees:

“What happens when you tell management something management doesn't want to hear?”

The answer can reveal a great deal about both the Information and Communication component and the Control Environment.


In an immature organization:

  • Employees may remain silent.

  • Managers may suppress unfavorable information.

  • Reports may be softened before reaching executives.

  • Significant issues may be omitted from presentations.

  • Employees may fear retaliation.

  • Problems may be discussed informally but never documented.


In a mature organization:

  • Escalation expectations are defined.

  • Significant matters have reporting thresholds.

  • Employees have alternative reporting channels.

  • Whistleblower mechanisms exist.

  • Retaliation is prohibited.

  • Significant issues reach appropriate governance levels.


The quality of organizational communication is often best measured by how the organization handles uncomfortable information.


Principle 15: How Mature Is External Communication?

Organizations also exchange information with outside parties.


Depending upon the organization, these may include:

  • Shareholders

  • Customers

  • Vendors

  • Regulators

  • External auditors

  • Government agencies

  • Lenders

  • Bondholders

  • Citizens

  • Taxpayers

  • Grantors

  • Contractors

  • Business partners


External communication should therefore also be assessed for maturity.


Level 1 — Initial / Ad Hoc

External communication is reactive.


The organization responds when someone asks.


Responsibilities may be unclear.


Different departments may provide inconsistent information.


Level 2 — Developing / Repeatable

Basic responsibilities have been assigned.


Regular reports are submitted to regulators, customers, investors, or other stakeholders.


Processes are repeatable but may remain decentralized.


Level 3 — Defined

External communication requirements are formally documented.


Management identifies:

  • Required reports

  • Responsible owners

  • Approval requirements

  • Reporting deadlines

  • Regulatory requirements

  • Disclosure responsibilities

  • Escalation requirements


Significant external communications receive appropriate review.


Level 4 — Managed and Measured

Management measures external communication performance.


Examples include:

  • Regulatory reporting errors

  • Late filings

  • Restatements

  • Customer complaints

  • External audit adjustments

  • Disclosure corrections

  • Missed reporting deadlines

  • Regulatory inquiries


Management identifies trends and recurring weaknesses.


Level 5 — Optimized

External communication becomes integrated with enterprise risk management and governance.


Management monitors changing stakeholder expectations.


New regulatory requirements are incorporated quickly.


External feedback is systematically analyzed.


Information received from outside the organization becomes an input into:

  • Risk assessment

  • Control design

  • Strategic planning

  • Compliance

  • Monitoring


Communication is no longer simply outbound.


It becomes a two-way control mechanism.


A Practical Information and Communication Maturity Scorecard

Management and Internal Audit can combine the three COSO principles into a practical maturity assessment.

COSO Principle

Current

Target

Gap

Principle 13 — Quality Information

2.7

4.0

1.3

Principle 14 — Internal Communication

2.4

4.0

1.6

Principle 15 — External Communication

3.2

4.0

0.8

Information & Communication Component

2.8

4.0

1.2

But don't stop with the numerical score.


Identify why the organization received that score.


For example: Principle 13 — Current Level 2.7


Major maturity gaps:

  • Excessive spreadsheet dependence

  • No formal data-quality standards

  • Inconsistent report ownership

  • Limited validation of management reports

  • No measurement of reporting errors


Principle 14 — Current Level 2.4


Major maturity gaps:

  • Weak upward communication

  • Inconsistent escalation requirements

  • Organizational silos

  • Limited tracking of significant issues

  • No measurement of communication effectiveness


Now management has something actionable.


Test the Information Behind the Control

Auditors should also reconsider how they test controls.


Suppose an auditor tests a management review control.


The auditor determines that:

  • The report was prepared.

  • The manager reviewed it.

  • The manager signed it.

  • The review occurred on time.


Excellent.


But what about the report itself?


Ask:

Was the information used by the control complete and accurate?

This is particularly important for controls relying upon:

  • System-generated reports

  • Spreadsheets

  • Data extracts

  • Dashboards

  • Exception reports

  • AI-generated information

  • Third-party information


A perfectly performed management review based upon unreliable information may still be a poorly functioning control.


Don't Forget Artificial Intelligence

Information maturity is becoming even more important as organizations adopt artificial intelligence.


Management may increasingly receive:

  • AI-generated summaries

  • Risk assessments

  • Exception analysis

  • Forecasts

  • Recommendations

  • Audit analytics

  • Compliance alerts


That raises new questions.


Where did the underlying data originate?


Is it complete?


Is it accurate?


Can the output be independently validated?


Could the model generate incorrect information?


Who reviews the output?


How is confidential information protected?


When is human judgment required?


The technology changes.


The COSO question does not:

Can management demonstrate that it is using relevant, quality information?

The Board and Audit Committee Should Be Part of the Assessment

Information and Communication maturity should not stop at senior management.


Boards and Audit Committees depend upon management for information.


They should periodically ask:

  • Are we receiving the information necessary for oversight?

  • Is information sufficiently timely?

  • Are significant issues clearly highlighted?

  • Are we receiving leading indicators or merely historical results?

  • Are significant control deficiencies reported?

  • Are disagreements with Internal Audit communicated?

  • Are significant fraud allegations reported?

  • Are cybersecurity incidents appropriately escalated?

  • Are corrective actions aging without resolution?

  • What information are we not receiving that we should receive?


The last question may be the most important.


A Mature Information System Tells the Truth Quickly

Ultimately, the maturity of Information and Communication can be reduced to a deceptively simple concept:

Does the organization get reliable information to the people who need it quickly enough for them to act?

At Level 1, information is fragmented and communication is largely informal.


At Level 2, reporting becomes repeatable.


At Level 3, information requirements and communication channels become defined.


At Level 4, quality and communication effectiveness are measured.


At Level 5, information becomes integrated, increasingly automated, risk-based, and continuously improved.


The objective is not simply better reporting.


The objective is better decision-making and better internal control.


The Question Internal Auditors Should Ask

Internal auditors traditionally ask:

“Was the information communicated?”

A maturity approach requires deeper questions:

Was it the right information?
Was it reliable?
Was it complete?
Did it reach the right person?
Did it arrive soon enough to matter?
Did management act upon it?
Could important information move upward when management didn't want to hear it?

Those questions tell us much more about the actual strength of the organization's internal-control system.


Because information sitting in a database has little control value.


A report nobody understands has little control value.


And critical information reaching management three months too late has little control value.


A mature Information and Communication system provides:

The right information, to the right people, in the right form, at the right time—so they can make the right decision.

That is the capability organizations should be measuring.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page