How Mature Is Your Risk Assessment Component? Why COSO Should Start With Objectives
- John C. Blackshire, Jr.

- Aug 25
- 10 min read
The COSO Internal Control—Integrated Framework is usually presented in this order:
Control Environment
Risk Assessment
Control Activities
Information and Communication
Monitoring Activities
That is COSO’s formal structure.
But from a practical management and auditing perspective, there is a strong argument that
Risk Assessment should be the first component considered when evaluating how an organization manages internal control.
Why?
Because COSO’s Risk Assessment component begins with objectives.
Before management can identify risks, design controls, monitor performance, or evaluate control effectiveness, it first needs to know:
What are we trying to accomplish?
COSO explicitly states that establishing suitable objectives is a precondition to risk assessment. The framework defines risk as the possibility that an event will occur and adversely affect the achievement of objectives. Risk assessment therefore forms the basis for determining how those risks should be managed.
That creates a simple but powerful logic:
Objectives
→ Risks
→ Controls
→ Information
→ Monitoring
This is why I believe Internal Auditors should consider beginning their practical COSO analysis with the Risk Assessment component.
The Four COSO Risk Assessment Principles
COSO establishes four principles within the Risk Assessment component:
Principle 6 — Specify suitable objectives
Principle 7 — Identify and analyze risks
Principle 8 — Assess fraud risk
Principle 9 — Identify and analyze significant change.
These four principles provide an excellent structure for assessing the maturity of an organization’s risk-management process.
A practical maturity model might use five levels:
Level 1 — Initial / Ad Hoc
Level 2 — Developing / Repeatable
Level 3 — Defined
Level 4 — Managed and Measured
Level 5 — Optimized
The objective is not to force every organization to Level 5. The target maturity should reflect the significance of the organization's risks, complexity, regulatory requirements, and objectives.
But management and governance should know:
Where are we today?
and
Where do we need to be?
Principle 6: Specify Suitable Objectives
COSO Principle 6 states that the organization specifies objectives with sufficient clarity to enable identification and assessment of risks relating to those objectives.
This may be the most important principle in the entire COSO Framework.
Why?
Because risk cannot be meaningfully evaluated without an objective.
Suppose someone asks:
“What is the risk?”
The first response should be:
“Risk to what?”
Consider this objective:
Process vendor payments accurately, completely, timely, and only to authorized vendors.
Now the risks become visible:
Fictitious vendors
Duplicate payments
Unauthorized payments
Incorrect bank information
Fraudulent vendor changes
Inaccurate invoice processing
Late payment penalties
Only after identifying those risks can management determine what controls are necessary.
That gives us:
Objective
→ Risk
→ Control
This is why starting with the objective changes the entire internal-control discussion.
Measuring the Maturity of Objective Setting
Level 1 — Initial
Objectives are informal, vague, or assumed.
Employees may understand generally what management wants, but objectives are not clearly documented.
Examples:
“Improve Accounts Payable.”
“Protect the company.”
“Make sure financial reporting is accurate.”
These statements are too vague to support disciplined risk assessment.
Level 2 — Developing
Major organizational objectives are documented.
Some departments establish operational objectives.
However, objectives may not consistently address:
Operations
Reporting
Compliance
or specific risk tolerances.
Level 3 — Defined
Objectives are formally established at organizational, business-unit, and process levels.
They are sufficiently specific to support risk identification.
Management understands the relationship:
Strategic Objective
→ Business Objective
→ Process Objective
→ Control Objective
Level 4 — Managed
Objectives include measurable expectations.
Performance measures are linked to them.
Risk tolerances are defined.
Changes to objectives trigger reassessment of related risks and controls.
Level 5 — Optimized
Objectives are dynamically integrated into strategy, risk management, budgeting, performance management, and internal control.
When strategy changes, the risk assessment automatically changes with it.
Management routinely asks:
“Has this objective changed, and what does that change mean for our risk and control environment?”
That is a mature control system.
Principle 7: Identify and Analyze Risk
Once objectives are defined, management needs to identify what could prevent their achievement.
COSO Principle 7 requires organizations to identify risks across the entity and analyze those risks as a basis for determining how they should be managed.
This should not be a once-a-year brainstorming session.
Risk assessment should be dynamic and iterative.
COSO guidance emphasizes considering risks across the organization and relative to established tolerances.
A good risk analysis asks:
What could go wrong?
Why could it happen?
How likely is it?
What would the impact be?
How quickly could it affect us?
What controls already exist?
What residual risk remains?
Is the residual risk acceptable?
Measuring Risk Identification Maturity
Level 1 — Initial
Risks are identified primarily after something goes wrong.
Risk management is reactive.
Different departments maintain informal lists.
No common methodology exists.
Level 2 — Developing
Formal risk assessments occur periodically.
Risk registers may exist.
Likelihood and impact are commonly used.
However, risk identification is often siloed by department.
Level 3 — Defined
A standardized methodology exists across the organization.
Risks are consistently linked to objectives.
Risk owners are identified.
Inherent and residual risk are distinguished.
Risk tolerances are documented.
Level 4 — Managed
Management uses multiple risk dimensions, potentially including:
Likelihood
Impact
Velocity
Persistence
Control Effectiveness
Residual Risk
Key Risk Indicators are monitored.
Risk assessments are updated when meaningful events occur.
Level 5 — Optimized
Risk information is embedded directly in decision-making.
Management evaluates interdependencies among risks and uses analytics, scenario modeling, and emerging-risk information.
Risk assessment is not an annual event.
It operates continuously.
The mature organization asks:
“What risk is changing right now?”
rather than:
“When is the next annual risk assessment?”
Don't Confuse a Risk Register With Risk Management
Organizations sometimes produce impressive spreadsheets containing:
Risk
Owner
Likelihood
Impact
Rating
That is useful.
It is not necessarily mature risk management.
The real question is what happens next.
For every significant risk:
What response was selected?
What controls address it?
What risk remains?
Who monitors it?
What happens if exposure increases?
A risk register that nobody uses to make decisions may be a compliance artifact rather than a functioning control.
Principle 8: Assess Fraud Risk
COSO makes fraud risk explicit.
Principle 8 requires the organization to consider the potential for fraud when assessing risks to achieving objectives.
COSO and the ACFE have subsequently reinforced this emphasis through the Fraud Risk Management Guide, which provides a structured framework for organizational fraud-risk management.
This principle matters because traditional business-risk assessments sometimes understate deliberate human behavior.
A normal operational risk question might be:
“Could this process fail?”
A fraud-risk question asks:
“Could someone intentionally make this process fail—or manipulate it for personal benefit?”
That requires a different mindset.
Fraud Risk Should Consider More Than Theft
The organization should consider risks involving:
Asset Misappropriation
Financial Statement Fraud
Corruption
Bribery
Conflicts of Interest
Management Override
Vendor Fraud
Payroll Fraud
Cyber-enabled Fraud
Collusion
Fraud risk should also consider incentives, opportunities, rationalizations, and the potential ability of senior management to override controls.
Measuring Fraud Risk Assessment Maturity
Level 1 — Initial
Fraud risk is considered primarily after a fraud occurs.
Management assumes:
“We trust our employees.”
Fraud is largely viewed as an Internal Audit or security problem.
Level 2 — Developing
Fraud risk is included in periodic risk assessments.
Hotlines and Codes of Conduct exist.
Some fraud scenarios are identified.
Level 3 — Defined
Formal fraud-risk assessments are conducted.
Management maps:
Fraud Scenario
→ Preventive Control
→ Detective Control
→ Control Owner
Fraud risks are documented by business process.
Level 4 — Managed
Fraud controls are tested.
Data analytics are used to detect unusual activity.
Management monitors:
Override activity
Hotline trends
Vendor anomalies
Journal entries
Conflicts of interest
Fraud losses
Repeat issues
Level 5 — Optimized
Fraud-risk assessment is integrated with cybersecurity, AML, compliance, Internal Audit, HR, and enterprise-risk information.
Advanced analytics and AI help identify emerging fraud patterns.
The organization continually asks:
“How would someone circumvent our existing controls?”
That is a mature fraud-risk culture.
Principle 9: Identify and Analyze Significant Change
This principle may be the one organizations most frequently underestimate.
COSO requires organizations to identify and assess changes that could significantly affect the system of internal control.
Deloitte notes that COSO calls for a dynamic risk-assessment program that considers changes in business operations and adapts to internal, external, and emerging risks.
Control environments do not remain static.
Consider changes involving:
New leadership
New employees
ERP implementations
Artificial intelligence
Acquisitions
New products
New regulations
Remote work
Cybersecurity threats
Organizational restructuring
Outsourcing
Economic conditions
New accounting standards
Every major change can create new risks or make existing controls obsolete.
Measuring Change-Risk Maturity
Level 1 — Initial
Control implications are considered only after problems emerge.
Change management is largely operational.
Level 2 — Developing
Major projects include some risk analysis.
Compliance or Internal Audit may become involved late.
Level 3 — Defined
Significant changes trigger formal risk assessments.
Major projects require evaluation of:
Internal-control impact
Technology impact
Compliance impact
Fraud risk
Financial-reporting impact
Level 4 — Managed
Change-risk assessments are embedded in project governance.
Risk and control functions participate early.
New systems and processes are tested before implementation.
Control owners formally acknowledge changes to responsibilities.
Level 5 — Optimized
The organization actively scans for external and internal change.
Emerging risks are continuously evaluated.
Management does not wait for a major project to ask whether controls are affected.
The question becomes:
“What has changed since our last assessment that could make our assumptions or controls wrong?”
That is a powerful risk-management question.
Build a COSO Risk Assessment Maturity Scorecard
Internal Audit can turn these four principles into a simple maturity dashboard:
COSO Risk Assessment Principle | Current | Target | Gap |
6. Suitable Objectives | 2 | 4 | 2 |
7. Risk Identification & Analysis | 3 | 4 | 1 |
8. Fraud Risk Assessment | 2 | 4 | 2 |
9. Significant Change | 1 | 4 | 3 |
This tells management something far more useful than:
“The Risk Assessment component needs improvement.”
It identifies precisely where the maturity gap exists.
In this example:
Management’s largest weakness is its ability to recognize and respond to significant change.
Now management has something specific to improve.
Use Evidence to Support the Maturity Rating
A maturity assessment should not be based solely on interviews.
Internal Audit should look for evidence.
For Objectives:
Strategic plans
Department objectives
Performance measures
Risk tolerances
Board-approved priorities
For Risk Identification:
Risk registers
Risk assessments
Risk-owner assignments
KRIs
Scenario analyses
Risk Committee minutes
For Fraud Risk:
Fraud-risk assessments
Hotline information
Investigation trends
Conflict-of-interest disclosures
Fraud analytics
Control testing
For Significant Change:
Project-risk assessments
Acquisition due diligence
IT implementation governance
Regulatory-change processes
Emerging-risk reports
Post-implementation reviews
The rating should follow the evidence.
Measure Current Maturity and Desired Maturity
This is critical.
A maturity score is not very useful by itself.
Suppose the organization receives: Risk Assessment Maturity = Level 2.7
Is that good?
Maybe.
Maybe not.
The important question is:
What maturity level does the organization need given its risk?
For a small private company, perhaps Level 3 is appropriate.
For a large SEC registrant:
Level 4 may be necessary for important financial-reporting risks.
For a heavily regulated financial institution or insurer:
certain risk-assessment processes may need to approach Level 4 or 5.
The assessment therefore becomes:
Current State
vs.
Desired State
The difference is the maturity gap.
Don't Average Away a Major Risk
As with the Control Environment maturity model, Internal Audit should avoid blindly averaging maturity scores.
Suppose:
Objectives — 5
Risk Analysis — 5
Fraud Risk — 1
Significant Change — 5
Average: 4.0
Does that mean Risk Assessment maturity is Level 4?
No.
A catastrophic weakness in fraud-risk assessment should not disappear mathematically.
Certain deficiencies should operate as gating factors.
For example, an organization should not receive a high overall Risk Assessment maturity rating if:
Significant fraud risks are not assessed.
Major strategic objectives are undefined.
Management has no process for assessing major organizational changes.
Material risks have no identified owners.
Risk tolerance is undefined for significant exposures.
Professional judgment matters.
Risk Assessment Should Drive Control Activities
This is where the COSO sequence becomes particularly important.
COSO Principle 10 says control activities should contribute to mitigating risks to the achievement of objectives to acceptable levels.
That means control activities logically follow risk assessment.
The relationship is:
Objective
↓
Risk
↓
Risk Response
↓
Control
↓
Control Activity
↓
Evidence
↓
Monitoring
This supports the argument for putting practical emphasis on the Risk Assessment component first.
You cannot intelligently design the control until you understand the risk.
And you cannot intelligently assess the risk until you understand the objective.
Why I Would Begin a COSO Review With Risk Assessment
COSO formally begins with the Control Environment, and there are good reasons for that. The Control Environment establishes the governance, integrity, competency, authority, and accountability necessary for internal control to function.
But when performing a practical assessment, I would often begin by asking management:
What are your objectives?
Then:
What could prevent you from achieving them?
Then:
What controls address those risks?
That immediately establishes the context for evaluating every other COSO component.
My practical sequence would therefore be:
1. Objectives
2. Risk Assessment
3. Control Environment
4. Control Activities
5. Information and Communication
6. Monitoring
This is not a replacement for COSO's official structure.
It is a way of using COSO more effectively as an auditing and management tool.
The Audit Committee Should Ask About Risk Maturity
Boards and Audit Committees should not receive only a list of top risks.
They should ask about the process that generated that list.
For example:
How mature is our risk assessment process?
Are organizational objectives sufficiently clear?
Who owns the significant risks?
What risks exceed tolerance?
When was the fraud-risk assessment last updated?
What significant changes have occurred since the last assessment?
What emerging risks have been added?
What risks disappeared, and why?
What does Internal Audit believe management is underestimating?
That last question can be especially valuable.
AI Can Improve Risk Assessment—But It Can Also Create Noise
AI can help management and Internal Audit:
Brainstorm risks
Analyze large volumes of information
Identify emerging trends
Compare risks across business units
Develop scenarios
Analyze historical events
Identify potential fraud schemes
Challenge assumptions
But AI can also generate huge lists of generic risks.
A 200-item AI-generated risk register is not automatically useful.
The professional still needs to connect:
Objective
→ Relevant Risk
→ Significance
→ Response
→ Control
The mature use of AI is not:
“Give me every possible risk.”
It is:
“Given this specific objective, business model, operating environment, and risk tolerance, what material uncertainties could prevent achievement, and what evidence should management examine?”
That is a much better risk prompt.
The Bottom Line: Everything Starts With the Objective
If you cannot clearly state the objective, you cannot clearly state the risk.
If you cannot clearly state the risk, you cannot intelligently select the control.
That is why COSO Principle 6 deserves far more attention.
The maturity chain is:
Level 1 — We have vague objectives and react to risks.
↓
Level 2 — We periodically identify risks.
↓
Level 3 — Objectives and risks are formally linked.
↓
Level 4 — Risks, tolerances, controls and indicators are actively measured.
↓
Level 5 — Risk assessment is embedded continuously into strategy and decision-making.
A mature Risk Assessment component should allow management to answer:
What are we trying to accomplish?
What could prevent us from accomplishing it?
Could fraud interfere with the objective?
What has changed that could alter the risk?
What level of risk are we willing to accept?
What are we doing about the remaining risk?
That is why, from a practical auditing perspective, I believe the COSO conversation should begin with:
Objectives.
Because from the objective comes the risk.
From the risk comes the control.
And from the control comes the evidence necessary to determine whether the organization is actually managing the risk.
Comments