top of page
Search

How Mature Is Your Control Environment? A Better Way to Measure the Foundation of Internal Control

Organizations frequently ask Internal Audit a deceptively simple question:

“Are our internal controls effective?”

There is another question that may tell management and the Audit Committee considerably more:

“How mature is our control environment?”

The distinction matters.


A control may exist and operate today while the broader control environment remains dependent on particular individuals, informal practices, management intervention, or institutional memory.


Another organization may have documented responsibilities, independent governance oversight, measurable accountability, competent personnel, systematic monitoring, and continuous improvement.


Both organizations may say:

“We have internal controls.”

They clearly do not have the same control maturity.


A maturity assessment provides Internal Audit with a way to move beyond the binary conclusion of effective/ineffective and describe how reliably the organization is likely to maintain effective control over time.


The concept is well established in the profession. The Institute of Internal Auditors has specifically discussed using maturity models to assess internal control structures, including a six-level internal-control-environment model ranging from nonexistent to optimized.


For many organizations, a practical five-level model is easier to communicate:


Level 1 — Initial / Ad Hoc

Level 2 — Developing / Repeatable

Level 3 — Defined

Level 4 — Managed and Measured

Level 5 — Optimized


The objective should not automatically be Level 5 everywhere. The appropriate maturity depends upon the organization's risks, complexity, regulatory environment and objectives.


But management should know where it is today and where it needs to be.


Start With COSO's Control Environment

COSO's Internal Control—Integrated Framework identifies five components of internal control:

Control Environment

Risk Assessment

Control Activities

Information and Communication

Monitoring Activities.


The Control Environment is foundational. It establishes the standards, processes and structures upon which the rest of the organization's internal-control system operates. It encompasses governance oversight, ethical values, organizational structure, authority, responsibility, competence and accountability.


COSO associates five principles with the Control Environment:

  1. Commitment to integrity and ethical values

  2. Independent board oversight

  3. Organizational structure, authority and responsibility

  4. Commitment to competence

  5. Accountability.


Those five principles provide an excellent architecture for a Control Environment Maturity Assessment.


Principle 1: Integrity and Ethical Values

The first question is not whether the organization has a Code of Conduct.


Most organizations do.


The better question is:

How deeply are integrity and ethical behavior embedded into the way the organization actually operates?

Level 1 — Initial

  • Ethics depend primarily upon individuals.

  • Standards may be poorly defined.

  • Management behavior can contradict stated organizational values.

  • Employees may be reluctant to report concerns.


Level 2 — Developing

  • A Code of Conduct exists.

  • Employees receive basic ethics training.

  • A hotline or reporting mechanism may exist.

  • Enforcement remains inconsistent.


Level 3 — Defined

  • Ethical expectations are formally documented and communicated.

  • Conflict-of-interest processes exist.

  • Hotline responsibilities are defined.

  • Investigations follow established procedures.

  • Management periodically certifies compliance.


Level 4 — Managed

  • Management measures the ethical environment.

  • Hotline trends are analyzed.

  • Investigations are tracked.

  • Retaliation concerns are monitored.

  • Ethics violations and corrective actions are reported to appropriate governance bodies.


Level 5 — Optimized

  • Ethics and integrity are deeply embedded in organizational decision-making.

  • Data from employee surveys, investigations, hotline reports, exit interviews, compliance incidents and Internal Audit findings are analyzed collectively.

  • Management identifies cultural warning signs before they become major control failures.


The maturity question is therefore not:

“Do we have an ethics policy?”

It is:

“Can we demonstrate that ethical expectations influence behavior throughout the organization?”

Principle 2: Board and Audit Committee Oversight

COSO specifically calls for the board to demonstrate independence from management and exercise oversight over the development and performance of internal control.


That makes governance maturity measurable.


Level 1 — Initial

  • The board depends almost entirely upon information selected and presented by management.

  • Internal-control discussions are largely reactive.

  • Serious problems reach governance only after something goes wrong.


Level 2 — Developing

  • An Audit Committee exists.

  • Regular meetings occur.

  • Internal Audit and external audit provide reports.

  • However, oversight remains heavily management-driven.


Level 3 — Defined

The Audit Committee operates under a strong charter.


It receives structured reporting on:

  • Internal Audit

  • External Audit

  • Risk

  • Fraud

  • Compliance

  • Financial reporting

  • Internal controls


Significant findings and corrective actions are formally tracked.


Level 4 — Managed

The Audit Committee receives dashboards showing control performance and emerging risks.


It monitors:

  • Repeat findings

  • Overdue corrective actions

  • Material weaknesses

  • Significant deficiencies

  • Fraud investigations

  • Whistleblower activity

  • Management overrides

  • Risk trends


Level 5 — Optimized

Governance actively challenges management's assumptions.


The board receives information from multiple independent sources.


Control maturity itself becomes part of governance reporting.


The Audit Committee doesn't merely ask:

“Were there any findings?”

It asks:

“Where is the control environment deteriorating, and what evidence supports management's assessment?”

That is a much more mature governance model.


Principle 3: Structure, Authority and Responsibility

An organizational chart does not establish effective organizational structure.


The real question is:

Does everyone understand who has authority, who owns the risk, who owns the control and who is accountable when the control fails?

Level 1 — Initial

  • Responsibilities are informal.

  • Employees learn processes through experience.

  • Key activities depend upon institutional knowledge.

  • Segregation-of-duties conflicts may be common.


Level 2 — Developing

  • Job descriptions exist.

  • Organizational charts exist.

  • Approval responsibilities are partially documented.

  • Important processes still depend heavily upon individuals.


Level 3 — Defined

  • Authority and responsibility are formally established.

  • Key controls have identified owners.

  • Delegations of authority are documented.

  • Reporting relationships are clear.

  • Segregation-of-duties requirements are defined.


Level 4 — Managed

  • Management periodically evaluates whether organizational structure continues to support objectives.

  • Changes in systems, personnel, acquisitions and business processes trigger reassessment of control responsibilities.


Level 5 — Optimized

  • Organizational changes are automatically integrated into risk and control assessments.

  • Control ownership is visible and measurable.


Management can answer quickly:

Who owns this risk?
Who operates this control?
Who monitors it?
Who provides independent assurance?

This aligns naturally with the IIA's Three Lines Model, which emphasizes accountability and the distinct contributions of organizational roles to governance and risk management.


Principle 4: Commitment to Competence

This principle is often underestimated.


A beautifully designed control can fail because the employee responsible for performing it does not have the competence necessary to perform it properly.


Level 1 — Initial

  • Competency depends on who happens to occupy the position.

  • Training is informal.

  • Critical knowledge may reside with one employee.


Level 2 — Developing

  • Job descriptions contain minimum qualifications.

  • Basic training programs exist.

  • Professional-development requirements may be inconsistent.


Level 3 — Defined

  • Critical positions have documented competency requirements.

  • Training is structured.

  • Management identifies succession needs.

  • Technical positions have defined qualifications.


Level 4 — Managed

  • Competence is measured.

  • Skill gaps are identified through performance evaluations, audit findings, control failures and changing business requirements.

  • Training addresses identified deficiencies.


Level 5 — Optimized

  • Workforce capabilities are linked directly to organizational risk.


Management anticipates future competency requirements involving areas such as:

  • Artificial intelligence

  • Cybersecurity

  • Data analytics

  • Regulatory compliance

  • Financial reporting

  • Fraud

  • Technology


The question changes from:

“Did employees complete their training?”

to:

“Do the people responsible for our critical controls actually possess the knowledge and skills necessary to operate them effectively?”

That is a far better control question.


Principle 5: Accountability

This may be the ultimate test of the control environment.


COSO specifically identifies holding individuals accountable for their internal-control responsibilities as one of the five Control Environment principles.


Level 1 — Initial

  • Control failures produce little consequence.

  • The same exceptions recur.

  • Corrective actions remain open.

  • Nobody clearly owns the problem.


Level 2 — Developing

  • Management assigns responsibility for corrective actions.

  • Follow-up occurs inconsistently.

  • Deadlines frequently move.


Level 3 — Defined

  • Control ownership is established.

  • Findings have responsible owners and due dates.

  • Management monitors corrective action.

  • Escalation procedures exist.


Level 4 — Managed

  • Control performance affects management evaluation.

  • Repeat findings are analyzed.

  • Overdue corrective actions are escalated.

  • Control failures have measurable accountability.


Level 5 — Optimized

  • Accountability becomes part of organizational culture.

  • Managers do not wait for Internal Audit to identify problems.

  • They identify, disclose and correct control weaknesses themselves.


That may be one of the strongest indicators of a mature control environment:

Management finds its own control problems before Internal Audit does.

Building a Control Environment Maturity Scorecard

Internal Audit can convert these concepts into a practical assessment.


A simple model might look like this:

COSO Control Environment Principle

Level 1

Level 2

Level 3

Level 4

Level 5

Integrity & Ethical Values





Board/Audit Committee Oversight





Structure, Authority & Responsibility





Commitment to Competence





Accountability





Now the Audit Committee can immediately see something a conventional audit report may obscure:

The organization may have reasonably defined structures while still having serious weaknesses in accountability and organizational culture.

That is valuable governance information.


But Don't Average Away a Critical Weakness

There is a major danger in maturity scoring.


Suppose the scores are:

  • Integrity — 1

  • Board Oversight — 4

  • Structure — 4

  • Competence — 4

  • Accountability — 4


Average score: 3.4


Does that mean the organization's Control Environment is reasonably mature?


Absolutely not.


A Level 1 problem involving integrity can undermine everything else.


A maturity model should therefore include gating criteria.


Certain deficiencies should prevent the organization from receiving a high overall maturity rating regardless of the mathematical average.


Examples might include:

  • Senior management integrity concerns

  • Management override

  • Board independence problems

  • Retaliation against whistleblowers

  • Known material control weaknesses left uncorrected

  • Repeated concealment of control deficiencies

  • Systematic failure to enforce accountability


Maturity requires professional judgment.


It should never become another mechanical checklist.


Measure Evidence, Not Opinions

A maturity assessment should not ask management:

“How mature do you think our control environment is?”

That will usually produce optimistic answers.


Internal Audit should identify maturity indicators.


For integrity:

  • Hotline reports

  • Substantiated ethics cases

  • Employee survey results

  • Retaliation allegations

  • Conflict-of-interest exceptions


For governance:

  • Audit Committee attendance

  • Meeting frequency

  • Private sessions with Internal Audit

  • Overdue findings

  • Frequency of management challenge


For competence:

  • Turnover

  • Vacancies in key control positions

  • Training completion

  • Certification levels

  • Recurring errors


For accountability:

  • Overdue corrective actions

  • Repeat findings

  • Policy violations

  • Management overrides

  • Control-owner performance


The maturity assessment becomes evidence-based rather than impression-based.


Add Trend to the Assessment

A maturity score becomes considerably more useful when repeated.


For example:

Control Environment Area

2024

2025

2026

Target

Integrity & Ethics

2

2

3

4

Governance Oversight

3

3

4

4

Structure & Responsibility

2

3

3

4

Competence

2

2

2

4

Accountability

1

2

2

4

Now governance can see:

We are improving, but competence and accountability remain below our desired maturity.

This is one of the major advantages of maturity models. The IIA notes that maturity assessments can be revisited to evaluate whether processes are achieving desired outcomes and to identify opportunities to raise process resiliency over time.


The IIA-Australia likewise describes combining COSO components with a maturity model as a way to evaluate control elements and demonstrate improvement between audits.


Current Maturity Is Only Half the Question

Management should establish two ratings:


Current Maturity

Where are we today?


Desired Maturity

Where should we be given our risks?


Then calculate the gap.


For example:

Control Area

Current

Desired

Gap

Integrity & Ethics

3

4

1

Governance Oversight

4

4

0

Authority & Responsibility

2

4

2

Competence

2

4

2

Accountability

1

4

3

Suddenly management has a Control Environment Improvement Plan rather than another audit report.


The largest problem is obvious.


Accountability.


Maturity Can Be Applied Beyond the Control Environment

The same methodology can eventually be extended across all five COSO components.


An enterprise maturity dashboard could assess:

COSO Component

Current Maturity

Target

Control Environment

2.4

4

Risk Assessment

2.8

4

Control Activities

3.5

4

Information & Communication

3.0

4

Monitoring

2.1

4

This can reveal something important.


An organization may have relatively sophisticated Control Activities while having weak Monitoring and a mediocre Control Environment.


That organization may have lots of controls.


It does not necessarily have a mature system of internal control.


COSO emphasizes that effective internal controls extend beyond compliance and financial reporting and support organizational objectives and reliable information more broadly.


Internal Audit Should Not Own the Maturity Level

There is an important governance distinction.


Management owns the internal-control system.


Management should therefore determine the level of maturity necessary to manage organizational risk.


Internal Audit can independently assess whether:

  • Management's maturity assessment is reasonable.

  • Evidence supports the rating.

  • Significant gaps have been identified.

  • Corrective actions address those gaps.

  • Reported improvement actually occurred.


That preserves the distinction between management responsibility and independent assurance.


What Level Should an Organization Target?

Not every control needs to reach Level 5.


Trying to optimize every process can become expensive and bureaucratic.


The target should reflect risk.


A low-risk administrative process might reasonably operate at:


Level 2 or Level 3.

Financial reporting for an SEC registrant may require:


Level 4.

Cybersecurity controls protecting highly sensitive information may justify:


Level 4 or Level 5.

Governance, ethics and fraud-related controls may also warrant higher maturity.


The principle should be:

The maturity of the control should be commensurate with the significance of the risk.

The Audit Committee Needs More Than Red, Yellow and Green

Audit Committees frequently receive dashboards containing:

🔴 High Risk

🟡 Moderate Risk

🟢 Low Risk


Useful—but incomplete.


Risk rating answers:

“How serious is the problem?”

Maturity answers:

“How capable is the organization of consistently managing the problem?”

Those are different questions.


Consider:

  • Risk: HIGH

  • Current Maturity: Level 2

  • Required Maturity: Level 4

  • Gap: 2 Levels


That gives the Audit Committee considerably more information about the underlying governance problem.


The Real Test of Maturity

The ultimate question isn't:

“Do we have controls?”

Almost every organization does.


It isn't:

“Do we have policies?”

Of course.


And it isn't:

“Did Internal Audit find exceptions?”

Exceptions will occur even in good organizations.


The more revealing questions are:

Are responsibilities clearly defined?
Do competent people operate the controls?
Does management know when controls fail?
Are failures reported rather than concealed?
Does management determine root cause?
Are problems corrected promptly?
Are repeat failures unusual?
Does governance independently challenge management?
Does the organization learn from control failures?
Are controls continuously improved as risks change?

Those questions distinguish an organization that merely has controls from an organization with a mature control environment.


The Bottom Line: Measure the Control Environment Like You Intend to Improve It

COSO provides the architecture.


The five Control Environment principles give Internal Audit and management the assessment areas:


Integrity and Ethical Values

Governance Oversight

Structure, Authority and Responsibility

Competence

Accountability


A maturity model adds another dimension:


Level 1 — Initial

Level 2 — Developing

Level 3 — Defined

Level 4 — Managed

Level 5 — Optimized


The result is far more useful than saying:

“The Control Environment appears adequate.”

Instead, Internal Audit can report:

“The Control Environment is currently assessed at Level 2.6 against a target maturity of Level 4.0. The largest gaps involve management accountability, competency management and monitoring of ethical culture.”

Now the Audit Committee has something it can govern.


Management has something it can improve.


Internal Audit has something it can independently assess.


And next year, everyone can determine whether the organization actually got better.


That is the real value of asking:

How Mature Is This Control Environment?

For additional background, COSO maintains its current Internal Control guidance and resources, while the IIA's maturity-model guidance provides auditors with a useful methodology for developing and applying maturity assessments.


 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page