How Mature Is Your Control Environment? A Better Way to Measure the Foundation of Internal Control
- John C. Blackshire, Jr.

- 1 day ago
- 10 min read
Organizations frequently ask Internal Audit a deceptively simple question:
“Are our internal controls effective?”
There is another question that may tell management and the Audit Committee considerably more:
“How mature is our control environment?”
The distinction matters.
A control may exist and operate today while the broader control environment remains dependent on particular individuals, informal practices, management intervention, or institutional memory.
Another organization may have documented responsibilities, independent governance oversight, measurable accountability, competent personnel, systematic monitoring, and continuous improvement.
Both organizations may say:
“We have internal controls.”
They clearly do not have the same control maturity.
A maturity assessment provides Internal Audit with a way to move beyond the binary conclusion of effective/ineffective and describe how reliably the organization is likely to maintain effective control over time.
The concept is well established in the profession. The Institute of Internal Auditors has specifically discussed using maturity models to assess internal control structures, including a six-level internal-control-environment model ranging from nonexistent to optimized.
For many organizations, a practical five-level model is easier to communicate:
Level 1 — Initial / Ad Hoc
Level 2 — Developing / Repeatable
Level 3 — Defined
Level 4 — Managed and Measured
Level 5 — Optimized
The objective should not automatically be Level 5 everywhere. The appropriate maturity depends upon the organization's risks, complexity, regulatory environment and objectives.
But management should know where it is today and where it needs to be.
Start With COSO's Control Environment
COSO's Internal Control—Integrated Framework identifies five components of internal control:
Control Environment
Risk Assessment
Control Activities
Information and Communication
Monitoring Activities.
The Control Environment is foundational. It establishes the standards, processes and structures upon which the rest of the organization's internal-control system operates. It encompasses governance oversight, ethical values, organizational structure, authority, responsibility, competence and accountability.
COSO associates five principles with the Control Environment:
Commitment to integrity and ethical values
Independent board oversight
Organizational structure, authority and responsibility
Commitment to competence
Accountability.
Those five principles provide an excellent architecture for a Control Environment Maturity Assessment.
Principle 1: Integrity and Ethical Values
The first question is not whether the organization has a Code of Conduct.
Most organizations do.
The better question is:
How deeply are integrity and ethical behavior embedded into the way the organization actually operates?
Level 1 — Initial
Ethics depend primarily upon individuals.
Standards may be poorly defined.
Management behavior can contradict stated organizational values.
Employees may be reluctant to report concerns.
Level 2 — Developing
A Code of Conduct exists.
Employees receive basic ethics training.
A hotline or reporting mechanism may exist.
Enforcement remains inconsistent.
Level 3 — Defined
Ethical expectations are formally documented and communicated.
Conflict-of-interest processes exist.
Hotline responsibilities are defined.
Investigations follow established procedures.
Management periodically certifies compliance.
Level 4 — Managed
Management measures the ethical environment.
Hotline trends are analyzed.
Investigations are tracked.
Retaliation concerns are monitored.
Ethics violations and corrective actions are reported to appropriate governance bodies.
Level 5 — Optimized
Ethics and integrity are deeply embedded in organizational decision-making.
Data from employee surveys, investigations, hotline reports, exit interviews, compliance incidents and Internal Audit findings are analyzed collectively.
Management identifies cultural warning signs before they become major control failures.
The maturity question is therefore not:
“Do we have an ethics policy?”
It is:
“Can we demonstrate that ethical expectations influence behavior throughout the organization?”
Principle 2: Board and Audit Committee Oversight
COSO specifically calls for the board to demonstrate independence from management and exercise oversight over the development and performance of internal control.
That makes governance maturity measurable.
Level 1 — Initial
The board depends almost entirely upon information selected and presented by management.
Internal-control discussions are largely reactive.
Serious problems reach governance only after something goes wrong.
Level 2 — Developing
An Audit Committee exists.
Regular meetings occur.
Internal Audit and external audit provide reports.
However, oversight remains heavily management-driven.
Level 3 — Defined
The Audit Committee operates under a strong charter.
It receives structured reporting on:
Internal Audit
External Audit
Risk
Compliance
Financial reporting
Internal controls
Significant findings and corrective actions are formally tracked.
Level 4 — Managed
The Audit Committee receives dashboards showing control performance and emerging risks.
It monitors:
Repeat findings
Overdue corrective actions
Material weaknesses
Significant deficiencies
Fraud investigations
Whistleblower activity
Management overrides
Risk trends
Level 5 — Optimized
Governance actively challenges management's assumptions.
The board receives information from multiple independent sources.
Control maturity itself becomes part of governance reporting.
The Audit Committee doesn't merely ask:
“Were there any findings?”
It asks:
“Where is the control environment deteriorating, and what evidence supports management's assessment?”
That is a much more mature governance model.
Principle 3: Structure, Authority and Responsibility
An organizational chart does not establish effective organizational structure.
The real question is:
Does everyone understand who has authority, who owns the risk, who owns the control and who is accountable when the control fails?
Level 1 — Initial
Responsibilities are informal.
Employees learn processes through experience.
Key activities depend upon institutional knowledge.
Segregation-of-duties conflicts may be common.
Level 2 — Developing
Job descriptions exist.
Organizational charts exist.
Approval responsibilities are partially documented.
Important processes still depend heavily upon individuals.
Level 3 — Defined
Authority and responsibility are formally established.
Key controls have identified owners.
Delegations of authority are documented.
Reporting relationships are clear.
Segregation-of-duties requirements are defined.
Level 4 — Managed
Management periodically evaluates whether organizational structure continues to support objectives.
Changes in systems, personnel, acquisitions and business processes trigger reassessment of control responsibilities.
Level 5 — Optimized
Organizational changes are automatically integrated into risk and control assessments.
Control ownership is visible and measurable.
Management can answer quickly:
Who owns this risk?
Who operates this control?
Who monitors it?
Who provides independent assurance?
This aligns naturally with the IIA's Three Lines Model, which emphasizes accountability and the distinct contributions of organizational roles to governance and risk management.
Principle 4: Commitment to Competence
This principle is often underestimated.
A beautifully designed control can fail because the employee responsible for performing it does not have the competence necessary to perform it properly.
Level 1 — Initial
Competency depends on who happens to occupy the position.
Training is informal.
Critical knowledge may reside with one employee.
Level 2 — Developing
Job descriptions contain minimum qualifications.
Basic training programs exist.
Professional-development requirements may be inconsistent.
Level 3 — Defined
Critical positions have documented competency requirements.
Training is structured.
Management identifies succession needs.
Technical positions have defined qualifications.
Level 4 — Managed
Competence is measured.
Skill gaps are identified through performance evaluations, audit findings, control failures and changing business requirements.
Training addresses identified deficiencies.
Level 5 — Optimized
Workforce capabilities are linked directly to organizational risk.
Management anticipates future competency requirements involving areas such as:
Artificial intelligence
Cybersecurity
Data analytics
Regulatory compliance
Financial reporting
Fraud
Technology
The question changes from:
“Did employees complete their training?”
to:
“Do the people responsible for our critical controls actually possess the knowledge and skills necessary to operate them effectively?”
That is a far better control question.
Principle 5: Accountability
This may be the ultimate test of the control environment.
COSO specifically identifies holding individuals accountable for their internal-control responsibilities as one of the five Control Environment principles.
Level 1 — Initial
Control failures produce little consequence.
The same exceptions recur.
Corrective actions remain open.
Nobody clearly owns the problem.
Level 2 — Developing
Management assigns responsibility for corrective actions.
Follow-up occurs inconsistently.
Deadlines frequently move.
Level 3 — Defined
Control ownership is established.
Findings have responsible owners and due dates.
Management monitors corrective action.
Escalation procedures exist.
Level 4 — Managed
Control performance affects management evaluation.
Repeat findings are analyzed.
Overdue corrective actions are escalated.
Control failures have measurable accountability.
Level 5 — Optimized
Accountability becomes part of organizational culture.
Managers do not wait for Internal Audit to identify problems.
They identify, disclose and correct control weaknesses themselves.
That may be one of the strongest indicators of a mature control environment:
Management finds its own control problems before Internal Audit does.
Building a Control Environment Maturity Scorecard
Internal Audit can convert these concepts into a practical assessment.
A simple model might look like this:
COSO Control Environment Principle | Level 1 | Level 2 | Level 3 | Level 4 | Level 5 |
Integrity & Ethical Values | ● | ||||
Board/Audit Committee Oversight | ● | ||||
Structure, Authority & Responsibility | ● | ||||
Commitment to Competence | ● | ||||
Accountability | ● |
Now the Audit Committee can immediately see something a conventional audit report may obscure:
The organization may have reasonably defined structures while still having serious weaknesses in accountability and organizational culture.
That is valuable governance information.
But Don't Average Away a Critical Weakness
There is a major danger in maturity scoring.
Suppose the scores are:
Integrity — 1
Board Oversight — 4
Structure — 4
Competence — 4
Accountability — 4
Average score: 3.4
Does that mean the organization's Control Environment is reasonably mature?
Absolutely not.
A Level 1 problem involving integrity can undermine everything else.
A maturity model should therefore include gating criteria.
Certain deficiencies should prevent the organization from receiving a high overall maturity rating regardless of the mathematical average.
Examples might include:
Senior management integrity concerns
Management override
Board independence problems
Retaliation against whistleblowers
Known material control weaknesses left uncorrected
Repeated concealment of control deficiencies
Systematic failure to enforce accountability
Maturity requires professional judgment.
It should never become another mechanical checklist.
Measure Evidence, Not Opinions
A maturity assessment should not ask management:
“How mature do you think our control environment is?”
That will usually produce optimistic answers.
Internal Audit should identify maturity indicators.
For integrity:
Hotline reports
Substantiated ethics cases
Employee survey results
Retaliation allegations
Conflict-of-interest exceptions
For governance:
Audit Committee attendance
Meeting frequency
Private sessions with Internal Audit
Overdue findings
Frequency of management challenge
For competence:
Turnover
Vacancies in key control positions
Training completion
Certification levels
Recurring errors
For accountability:
Overdue corrective actions
Repeat findings
Policy violations
Management overrides
Control-owner performance
The maturity assessment becomes evidence-based rather than impression-based.
Add Trend to the Assessment
A maturity score becomes considerably more useful when repeated.
For example:
Control Environment Area | 2024 | 2025 | 2026 | Target |
Integrity & Ethics | 2 | 2 | 3 | 4 |
Governance Oversight | 3 | 3 | 4 | 4 |
Structure & Responsibility | 2 | 3 | 3 | 4 |
Competence | 2 | 2 | 2 | 4 |
Accountability | 1 | 2 | 2 | 4 |
Now governance can see:
We are improving, but competence and accountability remain below our desired maturity.
This is one of the major advantages of maturity models. The IIA notes that maturity assessments can be revisited to evaluate whether processes are achieving desired outcomes and to identify opportunities to raise process resiliency over time.
The IIA-Australia likewise describes combining COSO components with a maturity model as a way to evaluate control elements and demonstrate improvement between audits.
Current Maturity Is Only Half the Question
Management should establish two ratings:
Current Maturity
Where are we today?
Desired Maturity
Where should we be given our risks?
Then calculate the gap.
For example:
Control Area | Current | Desired | Gap |
Integrity & Ethics | 3 | 4 | 1 |
Governance Oversight | 4 | 4 | 0 |
Authority & Responsibility | 2 | 4 | 2 |
Competence | 2 | 4 | 2 |
Accountability | 1 | 4 | 3 |
Suddenly management has a Control Environment Improvement Plan rather than another audit report.
The largest problem is obvious.
Accountability.
Maturity Can Be Applied Beyond the Control Environment
The same methodology can eventually be extended across all five COSO components.
An enterprise maturity dashboard could assess:
COSO Component | Current Maturity | Target |
Control Environment | 2.4 | 4 |
Risk Assessment | 2.8 | 4 |
Control Activities | 3.5 | 4 |
Information & Communication | 3.0 | 4 |
Monitoring | 2.1 | 4 |
This can reveal something important.
An organization may have relatively sophisticated Control Activities while having weak Monitoring and a mediocre Control Environment.
That organization may have lots of controls.
It does not necessarily have a mature system of internal control.
COSO emphasizes that effective internal controls extend beyond compliance and financial reporting and support organizational objectives and reliable information more broadly.
Internal Audit Should Not Own the Maturity Level
There is an important governance distinction.
Management owns the internal-control system.
Management should therefore determine the level of maturity necessary to manage organizational risk.
Internal Audit can independently assess whether:
Management's maturity assessment is reasonable.
Evidence supports the rating.
Significant gaps have been identified.
Corrective actions address those gaps.
Reported improvement actually occurred.
That preserves the distinction between management responsibility and independent assurance.
What Level Should an Organization Target?
Not every control needs to reach Level 5.
Trying to optimize every process can become expensive and bureaucratic.
The target should reflect risk.
A low-risk administrative process might reasonably operate at:
Level 2 or Level 3.
Financial reporting for an SEC registrant may require:
Level 4.
Cybersecurity controls protecting highly sensitive information may justify:
Level 4 or Level 5.
Governance, ethics and fraud-related controls may also warrant higher maturity.
The principle should be:
The maturity of the control should be commensurate with the significance of the risk.
The Audit Committee Needs More Than Red, Yellow and Green
Audit Committees frequently receive dashboards containing:
🔴 High Risk
🟡 Moderate Risk
🟢 Low Risk
Useful—but incomplete.
Risk rating answers:
“How serious is the problem?”
Maturity answers:
“How capable is the organization of consistently managing the problem?”
Those are different questions.
Consider:
Risk: HIGH
Current Maturity: Level 2
Required Maturity: Level 4
Gap: 2 Levels
That gives the Audit Committee considerably more information about the underlying governance problem.
The Real Test of Maturity
The ultimate question isn't:
“Do we have controls?”
Almost every organization does.
It isn't:
“Do we have policies?”
Of course.
And it isn't:
“Did Internal Audit find exceptions?”
Exceptions will occur even in good organizations.
The more revealing questions are:
Are responsibilities clearly defined?
Do competent people operate the controls?
Does management know when controls fail?
Are failures reported rather than concealed?
Does management determine root cause?
Are problems corrected promptly?
Are repeat failures unusual?
Does governance independently challenge management?
Does the organization learn from control failures?
Are controls continuously improved as risks change?
Those questions distinguish an organization that merely has controls from an organization with a mature control environment.
The Bottom Line: Measure the Control Environment Like You Intend to Improve It
COSO provides the architecture.
The five Control Environment principles give Internal Audit and management the assessment areas:
Integrity and Ethical Values
→ Governance Oversight
→ Structure, Authority and Responsibility
→ Competence
→ Accountability
A maturity model adds another dimension:
Level 1 — Initial
→ Level 2 — Developing
→ Level 3 — Defined
→ Level 4 — Managed
→ Level 5 — Optimized
The result is far more useful than saying:
“The Control Environment appears adequate.”
Instead, Internal Audit can report:
“The Control Environment is currently assessed at Level 2.6 against a target maturity of Level 4.0. The largest gaps involve management accountability, competency management and monitoring of ethical culture.”
Now the Audit Committee has something it can govern.
Management has something it can improve.
Internal Audit has something it can independently assess.
And next year, everyone can determine whether the organization actually got better.
That is the real value of asking:
How Mature Is This Control Environment?
For additional background, COSO maintains its current Internal Control guidance and resources, while the IIA's maturity-model guidance provides auditors with a useful methodology for developing and applying maturity assessments.
Comments