How Mature Are Your Monitoring Activities?
- John C. Blackshire, Jr.

- 6 minutes ago
- 10 min read
Measuring Whether Management Knows When Internal Controls Stop Working
Every organization has internal controls.
But here is the more difficult question:
How does management know those controls are still working?
A control may have been properly designed two years ago.
It may have worked perfectly when Internal Audit tested it last year.
But what about today?
Perhaps:
The employee performing the control changed.
Transaction volumes doubled.
A new information system was implemented.
A key spreadsheet was modified.
Responsibilities were reorganized.
Management overrides increased.
A new fraud risk emerged.
A critical report changed.
Employees developed workarounds.
A third-party service provider took over part of the process.
Internal controls do not remain effective simply because they were effective when originally implemented.
Controls deteriorate.
Processes change.
People change.
Technology changes.
Risks change.
That is why Monitoring Activities are one of the five components of the COSO Internal Control—Integrated Framework.
And just as organizations can assess the maturity of the Control Environment, Risk Assessment, Control Activities, and Information and Communication, they can measure the maturity of their Monitoring Activities.
What Is Monitoring?
Monitoring determines whether the components and principles of internal control are present and functioning over time.
This is an important distinction.
Control Activities help manage risks.
Monitoring helps management determine whether those controls—and the broader internal-control system—continue to function.
Consider a bank reconciliation.
The reconciliation itself is a Control Activity.
Management's process for determining whether reconciliations are being completed accurately, reviewed on time, and resolving reconciling items is part of Monitoring.
Monitoring asks:
Is the control system continuing to work the way management intended?
The Two COSO Monitoring Principles
The Monitoring Activities component contains two COSO principles.
Principle 16 — Conduct Ongoing and/or Separate Evaluations
The organization selects, develops, and performs ongoing and/or separate evaluations to determine whether the components of internal control are present and functioning.
Principle 17 — Evaluate and Communicate Deficiencies
The organization evaluates and communicates internal-control deficiencies in a timely manner to the parties responsible for corrective action, including senior management and the Board, as appropriate.
Those two principles provide a practical structure for assessing Monitoring maturity.
Principle 16: How Mature Are Your Evaluations?
Start with a basic question:
How does management discover that a control has stopped working?
The answer tells us a great deal about monitoring maturity.
Level 1 — Initial / Ad Hoc
At Level 1, control problems are primarily discovered after something goes wrong.
Management may learn about control failures because of:
An accounting error
A fraud
A customer complaint
A regulatory finding
An external audit adjustment
An Internal Audit finding
A cybersecurity incident
A missed deadline
A financial loss
A whistleblower complaint
Monitoring is predominantly reactive.
Controls may exist, but management has limited systematic information about whether they continue to function.
A common management response is:
“We didn't know there was a problem.”
That statement itself may indicate weak Monitoring Activities.
Level 2 — Developing / Repeatable
Basic monitoring activities have developed.
Management performs recurring activities such as:
Supervisory reviews
Budget-to-actual comparisons
Account reconciliations
Exception reviews
Management meetings
Periodic compliance reviews
Internal-control checklists
Internal Audit and external audit findings may also provide information about control performance.
Monitoring occurs, but it may be fragmented.
Different departments monitor controls differently.
Documentation may be inconsistent.
There may be no enterprise methodology for determining:
Which controls require monitoring
Who is responsible
How frequently monitoring occurs
What evidence is retained
What constitutes an exception
When escalation is required
Monitoring is repeatable, but not yet fully institutionalized.
Level 3 — Defined
At Level 3, management establishes a formal monitoring framework.
Significant controls have:
Defined control owners
Monitoring responsibilities
Monitoring frequency
Evaluation criteria
Evidence requirements
Exception thresholds
Escalation procedures
Corrective-action requirements
Management distinguishes between:
Ongoing evaluations
and
Separate evaluations.
Ongoing evaluations are embedded into normal operations.
Separate evaluations are performed periodically and provide a more independent assessment of the control system.
At this level, management can answer:
Who is monitoring our significant controls, how are they doing it, and what evidence demonstrates that it occurred?
Level 4 — Managed and Measured
At Level 4, monitoring becomes measurable.
Management establishes Control Performance Indicators and other metrics that show whether controls are functioning as expected.
Examples might include:
Percentage of reconciliations completed on time
Number of unreconciled differences
Approval overrides
Segregation-of-duties conflicts
Access-review exceptions
Duplicate payments
Policy exceptions
Late regulatory filings
Control failures
Repeat audit findings
Unresolved deficiencies
Corrective-action aging
Cybersecurity exceptions
Failed automated controls
Management does not simply know that monitoring occurred.
Management can measure what monitoring is telling it.
Trends become visible.
Recurring failures can be identified.
Departments can be compared.
Control deterioration can be detected earlier.
Level 5 — Optimized
At Level 5, monitoring becomes increasingly continuous, automated, predictive, and risk-based.
The organization may use:
Continuous controls monitoring
Automated exception reporting
Data analytics
Transaction monitoring
Automated access monitoring
Continuous configuration monitoring
Key Risk Indicators
Control Performance Indicators
Predictive analytics
AI-assisted anomaly detection
Integrated dashboards
Automated escalation
Instead of waiting until month-end or quarter-end, management may identify control failures almost immediately.
Monitoring also changes as risks change.
The organization continually asks:
Are we monitoring the controls that matter most?
That is a very different capability from simply reviewing last year's audit findings.
Ongoing Evaluations Versus Separate Evaluations
A mature monitoring program needs to understand the difference.
Ongoing Evaluations
These are built into normal business processes.
Examples include:
Supervisor reviews
Automated exception reports
Daily transaction monitoring
Reconciliation reviews
Budget variance analysis
Security alerts
Performance dashboards
Management review controls
They provide management with relatively timely information.
Separate Evaluations
These occur periodically and provide a different perspective.
Examples include:
Internal Audit engagements
Control self-assessments
Compliance reviews
Quality-assurance reviews
Independent cybersecurity assessments
External assessments
Peer reviews
The appropriate combination should depend upon risk.
A critical control may require continuous or frequent monitoring.
A lower-risk control may require only periodic evaluation.
The objective should not be:
Monitor everything continuously.
The objective should be:
Apply monitoring intensity commensurate with risk.
Internal Audit Is Not Management's Monitoring System
This distinction is critical.
Management sometimes believes:
“Internal Audit monitors our controls.”
Internal Audit certainly evaluates controls.
But management owns the system of internal control.
Management cannot outsource that responsibility to Internal Audit.
Consider an organization where Internal Audit reviews procurement every three years.
Suppose a critical procurement control fails one month after the audit.
Should management wait another 35 months for Internal Audit to discover it?
Clearly not.
Management needs its own monitoring processes.
Internal Audit can independently evaluate whether those monitoring processes are properly designed and operating effectively.
That preserves the appropriate roles:
Management owns and monitors internal control.
Internal Audit independently evaluates and provides assurance.
Principle 17: What Happens When a Deficiency Is Found?
Finding a problem is only half of Monitoring.
The second question is:
What does the organization do with the problem?
An organization may have sophisticated monitoring tools and still have immature
Monitoring Activities if deficiencies remain unresolved.
Level 1 — Initial / Ad Hoc
Problems are handled informally.
There may be:
No centralized issue tracking
No formal ownership
No due dates
No escalation
No root-cause analysis
No verification of corrective action
Management may repeatedly encounter the same problem.
Level 2 — Developing / Repeatable
Significant deficiencies are generally documented.
Management assigns responsibility for corrective action.
However, tracking may rely upon:
Emails
Spreadsheets
Departmental logs
Individual follow-up
Issues can disappear as employees or managers change.
Level 3 — Defined
The organization establishes a formal deficiency-management process.
Each significant issue includes:
Description
Risk
Root cause
Responsible owner
Corrective action
Target completion date
Status
Escalation requirements
Evidence of remediation
Internal-control deficiencies are communicated to appropriate levels of management and governance.
Level 4 — Managed and Measured
Management measures the deficiency-management process.
Metrics might include:
Number of open deficiencies
High-risk findings
Average days outstanding
Percentage overdue
Repeat findings
Aging by department
Management extensions
Root-cause categories
Corrective actions awaiting validation
Senior management and the Audit Committee receive dashboards highlighting significant unresolved issues.
Management can identify departments where remediation consistently fails.
Level 5 — Optimized
At the highest maturity level, deficiency information becomes an input into organizational improvement.
Management analyzes patterns.
For example:
Why are we repeatedly finding segregation-of-duties problems?
Why do reconciliations continually fail?
Why are corrective actions consistently late?
Why do cybersecurity findings recur?
Why do different audits keep identifying problems caused by inadequate training?
Instead of correcting individual symptoms, management identifies systemic root causes.
Deficiencies become organizational learning opportunities.
Finding the Problem Is Not the Same as Fixing the Problem
Consider this scenario.
Internal Audit identifies a high-risk control deficiency.
Management agrees.
A corrective action is established.
Twelve months later, the issue is marked: Closed.
But what does “closed” mean?
Did management complete the promised action?
Or did someone independently determine that the corrective action actually corrected the deficiency?
Those are not the same thing.
A mature monitoring process should distinguish among:
Management says the action is complete.
Evidence demonstrates the action was implemented.
Testing demonstrates the revised control is operating effectively.
Only the third conclusion provides strong evidence that the risk has actually been addressed.
Repeat Findings Are a Maturity Warning
Repeat findings deserve special attention.
A recurring audit finding may indicate something more significant than failure to complete a corrective action.
It may indicate weak:
Accountability
Root-cause analysis
Management oversight
Issue tracking
Escalation
Governance
Organizational culture
If the same problem appears repeatedly, management should stop asking:
“How do we close this finding?”
and start asking:
“Why does our organization keep producing this problem?”
That is maturity thinking.
Build a Monitoring Inventory
One practical way to begin assessing maturity is to create an inventory of significant monitoring activities.
For each significant risk and control, identify:
Risk
Key Control
Control Owner
Monitoring Activity
Monitoring Owner
Frequency
Evidence
Exception Threshold
Escalation Requirement
Corrective-Action Process
This can reveal important gaps.
An organization may discover that it has 150 key controls but only 40 have clearly defined monitoring mechanisms.
That is useful information.
Develop Control Performance Indicators
Organizations routinely use Key Performance Indicators.
They increasingly use Key Risk Indicators.
But what about Control Performance Indicators?
Suppose accounts payable has a key three-way-match control.
Possible monitoring indicators might include:
Percentage of invoices automatically matched
Manual overrides
Match exceptions
Duplicate invoices
Payments without purchase orders
Post-payment corrections
Now management can see whether the control environment is changing.
The same concept can be applied to:
Payroll
Procurement
Cybersecurity
Financial reporting
Grants
Inventory
Regulatory compliance
Revenue
Cash management
This moves Monitoring from periodic inspection toward continuous management information.
A Practical Monitoring Maturity Scorecard
Management and Internal Audit can evaluate the two COSO principles separately.
COSO Principle | Current Maturity | Target Maturity | Gap |
Principle 16 — Ongoing and Separate Evaluations | 2.5 | 4.0 | 1.5 |
Principle 17 — Evaluate and Communicate Deficiencies | 3.0 | 4.0 | 1.0 |
Monitoring Activities Component | 2.75 | 4.0 | 1.25 |
But the score alone is not enough.
Management should identify the underlying capability gaps.
For example:
Principle 16 — Current Level 2.5
Major gaps:
No enterprise monitoring methodology
Limited Control Performance Indicators
Excessive reliance on Internal Audit
Inconsistent monitoring documentation
Limited automated monitoring
No risk-based monitoring frequency
Principle 17 — Current Level 3.0
Major gaps:
Corrective actions frequently overdue
Limited root-cause analysis
Inconsistent validation before closure
Repeat findings
Limited Board reporting
Now management has a roadmap.
Don't Average Away a Serious Monitoring Failure
As with other maturity assessments, averages can be dangerous.
Suppose an organization scores highly on most monitoring practices but has no reliable mechanism for escalating critical cybersecurity control failures.
The mathematical average may still look respectable.
The risk does not.
Organizations should establish minimum acceptable maturity levels for critical controls and risks.
A Level 2 monitoring capability may be acceptable for a low-risk administrative process.
It may be completely unacceptable for:
Cash
Payroll
Financial reporting
Cybersecurity
Regulatory compliance
Public safety
Fraud prevention
Again:
Required maturity should be commensurate with risk.
What Should the Audit Committee Ask?
Monitoring should be particularly important to the Audit Committee.
Useful questions include:
How does management know our key controls are working?
Which controls are continuously monitored?
Which controls receive only periodic evaluation?
What significant control failures occurred this quarter?
What are our oldest unresolved deficiencies?
How many corrective actions are overdue?
Which findings have been repeated?
Who can extend corrective-action deadlines?
How are high-risk deficiencies escalated?
Does Internal Audit validate remediation before significant findings are closed?
What trends are our monitoring systems identifying?
Where are we relying too heavily on manual monitoring?
Perhaps the most revealing question is:
“What significant control problem could occur today that management would not discover until an auditor found it?”
The answer identifies potential monitoring gaps.
Monitoring Should Create an Early-Warning System
The ultimate objective of Monitoring Activities is not to generate more reports.
It is to create an early-warning capability.
At Level 1:
Something goes wrong → Management eventually discovers it.
At Level 2:
Someone periodically reviews the process.
At Level 3:
Monitoring responsibilities and procedures are formally defined.
At Level 4:
Management measures control performance and identifies trends.
At Level 5:
Technology, analytics, continuous monitoring, and organizational learning identify control deterioration rapidly and drive improvement.
That progression captures what Monitoring maturity is really about.
The Question Every Manager Should Be Able to Answer
Management should be able to answer:
“How do you know this control is still working?”
Not:
“Internal Audit didn't find anything.”
Not:
“The external auditors haven't complained.”
Not:
“We've always done it this way.”
And certainly not:
“We'll know if something goes wrong.”
A mature answer sounds more like:
“We have defined monitoring procedures, assigned responsibility, established performance indicators and exception thresholds, review the results regularly, escalate significant deficiencies, track corrective actions, and independently validate remediation.”
That is a very different level of internal-control capability.
Moving From Detection to Continuous Improvement
Monitoring is sometimes treated as the final COSO component.
In practice, it should help restart the internal-control cycle.
Monitoring identifies a problem.
That information may cause management to reconsider:
Control Environment
Is accountability adequate?
Risk Assessment
Has the risk changed?
Control Activities
Does the control need redesign?
Information and Communication
Did the right people receive the right information?
Then Monitoring evaluates whether the corrective action actually worked.
The five COSO components therefore operate as an integrated system.
That is why mature Monitoring Activities can become one of management's most powerful tools for improving internal control.
The objective is not merely to discover that a control failed.
The objective is to know when it begins to fail, why it failed, what must change, and whether the corrective action actually worked.
hat is the difference between simply having internal controls and having a mature system of internal control.
Continue Developing Your COSO and Internal-Control Skills With CCS
Corporate Compliance Seminars provides CPE training addressing COSO, internal-control assessment, control testing, monitoring, risk management, and auditing.
Relevant CCS training includes programs covering:
Understanding COSO Framework Compliance
Effective Use of the COSO Framework
COSO Framework: ICFR Assessments
Using COSO Framework for Compliance and SOX
Testing the Operating Effectiveness of Internal Controls
GAO Green Book Compliance
These programs can help internal auditors, external auditors, compliance professionals, risk managers, governmental auditors, and management move beyond documenting controls toward evaluating whether internal-control systems are properly designed, operating effectively, monitored, and continuously improved.
Comments