Internal Control Checklist Template: COSO Areas and Review Steps

An internal control checklist template is a structured worksheet your organization uses to test, on a repeatable schedule, whether its safeguards against fraud, error, and regulatory violations are actually working. A good template maps its sections to the five components of the Committee of Sponsoring Organizations (COSO) framework, walks the assessor through the operational areas where control failures cause the most damage, and produces a documented pass/fail record with severity ratings and follow-up dates. What follows is what belongs in that template and how to use it.

The Five COSO Components Your Template Should Map To

COSO defines internal control as a process carried out by an organization’s board, management, and staff to provide reasonable assurance that the organization meets its objectives around operations, reporting, and compliance. The framework breaks internal control into five integrated components, and each section of your template should tie back to one or more of them:

  • Control environment: the standards, processes, and structures that set the tone for how seriously the organization takes internal control, including leadership’s commitment to ethical conduct and how reporting lines are assigned.
  • Risk assessment: identifying and analyzing the risks, including fraud risks, that could keep the organization from reaching its objectives.
  • Control activities: the policies and procedures that carry out management’s instructions for reducing risk. Approvals, authorizations, reconciliations, and segregation of duties all sit here.
  • Information and communication: getting relevant, accurate information to the right people at the right time.
  • Monitoring: ongoing evaluations and separate assessments to confirm the other four components are present and functioning.

When each checklist section is tagged to a component, gaps in coverage become obvious during planning rather than during a crisis. COSO applies to public companies, private businesses, and nonprofits, though the depth and formality of your controls scale with the size and complexity of the organization.

What to Gather Before You Fill Anything In

A checklist is only as useful as the information behind it. Pull these materials together before the assessment starts so the template header (assessor name, department, scope, review date) can be populated and the review doesn’t stall halfway through:

  • Organizational chart, so you know who owns each control.
  • Prior audit reports and management letters, so areas that failed last cycle get extra scrutiny.
  • Policy manuals and employee handbooks, which are the written standards you’ll measure actual practices against.
  • Financial records: bank statements from the most recent quarter, general ledger access, inventory logs, and accounts payable aging reports.
  • System access logs, user access lists, password policy documentation, and termination records.

Core Operational Areas the Template Should Cover

Every organization is different, but most templates share the same operational spine. These are the sections where control failures cost the most.

Cash Handling and Disbursements

Cash is the asset most vulnerable to theft, so this section runs the longest. Include fields for daily cash reconciliation schedules, a dual-signature requirement above a threshold your organization sets (common thresholds run from $1,000 to $10,000 depending on size), and documentation of who has physical access to cash rooms or safes. The reconciliation field should capture whether the person counting cash is different from the person recording it in the ledger. If one employee handles both, that’s a segregation-of-duties gap that makes fraud easy to commit and hard to detect.

Payroll Processing

Payroll fraud tends to go undetected longer than any other type because the per-period amounts look routine. The template needs fields for timecard authorization, verification that benefit calculations match the employee’s enrollment elections, and confirmation that the person approving hours is not the person issuing the payment. Ghost employees and inflated hours are the two most common schemes, and both become nearly impossible when no single person controls the process from time entry through check issuance.

Accounts Payable and Procurement

The procurement cycle creates fraud opportunities at every stage. Build in a field for three-way matching: the purchase order, the supplier’s invoice, and the receiving report compared line by line before payment is approved. Quantities, prices, and additional charges should all match. If they don’t, the template should require investigation before the invoice moves. This one control catches pricing errors, short shipments, and unauthorized purchases before money leaves.

Include a separate field verifying that changes to the vendor master file (new vendors, bank account updates) require approval from someone outside accounts payable. Vendor master file manipulation is how many embezzlement schemes start.

Fixed Asset Management

Equipment, vehicles, and other long-lived assets need controls that cover the entire lifecycle: acquisition, tagging, depreciation, and disposal. Add fields for physical count discrepancies, write-off approvals, and confirmation that custodial responsibility is assigned to the department manager who actually uses the asset. A capitalization threshold field documents the dollar amount above which a purchase gets recorded as an asset rather than expensed. Organizations commonly set this between $1,000 and $5,000. Without a documented threshold, similar purchases get treated inconsistently, which distorts financial statements.

Information Technology Access

IT controls have become as important as any financial control. Cover user access rights, password complexity standards, and access revocation for terminated employees. On revocation, verify that system access is actually removed promptly after an employee leaves. NIST guidance treats the revocation timeline as something each organization defines based on its own risk profile rather than imposing a fixed deadline, but most security professionals treat same-day revocation as the minimum for sensitive systems.

If your organization is a financial institution under the Gramm-Leach-Bliley Act (banks, insurance companies, and companies offering financial products or services to consumers), your IT access controls need to fit into a comprehensive information security program with administrative, technical, and physical safeguards appropriate to the size of the organization and the sensitivity of the customer information it handles.1Federal Trade Commission. Gramm-Leach-Bliley Act Organizations outside financial services face different data privacy obligations depending on industry and state.

Segregation of Duties as a Cross-Cutting Check

Segregation of duties shows up in almost every section of the template because it’s the single most effective control against fraud. The principle is simple: no one person should control an entire transaction from start to finish. When the same person creates vendor records and processes invoices, they can invent a fake vendor and pay themselves. When the same person orders assets and confirms delivery in the accounting system, they can accept kickbacks for goods that never arrive.

For each key process, identify who initiates, who authorizes, who records, and who reconciles. If any two of those functions land on the same person, flag it. Small organizations where staff size makes perfect segregation impossible should document the overlap and identify what compensating controls exist, such as management review or surprise audits, to offset the risk.

Running the Review

A completed template is worthless if the review behind it was superficial. Combine three methods:

  • Walk-throughs. Physically observe daily operations in real time. Watch how cash gets counted, how invoices get matched, how inventory gets received. What people say in an interview and what they do often diverge.
  • Interviews. Talk to the staff performing each process. Confirm they understand the written procedure and can explain why the control exists. If someone can’t articulate the purpose, the control is probably being followed mechanically at best.
  • Document testing. Pull a sample of transactions and trace them through the system. Compare ledger entries against receipts, reconciliation reports against bank statements, and access logs against the current employee roster.

Mark each line item pass or fail based on the evidence. If a control fails, record a detailed description in the observations field and attach supporting documentation: copies of mismatched invoices, screenshots of unauthorized access, photos of unsecured cash drawers. That evidence trail justifies the assessment and gives whoever designs the corrective action a clear picture of what went wrong.

Classifying What You Find

Not all failures carry the same weight. The Public Company Accounting Oversight Board draws a line between two categories that every organization can use, whether public or not:

  • Material weakness: a control gap, or combination of gaps, where there’s a reasonable possibility that a material misstatement in the financial statements won’t be caught in time. This is the most serious finding. For public companies, a material weakness must be publicly disclosed and prevents management from concluding that internal controls are effective.2Public Company Accounting Oversight Board. Auditing Standard No. 5 – Appendix A Definitions
  • Significant deficiency: less severe than a material weakness but still important enough to merit the attention of people overseeing financial reporting.2Public Company Accounting Oversight Board. Auditing Standard No. 5 – Appendix A Definitions

Using these labels in your template gives every finding a consistent severity rating that helps leadership prioritize remediation. A material weakness gets resources immediately; a significant deficiency goes on the near-term action plan.

Retention and Follow-Up

Once the assessor signs off, submit the completed template to the compliance officer or board of directors. High-level management should formally acknowledge any failures identified during the process. For areas marked fail, schedule a follow-up review (six months is standard) to verify that corrective actions were implemented and are working.

Archive the completed checklist in a secure repository. Federal rules require accounting firms to retain audit workpapers and related records for seven years after concluding an audit or review.3eCFR. 17 CFR 210.2-06 – Retention of Audit and Review Records That rule applies to the audit firm rather than the company itself, but many organizations adopt the same seven-year standard for their own internal control documentation. If your industry has a longer retention requirement, follow whichever is longer.

Extra Fields Public Companies Need

If the organization is publicly traded, the checklist feeds directly into legally required disclosures, so the template needs additional fields.

Section 404(a) of the Sarbanes-Oxley Act requires every annual report filed with the SEC to include an internal control report stating management’s responsibility for internal controls over financial reporting and containing management’s assessment of whether those controls were effective as of the fiscal year end.4Office of the Law Revision Counsel. United States Code Title 15 Section 7262 – Management Assessment of Internal Controls Section 404(b) requires an independent auditor to attest to that assessment, but smaller issuers that don’t qualify as accelerated filers are exempt from the attestation.5U.S. Securities and Exchange Commission. Smaller Reporting Companies A company with a public float under $75 million, or one with a public float of $75 million or more but less than $100 million in revenues, generally qualifies as a non-accelerated filer. Management also cannot conclude that internal controls are effective while a material weakness exists, and any material change to internal controls must be disclosed in every subsequent quarterly and annual report after the first management report.6U.S. Securities and Exchange Commission. Management’s Report on Internal Control Over Financial Reporting

Under SOX Section 301, public companies must establish procedures for receiving complaints about accounting, internal controls, or auditing matters. The audit committee, not management, is responsible for creating and overseeing these procedures, and the system must let employees submit concerns confidentially and anonymously.7U.S. Department of Labor. Sarbanes-Oxley Act of 2002 Public Law 107-204 The template should include a field verifying that this reporting mechanism exists, is accessible to all employees at all locations, and that the audit committee keeps records of every complaint received, investigated, and resolved.

Weak internal controls are often what lead to inaccurate financial statements, and inaccurate financial statements are what put CEO and CFO certifications at risk under 18 U.S.C. ยง 1350, which carries fines up to $1 million and up to 10 years in prison for knowing false certifications, and up to $5 million and 20 years for willful ones.8Office of the Law Revision Counsel. United States Code Title 18 Section 1350 – Failure of Corporate Officers to Certify Financial Reports A thorough checklist is one of the better defenses against ending up there.

Extra Fields Nonprofits Need

Nonprofits aren’t subject to SOX, but they answer to donors, grantmakers, and state regulators through IRS Form 990. Part VI of the 990 asks directly whether the organization has a written conflict of interest policy, a whistleblower policy, and a document retention and destruction policy.9Internal Revenue Service. Instructions for Form 990 Answering “no” doesn’t create a penalty by itself, but the 990 is publicly available.

Form 990 also asks whether the organization used a specific process for setting executive compensation, including review by an independent body, use of comparable compensation data, and contemporaneous documentation of the deliberations.9Internal Revenue Service. Instructions for Form 990 A nonprofit’s template should include fields matching each of these questions, so completing the annual review also prepares the organization for its 990 filing.

Board members share responsibility for financial controls, and failing to protect charitable assets can constitute a breach of fiduciary duty. At minimum, the board should receive and review monthly financial reports, compare budgeted figures against actual income and expenses, and set a reasonable threshold for requiring dual signatures on checks. Treating the internal control checklist as a standing board agenda item builds a documented record that the board took its oversight role seriously.