top of page
Search

How Mature Are Your Monitoring Activities?


Measuring Whether Management Knows When Internal Controls Stop Working

Every organization has internal controls.


But here is the more difficult question:

How does management know those controls are still working?

A control may have been properly designed two years ago.


It may have worked perfectly when Internal Audit tested it last year.


But what about today?


Perhaps:

  • The employee performing the control changed.

  • Transaction volumes doubled.

  • A new information system was implemented.

  • A key spreadsheet was modified.

  • Responsibilities were reorganized.

  • Management overrides increased.

  • A new fraud risk emerged.

  • A critical report changed.

  • Employees developed workarounds.

  • A third-party service provider took over part of the process.


Internal controls do not remain effective simply because they were effective when originally implemented.


Controls deteriorate.


Processes change.


People change.


Technology changes.


Risks change.


That is why Monitoring Activities are one of the five components of the COSO Internal Control—Integrated Framework.


And just as organizations can assess the maturity of the Control Environment, Risk Assessment, Control Activities, and Information and Communication, they can measure the maturity of their Monitoring Activities.


What Is Monitoring?

Monitoring determines whether the components and principles of internal control are present and functioning over time.


This is an important distinction.


Control Activities help manage risks.


Monitoring helps management determine whether those controls—and the broader internal-control system—continue to function.


Consider a bank reconciliation.


The reconciliation itself is a Control Activity.


Management's process for determining whether reconciliations are being completed accurately, reviewed on time, and resolving reconciling items is part of Monitoring.


Monitoring asks:

Is the control system continuing to work the way management intended?

The Two COSO Monitoring Principles

The Monitoring Activities component contains two COSO principles.


Principle 16 — Conduct Ongoing and/or Separate Evaluations

The organization selects, develops, and performs ongoing and/or separate evaluations to determine whether the components of internal control are present and functioning.


Principle 17 — Evaluate and Communicate Deficiencies

The organization evaluates and communicates internal-control deficiencies in a timely manner to the parties responsible for corrective action, including senior management and the Board, as appropriate.


Those two principles provide a practical structure for assessing Monitoring maturity.


Principle 16: How Mature Are Your Evaluations?

Start with a basic question:

How does management discover that a control has stopped working?

The answer tells us a great deal about monitoring maturity.


Level 1 — Initial / Ad Hoc

At Level 1, control problems are primarily discovered after something goes wrong.


Management may learn about control failures because of:

  • An accounting error

  • A fraud

  • A customer complaint

  • A regulatory finding

  • An external audit adjustment

  • An Internal Audit finding

  • A cybersecurity incident

  • A missed deadline

  • A financial loss

  • A whistleblower complaint


Monitoring is predominantly reactive.


Controls may exist, but management has limited systematic information about whether they continue to function.


A common management response is:

“We didn't know there was a problem.”

That statement itself may indicate weak Monitoring Activities.


Level 2 — Developing / Repeatable

Basic monitoring activities have developed.


Management performs recurring activities such as:

  • Supervisory reviews

  • Budget-to-actual comparisons

  • Account reconciliations

  • Exception reviews

  • Management meetings

  • Periodic compliance reviews

  • Internal-control checklists


Internal Audit and external audit findings may also provide information about control performance.


Monitoring occurs, but it may be fragmented.


Different departments monitor controls differently.


Documentation may be inconsistent.


There may be no enterprise methodology for determining:

  • Which controls require monitoring

  • Who is responsible

  • How frequently monitoring occurs

  • What evidence is retained

  • What constitutes an exception

  • When escalation is required


Monitoring is repeatable, but not yet fully institutionalized.


Level 3 — Defined

At Level 3, management establishes a formal monitoring framework.


Significant controls have:

  • Defined control owners

  • Monitoring responsibilities

  • Monitoring frequency

  • Evaluation criteria

  • Evidence requirements

  • Exception thresholds

  • Escalation procedures

  • Corrective-action requirements


Management distinguishes between:

Ongoing evaluations

and

Separate evaluations.


Ongoing evaluations are embedded into normal operations.


Separate evaluations are performed periodically and provide a more independent assessment of the control system.


At this level, management can answer:

Who is monitoring our significant controls, how are they doing it, and what evidence demonstrates that it occurred?

Level 4 — Managed and Measured

At Level 4, monitoring becomes measurable.


Management establishes Control Performance Indicators and other metrics that show whether controls are functioning as expected.


Examples might include:

  • Percentage of reconciliations completed on time

  • Number of unreconciled differences

  • Approval overrides

  • Segregation-of-duties conflicts

  • Access-review exceptions

  • Duplicate payments

  • Policy exceptions

  • Late regulatory filings

  • Control failures

  • Repeat audit findings

  • Unresolved deficiencies

  • Corrective-action aging

  • Cybersecurity exceptions

  • Failed automated controls


Management does not simply know that monitoring occurred.


Management can measure what monitoring is telling it.


Trends become visible.


Recurring failures can be identified.


Departments can be compared.


Control deterioration can be detected earlier.


Level 5 — Optimized

At Level 5, monitoring becomes increasingly continuous, automated, predictive, and risk-based.


The organization may use:

  • Continuous controls monitoring

  • Automated exception reporting

  • Data analytics

  • Transaction monitoring

  • Automated access monitoring

  • Continuous configuration monitoring

  • Key Risk Indicators

  • Control Performance Indicators

  • Predictive analytics

  • AI-assisted anomaly detection

  • Integrated dashboards

  • Automated escalation


Instead of waiting until month-end or quarter-end, management may identify control failures almost immediately.


Monitoring also changes as risks change.


The organization continually asks:

Are we monitoring the controls that matter most?

That is a very different capability from simply reviewing last year's audit findings.


Ongoing Evaluations Versus Separate Evaluations

A mature monitoring program needs to understand the difference.


Ongoing Evaluations

These are built into normal business processes.


Examples include:

  • Supervisor reviews

  • Automated exception reports

  • Daily transaction monitoring

  • Reconciliation reviews

  • Budget variance analysis

  • Security alerts

  • Performance dashboards

  • Management review controls


They provide management with relatively timely information.


Separate Evaluations

These occur periodically and provide a different perspective.


Examples include:

  • Internal Audit engagements

  • Control self-assessments

  • Compliance reviews

  • Quality-assurance reviews

  • Independent cybersecurity assessments

  • External assessments

  • Peer reviews


The appropriate combination should depend upon risk.


A critical control may require continuous or frequent monitoring.


A lower-risk control may require only periodic evaluation.


The objective should not be:

Monitor everything continuously.

The objective should be:

Apply monitoring intensity commensurate with risk.

Internal Audit Is Not Management's Monitoring System

This distinction is critical.


Management sometimes believes:

“Internal Audit monitors our controls.”

Internal Audit certainly evaluates controls.


But management owns the system of internal control.


Management cannot outsource that responsibility to Internal Audit.


Consider an organization where Internal Audit reviews procurement every three years.


Suppose a critical procurement control fails one month after the audit.


Should management wait another 35 months for Internal Audit to discover it?


Clearly not.


Management needs its own monitoring processes.


Internal Audit can independently evaluate whether those monitoring processes are properly designed and operating effectively.


That preserves the appropriate roles:

  • Management owns and monitors internal control.

  • Internal Audit independently evaluates and provides assurance.


Principle 17: What Happens When a Deficiency Is Found?

Finding a problem is only half of Monitoring.


The second question is:

What does the organization do with the problem?

An organization may have sophisticated monitoring tools and still have immature


Monitoring Activities if deficiencies remain unresolved.


Level 1 — Initial / Ad Hoc

Problems are handled informally.


There may be:

  • No centralized issue tracking

  • No formal ownership

  • No due dates

  • No escalation

  • No root-cause analysis

  • No verification of corrective action


Management may repeatedly encounter the same problem.


Level 2 — Developing / Repeatable

Significant deficiencies are generally documented.


Management assigns responsibility for corrective action.


However, tracking may rely upon:

  • Emails

  • Spreadsheets

  • Departmental logs

  • Individual follow-up


Issues can disappear as employees or managers change.


Level 3 — Defined

The organization establishes a formal deficiency-management process.


Each significant issue includes:

  • Description

  • Risk

  • Root cause

  • Responsible owner

  • Corrective action

  • Target completion date

  • Status

  • Escalation requirements

  • Evidence of remediation


Internal-control deficiencies are communicated to appropriate levels of management and governance.


Level 4 — Managed and Measured

Management measures the deficiency-management process.


Metrics might include:

  • Number of open deficiencies

  • High-risk findings

  • Average days outstanding

  • Percentage overdue

  • Repeat findings

  • Aging by department

  • Management extensions

  • Root-cause categories

  • Corrective actions awaiting validation


Senior management and the Audit Committee receive dashboards highlighting significant unresolved issues.


Management can identify departments where remediation consistently fails.


Level 5 — Optimized

At the highest maturity level, deficiency information becomes an input into organizational improvement.


Management analyzes patterns.


For example:

  • Why are we repeatedly finding segregation-of-duties problems?

  • Why do reconciliations continually fail?

  • Why are corrective actions consistently late?

  • Why do cybersecurity findings recur?

  • Why do different audits keep identifying problems caused by inadequate training?


Instead of correcting individual symptoms, management identifies systemic root causes.


Deficiencies become organizational learning opportunities.


Finding the Problem Is Not the Same as Fixing the Problem

Consider this scenario.


Internal Audit identifies a high-risk control deficiency.


Management agrees.


A corrective action is established.


Twelve months later, the issue is marked: Closed.


But what does “closed” mean?


Did management complete the promised action?


Or did someone independently determine that the corrective action actually corrected the deficiency?


Those are not the same thing.


A mature monitoring process should distinguish among:

  • Management says the action is complete.

  • Evidence demonstrates the action was implemented.

  • Testing demonstrates the revised control is operating effectively.


Only the third conclusion provides strong evidence that the risk has actually been addressed.


Repeat Findings Are a Maturity Warning

Repeat findings deserve special attention.


A recurring audit finding may indicate something more significant than failure to complete a corrective action.


It may indicate weak:

  • Accountability

  • Root-cause analysis

  • Management oversight

  • Issue tracking

  • Escalation

  • Governance

  • Organizational culture


If the same problem appears repeatedly, management should stop asking:

“How do we close this finding?”

and start asking:

“Why does our organization keep producing this problem?”

That is maturity thinking.


Build a Monitoring Inventory

One practical way to begin assessing maturity is to create an inventory of significant monitoring activities.


For each significant risk and control, identify:

  • Risk

  • Key Control

  • Control Owner

  • Monitoring Activity

  • Monitoring Owner

  • Frequency

  • Evidence

  • Exception Threshold

  • Escalation Requirement

  • Corrective-Action Process


This can reveal important gaps.


An organization may discover that it has 150 key controls but only 40 have clearly defined monitoring mechanisms.


That is useful information.


Develop Control Performance Indicators

Organizations routinely use Key Performance Indicators.


They increasingly use Key Risk Indicators.


But what about Control Performance Indicators?


Suppose accounts payable has a key three-way-match control.


Possible monitoring indicators might include:

  • Percentage of invoices automatically matched

  • Manual overrides

  • Match exceptions

  • Duplicate invoices

  • Payments without purchase orders

  • Post-payment corrections


Now management can see whether the control environment is changing.


The same concept can be applied to:

  • Payroll

  • Procurement

  • Cybersecurity

  • Financial reporting

  • Grants

  • Inventory

  • Regulatory compliance

  • Revenue

  • Cash management


This moves Monitoring from periodic inspection toward continuous management information.


A Practical Monitoring Maturity Scorecard

Management and Internal Audit can evaluate the two COSO principles separately.

COSO Principle

Current Maturity

Target Maturity

Gap

Principle 16 — Ongoing and Separate Evaluations

2.5

4.0

1.5

Principle 17 — Evaluate and Communicate Deficiencies

3.0

4.0

1.0

Monitoring Activities Component

2.75

4.0

1.25

But the score alone is not enough.


Management should identify the underlying capability gaps.


For example:


Principle 16 — Current Level 2.5

Major gaps:

  • No enterprise monitoring methodology

  • Limited Control Performance Indicators

  • Excessive reliance on Internal Audit

  • Inconsistent monitoring documentation

  • Limited automated monitoring

  • No risk-based monitoring frequency


Principle 17 — Current Level 3.0

Major gaps:

  • Corrective actions frequently overdue

  • Limited root-cause analysis

  • Inconsistent validation before closure

  • Repeat findings

  • Limited Board reporting


Now management has a roadmap.


Don't Average Away a Serious Monitoring Failure

As with other maturity assessments, averages can be dangerous.


Suppose an organization scores highly on most monitoring practices but has no reliable mechanism for escalating critical cybersecurity control failures.


The mathematical average may still look respectable.


The risk does not.


Organizations should establish minimum acceptable maturity levels for critical controls and risks.


A Level 2 monitoring capability may be acceptable for a low-risk administrative process.


It may be completely unacceptable for:

  • Cash

  • Payroll

  • Financial reporting

  • Cybersecurity

  • Regulatory compliance

  • Public safety

  • Fraud prevention


Again:

Required maturity should be commensurate with risk.

What Should the Audit Committee Ask?

Monitoring should be particularly important to the Audit Committee.


Useful questions include:

  • How does management know our key controls are working?

  • Which controls are continuously monitored?

  • Which controls receive only periodic evaluation?

  • What significant control failures occurred this quarter?

  • What are our oldest unresolved deficiencies?

  • How many corrective actions are overdue?

  • Which findings have been repeated?

  • Who can extend corrective-action deadlines?

  • How are high-risk deficiencies escalated?

  • Does Internal Audit validate remediation before significant findings are closed?

  • What trends are our monitoring systems identifying?

  • Where are we relying too heavily on manual monitoring?


Perhaps the most revealing question is:

“What significant control problem could occur today that management would not discover until an auditor found it?”

The answer identifies potential monitoring gaps.


Monitoring Should Create an Early-Warning System

The ultimate objective of Monitoring Activities is not to generate more reports.


It is to create an early-warning capability.


At Level 1:

Something goes wrong → Management eventually discovers it.


At Level 2:

Someone periodically reviews the process.


At Level 3:

Monitoring responsibilities and procedures are formally defined.


At Level 4:

Management measures control performance and identifies trends.


At Level 5:

Technology, analytics, continuous monitoring, and organizational learning identify control deterioration rapidly and drive improvement.


That progression captures what Monitoring maturity is really about.


The Question Every Manager Should Be Able to Answer

Management should be able to answer:

“How do you know this control is still working?”

Not:

“Internal Audit didn't find anything.”

Not:

“The external auditors haven't complained.”

Not:

“We've always done it this way.”

And certainly not:

“We'll know if something goes wrong.”

A mature answer sounds more like:

“We have defined monitoring procedures, assigned responsibility, established performance indicators and exception thresholds, review the results regularly, escalate significant deficiencies, track corrective actions, and independently validate remediation.”

That is a very different level of internal-control capability.


Moving From Detection to Continuous Improvement

Monitoring is sometimes treated as the final COSO component.


In practice, it should help restart the internal-control cycle.


Monitoring identifies a problem.


That information may cause management to reconsider:


Control Environment

Is accountability adequate?


Risk Assessment

Has the risk changed?


Control Activities

Does the control need redesign?


Information and Communication

Did the right people receive the right information?


Then Monitoring evaluates whether the corrective action actually worked.


The five COSO components therefore operate as an integrated system.


That is why mature Monitoring Activities can become one of management's most powerful tools for improving internal control.


The objective is not merely to discover that a control failed.


The objective is to know when it begins to fail, why it failed, what must change, and whether the corrective action actually worked.


hat is the difference between simply having internal controls and having a mature system of internal control.


Continue Developing Your COSO and Internal-Control Skills With CCS

Corporate Compliance Seminars provides CPE training addressing COSO, internal-control assessment, control testing, monitoring, risk management, and auditing.


Relevant CCS training includes programs covering:

  • Understanding COSO Framework Compliance

  • Effective Use of the COSO Framework

  • COSO Framework: ICFR Assessments

  • Using COSO Framework for Compliance and SOX

  • Testing the Operating Effectiveness of Internal Controls

  • GAO Green Book Compliance


These programs can help internal auditors, external auditors, compliance professionals, risk managers, governmental auditors, and management move beyond documenting controls toward evaluating whether internal-control systems are properly designed, operating effectively, monitored, and continuously improved.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page