top of page
Search

True Quality Management with COSO needs a Maturity Model!

The History of Maturity Models—and How Auditors Can Put Them to Work

How good is your organization's system of internal control?


For decades, auditors have approached that question primarily by determining whether controls are properly designed and operating effectively.


Those are essential questions—but they don't tell the whole story.


Consider two organizations with the same key control.


At Organization A, the control is performed manually by an experienced employee who knows what to do. Procedures are limited, documentation is inconsistent, and management does not measure the control's performance.


At Organization B, the same control has:

  • A defined control objective

  • A documented risk

  • An assigned control owner

  • Written procedures

  • Defined evidence requirements

  • Supervisory review

  • Exception reporting

  • Performance metrics

  • Technology support

  • Periodic reassessment


Both controls might pass an operating-effectiveness test today.


But the two organizations clearly do not possess the same control capability.


Organization A does not have sustainability.


That is where maturity models become valuable.


A maturity model allows management and auditors to move beyond:

“Does the control work?”

and ask:

“How mature, sustainable, measurable, and adaptable is the control?”

Maturity models did not originate with COSO. Their history stretches back decades through quality management, software engineering, information technology, cybersecurity, and other disciplines.


Understanding that history can help auditors use maturity assessments more effectively.


The Quality Management Roots of Maturity Models

One of the important early influences on modern maturity thinking came from the quality-management movement.


Philip B. Crosby introduced his Quality Management Maturity Grid in his 1979 book Quality Is Free.


Crosby's model described organizational quality management through five stages:

  1. Uncertainty

  2. Awakening

  3. Enlightenment

  4. Wisdom

  5. Certainty


The terminology is different from many modern maturity models, but the underlying concept is remarkably familiar.


Organizations develop capabilities progressively.


They move from reactive and inconsistent practices toward increasingly structured, managed, measured, and sustainable processes.


Instead of simply asking:

“Do we have a quality-management process?”

management could ask:

“How mature is our quality-management process?”

That was an important change in thinking.


And the concept was about to spread much further.


Software Engineering Takes Maturity to Another Level

During the 1980s, the U.S. Department of Defense faced a significant challenge.


Government agencies depended increasingly upon contractors to develop sophisticated software systems, but software-development projects frequently suffered from:

  • Cost overruns

  • Schedule problems

  • Quality problems

  • Inconsistent processes

  • Unpredictable results


Evaluating only the finished software was not enough.


The government needed to understand the capability of the organization and processes producing the software.


Work at Carnegie Mellon University's Software Engineering Institute helped formalize the concept of process maturity.


Watts S. Humphrey became one of the central figures in this movement.


The basic premise was powerful:

Consistently reliable results require consistently capable processes.

That concept should sound very familiar to an auditor.


Auditing is not simply about finding errors.


We evaluate the processes and internal controls responsible for preventing or detecting those errors.

The Five-Level Capability Maturity Model

The Capability Maturity Model ultimately popularized a five-level progression that influenced generations of maturity models.


The classic progression was essentially:


Level 1 — Initial

Processes are unpredictable, reactive, and dependent upon individuals.


Level 2 — Repeatable

Basic processes exist and previous successes can generally be repeated.


Level 3 — Defined

Processes are documented, standardized, and institutionalized.


Level 4 — Managed

Performance is quantitatively measured and controlled.


Level 5 — Optimizing

Continuous improvement becomes part of how the organization operates.


Different maturity models subsequently changed the terminology.


But the underlying progression remains remarkably consistent:

Ad Hoc → Repeatable → Defined → Measured → Optimized

That progression can be applied to far more than software development.


Maturity Thinking Moves Into Information Technology

Information technology became another major application of maturity and capability assessment.


Frameworks such as COBIT helped auditors, IT professionals, and management evaluate not merely whether technology controls existed, but the capability of the processes supporting IT governance and control.


This represented another important change for auditors.


Instead of asking only:

“Does the access control exist?”

we could ask:

“How mature is the organization's entire access-management process?”

That opens a much broader assessment.


Does management have:

  • Defined access policies?

  • Formal authorization requirements?

  • Role-based access?

  • Segregation-of-duties rules?

  • Privileged-access controls?

  • Periodic access certifications?

  • Termination procedures?

  • Exception monitoring?

  • Performance metrics?

  • Automated access governance?


The individual control remains important.


But the maturity assessment examines the capability surrounding the control.


Cybersecurity Makes Maturity a Business Issue

Cybersecurity provides one of today's clearest examples of maturity-model thinking.


Organizations do not suddenly move from “insecure” to “secure.”


Cybersecurity capabilities must be progressively developed, institutionalized, managed, tested, and improved.


The Cybersecurity Maturity Model Certification (CMMC) demonstrates how significant the maturity concept has become.


For organizations in the Defense Industrial Base, cybersecurity maturity is not merely an academic exercise.


It can become a business and contractual requirement.


Corporate Compliance Seminars provides several programs specifically addressing CMMC and the development of cybersecurity capabilities.


CCS Training: Overview of the CMMC Compliance Model

The Overview of the CMMC Compliance Model provides a foundation for understanding CMMC, cybersecurity practices, assessment requirements, and the progression of cybersecurity capabilities.


This is particularly useful for auditors, IT professionals, compliance professionals, and managers who need to understand how cybersecurity maturity differs from simply maintaining a list of security controls.


CCS Training: CMMC Level 1 Implementation

The CMMC Level 1 Implementation program addresses foundational safeguarding practices and the development of the basic security capabilities necessary to protect information systems.


CCS Training: CMMC Level 2 Implementation

The CMMC Level 2 Implementation training moves further into implementing and managing cybersecurity practices, including incident-detection, reporting, and response capabilities.


CCS Training: CMMC Level 3 Implementation

The CMMC Level 3 Implementation program addresses more advanced cybersecurity practices and the resources, processes, and management disciplines required to sustain stronger cybersecurity capabilities.


CMMC provides an excellent real-world example of why maturity matters.

Cybersecurity is not achieved because management purchased cybersecurity software.


Capability must be built.


Where Does COSO Fit?

This requires an important distinction.


The COSO Internal Control—Integrated Framework is not itself a five-level maturity model.


COSO provides a principles-based framework for designing, implementing, and evaluating internal control.


The Framework contains five components:

  1. Control Environment

  2. Risk Assessment

  3. Control Activities

  4. Information and Communication

  5. Monitoring Activities


Those components are supported by 17 principles.


A maturity methodology can then be overlaid on COSO to provide management with another dimension for assessing the system of internal control.


That distinction matters.


We are not claiming that COSO established five maturity levels.


Instead, we are asking:

How mature is our organization's implementation of each COSO component and principle?

A Five-Level COSO Maturity Approach

For practical internal-control assessments, organizations can use a progression such as:


Level 1 — Initial / Ad Hoc

Controls are informal, inconsistent, and highly dependent upon individual employees.


Level 2 — Developing / Repeatable

Basic control practices exist and are generally performed consistently.


Level 3 — Defined

Controls are documented, standardized, assigned to control owners, and linked to identified risks.


Level 4 — Managed and Measured

Management measures control performance, exceptions, failures, deficiencies, and corrective actions.


Level 5 — Optimized

Controls and control processes are continually reassessed and improved as risks, technology, operations, and organizational objectives change.


Now we can apply those levels to each COSO component.


Control Environment Maturity

How mature is the organization's foundation for internal control?


Consider:

  • Governance

  • Ethical values

  • Organizational structure

  • Management accountability

  • Assignment of authority

  • Competence

  • Human-resource practices

  • Board and Audit Committee oversight


An organization may have a Code of Conduct and technically satisfy a control requirement.


A more mature organization measures whether expected behaviors have actually become embedded within its corporate culture.


That is a fundamentally different level of capability.


Risk Assessment Maturity

A Level 1 organization may identify risks when something goes wrong.


A more mature organization has:

  • Defined objectives

  • Formal risk-identification processes

  • Risk owners

  • Risk-assessment criteria

  • Fraud-risk assessments

  • Consideration of significant change

  • Risk appetite and tolerance

  • Enterprise reporting

  • Periodic reassessment


At higher maturity levels, risk assessment becomes a continuing management process rather than an annual workshop.


Control Activities Maturity

Control Activities provide another clear example.


At a lower maturity level, employees may simply know:

“Mary approves all invoices.”

At higher maturity levels, management can demonstrate:


Risk → Control Objective → Control Activity → Control Owner → Evidence → Monitoring


Control Activities become deliberately designed responses to identified risks.


Management can then measure:

  • Exceptions

  • Overrides

  • Reconciliation differences

  • Segregation-of-duties conflicts

  • Processing errors

  • Control failures

  • Corrective-action aging


The control has moved from merely existing to being managed.


Information and Communication Maturity

Every organization communicates.


That doesn't mean communication is mature.


A mature information and communication process considers:

  • What information is required?

  • Who needs it?

  • When do they need it?

  • Is the information complete?

  • Is it accurate?

  • Is it timely?

  • Can employees communicate concerns upward?

  • Does the Board receive the information necessary for oversight?


The maturity question becomes particularly important when auditors encounter management reports containing incomplete, inaccurate, delayed, or misleading information.


Monitoring Activities Maturity

Monitoring is where maturity assessment becomes especially powerful.


At lower maturity levels, organizations often depend heavily upon:

  • External auditors

  • Internal auditors

  • Regulatory examinations

  • Employee complaints

  • Management discovering problems


More mature organizations develop their own mechanisms for identifying control deterioration.


They use:

  • Key performance indicators

  • Key risk indicators

  • Control-performance indicators

  • Exception reporting

  • Continuous monitoring

  • Data analytics

  • Control self-assessments

  • Issue tracking

  • Corrective-action monitoring


Management increasingly knows when controls are deteriorating before the auditor tells them.


That represents a substantial increase in maturity.


CCS Training: Understanding COSO Framework Compliance

For professionals beginning this journey, Corporate Compliance Seminars offers Understanding COSO Framework Compliance.


The program addresses the five COSO components, principles and points of focus, the top-down risk-based approach, internal-control classifications, control effectiveness, and practical application of the Framework.


It provides an appropriate foundation before attempting to assess maturity.


After all:

You cannot meaningfully measure COSO maturity without first understanding COSO.

CCS Training: Effective Use of the COSO Framework

Organizations wanting to move beyond basic understanding can consider the CCS Effective Use of the COSO Framework in-person program.


This two-day, 16-CPE program focuses on practical application of the Framework, including the five components, 17 principles, risk assessment, internal-control evaluation, documentation, and methods for improving an internal-control system.


The distinction between knowing a framework and effectively using a framework is itself a maturity issue.


CCS Training: COSO Framework — ICFR Assessments

The CCS COSO Framework: ICFR Assessments program takes the concept another step.


Among the subjects addressed are:

  • COSO concepts

  • Control deficiencies

  • ICFR scoping

  • Policy and protocol management

  • Control self-assessments

  • Key-control testing

  • Employee noncompliance

  • Measuring control maturity


This is where traditional control testing and maturity assessment begin to come together.


An auditor should understand both.


CCS Training: Testing the Operating Effectiveness of Internal Controls

Maturity assessment should never become a substitute for testing.

A beautifully documented Level 4 maturity presentation means very little if the underlying control isn't actually being performed.


CCS's Testing the Operating Effectiveness of Internal Controls training focuses on evaluating whether controls operate as intended and specifically incorporates control maturity into the broader assessment of internal controls.


The two concepts should complement one another:

Operating effectiveness tells us whether the control works.
Maturity tells us how developed and sustainable the control capability has become.

Organizations need both perspectives.


Don't Automatically Aim for Level 5

One of the biggest mistakes organizations can make is deciding:

“Every process needs to reach Level 5.”

No, it doesn't.


Maturity costs money.


It requires:

  • People

  • Technology

  • Documentation

  • Monitoring

  • Management attention

  • Training

  • Measurement


The appropriate maturity level should therefore be determined by risk.


A low-risk administrative process might function perfectly well at Level 2 or Level 3.


A critical financial-reporting, cybersecurity, regulatory-compliance, fraud-prevention, or safety control might require Level 4 or Level 5.


The objective should be:

Maturity commensurate with risk.

A Better Conversation With Management

Imagine an auditor reporting:

“Risk Assessment needs improvement.”

That doesn't tell management much.


Now consider:


COSO Component: Risk Assessment

  • Current Maturity: Level 2 — Developing

  • Target Maturity: Level 4 — Managed and Measured

  • Gap: Two maturity levels

  • Primary Capability Gaps:

    • Inconsistent enterprise risk identification

    • Limited assignment of risk ownership

    • No defined risk-tolerance methodology

    • Inadequate fraud-risk assessment

    • Limited consideration of significant change

    • No formal risk-performance reporting


  • Management Objective: Level 3 within six months and Level 4 within 18 months.


Now management has something actionable.


The Audit Committee also has something it can monitor.


From Audit Findings to Organizational Improvement

This may ultimately be the greatest contribution maturity models can make to Internal Audit.


Traditional auditing tends to concentrate on deficiencies.


Something is wrong.


The auditor documents it.


Management agrees or disagrees.


A corrective action is developed.


Eventually the finding is closed.


A maturity approach asks a larger question:

What capability does the organization need to develop so this problem is less likely to happen again?

That changes the conversation from correcting findings to building capability.


And that is exactly what the history of maturity models—from quality management to software engineering, IT governance, cybersecurity, and internal control—has been teaching organizations for decades.


The Question Auditors Should Be Asking

Auditors should continue asking:

Is the control properly designed?

We should continue asking:

Is the control operating effectively?

But there is value in adding another question:

How mature is the system responsible for making this control work consistently?

That question gives management and the Audit Committee a much better picture of organizational capability.


Because an effective control tells us something about today.


A mature control system gives us greater confidence about tomorrow.


Continue Building Your Internal Control and Maturity Assessment Skills

Corporate Compliance Seminars provides CPE training addressing COSO, internal-control assessment, operating effectiveness, ICFR, and cybersecurity maturity.


Relevant CCS programs include:

  • Understanding COSO Framework Compliance — Build a foundation in COSO's five components, 17 principles, internal-control concepts, and the top-down risk-based approach.

  • Effective Use of the COSO Framework — Develop practical skills for applying COSO to risk assessment, internal controls, governance, and organizational improvement.

  • Using COSO Framework for Compliance and SOX — Apply COSO concepts to compliance and Sarbanes-Oxley internal-control requirements.

  • COSO Framework: ICFR Assessments — Examine ICFR assessment techniques, control deficiencies, testing, control self-assessment, and control maturity.

  • Testing the Operating Effectiveness of Internal Controls — Develop stronger methods for determining whether controls actually operate as intended while considering control maturity.

  • Overview of the CMMC Compliance Model — Explore one of the most important contemporary applications of maturity-model thinking to cybersecurity.

  • CMMC Level 1, Level 2 and Level 3 Implementation Training — Examine the progressive development of cybersecurity practices and organizational capabilities.


Visit Corporate Compliance Seminars to explore upcoming CPE training events for internal auditors, external auditors, compliance professionals, risk professionals, and information technology professionals.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page