COSO vs. the GAO Green Book: Which Internal Control Framework Should Your Organization Use?
- John Blackshire
- Aug 2
- 13 min read
They Share the Same Architecture, but They Serve Different Governance Environments
Organizations often speak about COSO and the GAO Green Book as though they are competing internal control frameworks.
That is not an accurate way to view them.
The two frameworks share the same fundamental internal control architecture:
Five components of internal control
Seventeen principles
Objectives involving operations, reporting, and compliance
An entity-wide approach to designing, implementing, operating, and evaluating internal control
The principal difference is their intended environment.
The COSO Internal Control—Integrated Framework is broadly designed for businesses, nonprofit organizations, public companies, and other entities seeking a recognized system for internal control. COSO issued the original framework in 1992 and refreshed it in 2013. It remains one of the most widely used internal control frameworks in the United States and internationally.
The GAO Standards for Internal Control in the Federal Government, commonly called the Green Book, establishes internal control standards for federal agencies. Federal executive branch agencies are required to establish controls in accordance with it, while state, local, quasi-governmental, and nonprofit organizations may also adopt it. GAO issued a major revision in May 2025, effective beginning with fiscal year 2026.
The practical conclusion is straightforward:
COSO provides the broad internal control framework. The Green Book adapts and strengthens that framework for public-sector accountability.
For government entities, school districts, grant recipients, public authorities, and organizations administering public funds, that difference matters.
What Is the COSO Internal Control Framework?
The Committee of Sponsoring Organizations of the Treadway Commission—COSO—developed the Internal Control—Integrated Framework to help organizations design, implement, and evaluate internal control.
COSO’s mission extends across:
Internal control
Enterprise risk management
Governance
Fraud deterrence
Organizational performance
The current core internal control framework was refreshed in 2013. COSO explains that the framework was developed to improve confidence in all types of information and to help organizations address operations, reporting, and compliance objectives.
COSO is used extensively by:
Public companies
Private companies
Financial institutions
Insurance companies
Healthcare organizations
Nonprofit organizations
Internal audit departments
External auditors
Compliance functions
It is also closely associated with management assessments of Internal Control over
Financial Reporting under the Sarbanes-Oxley Act.
However, COSO is not limited to financial reporting.
Its structure can support controls over:
Operations
Regulatory compliance
Cybersecurity
Sustainability reporting
Data quality
Fraud risk
Information technology
Strategic execution
COSO has continued to publish supplemental guidance applying the framework to developing areas, including sustainability reporting, robotic process automation, and generative artificial intelligence.
What Is the GAO Green Book?
The Green Book is GAO’s Standards for Internal Control in the Federal Government.
The Federal Managers’ Financial Integrity Act requires the Comptroller General to issue internal control standards for the federal government. Federal executive branch agencies must establish controls consistent with those standards and periodically review and report on their systems.
GAO describes internal control as a management process used to help an agency:
Operate efficiently and effectively
Produce reliable information
Comply with applicable laws and regulations
The Green Book applies directly to federal agencies, but it may also be adopted by:
State governments
Local governments
School districts
Public authorities
Quasi-governmental organizations
Nonprofit organizations
Entities administering federal awards
It is also an important source of criteria for:
Inspectors general
Government auditors
Performance auditors
Independent public accountants
Grant compliance reviewers
Program managers
Financial managers
The 2025 Green Book superseded the 2014 version and became effective beginning with fiscal year 2026. Early implementation was permitted.
The Green Book Is Deliberately Harmonized with COSO
The similarities between COSO and the Green Book are not accidental.
GAO has intentionally aligned the Green Book with COSO’s Internal Control—Integrated Framework. The 2025 revision continued that harmonization while adding requirements and guidance tailored to government operations and public accountability.
Both frameworks use five integrated components:
Control Environment
Risk Assessment
Control Activities
Information and Communication
Monitoring Activities
Both also organize those components through seventeen principles.
This common structure allows professionals familiar with one framework to understand the other relatively quickly.
The terminology may differ in certain areas, and the Green Book includes more explicit government-focused requirements, but the conceptual foundation is substantially the same.
The Five Components Compared
1. Control Environment
The control environment provides the foundation for the internal control system.
It includes matters such as:
Integrity and ethical values
Oversight
Organizational structure
Authority and responsibility
Competence
Accountability
Under both frameworks, the tone established by leadership influences the effectiveness of every other control.
A technically sound reconciliation process will not remain effective in an organization where:
Deadlines are routinely ignored
Managers override controls
Employees fear reporting concerns
Responsibility is unclear
Poor performance has no consequence
The COSO emphasis
COSO presents the control environment as the organizational foundation supporting effective internal control across business and reporting objectives.
The Green Book emphasis
The Green Book applies these concepts to public-sector governance, emphasizing stewardship of public resources, accountability, ethical conduct, and management responsibility throughout the organization.
The 2025 revision specifically highlighted that internal control is management’s responsibility at every organizational level—not merely the responsibility of finance, compliance, or Internal Audit.
2. Risk Assessment
Risk assessment identifies and evaluates threats to the achievement of objectives.
Both frameworks expect management to:
Establish suitable objectives
Identify risks
Analyze risks
Consider fraud
Evaluate significant changes
The COSO emphasis
COSO allows organizations to tailor risk assessment to their strategy, industry, reporting environment, operations, and compliance obligations.
The Green Book emphasis
The Green Book applies risk assessment to government missions, programs, public funds, statutory responsibilities, and changing operating environments.
The 2025 revision strengthened requirements involving:
Fraud risk
Improper payments
Information security
New or substantially changed programs
Significant changes
Documentation of risk assessment results
Documentation of management’s change-assessment process
This additional specificity is particularly important for government entities managing:
Emergency assistance
Federal grants
Benefit programs
Public procurement
Student funding
Healthcare payments
Infrastructure projects
3. Control Activities
Control activities are the policies, procedures, and actions used to respond to risk.
Examples include:
Approvals
Reconciliations
Segregation of duties
Access controls
Physical safeguards
Exception reports
Supervisory reviews
Data validation
System controls
The COSO emphasis
COSO provides a flexible framework for selecting control activities appropriate to the entity’s objectives and identified risks.
The Green Book emphasis
The Green Book places stronger attention on the public-sector consequences of control failures, including waste, fraud, abuse, improper payments, and failure to fulfill legislative or program responsibilities.
The 2025 revision emphasizes the prioritization of preventive control activities. It also adds appendixes with examples of preventive and detective controls and potential sources of data that management can use when designing its system.
That does not mean detective controls are unimportant.
It means government entities should avoid relying exclusively on identifying errors after public money has already been:
Improperly spent
Paid to an ineligible recipient
Diverted through fraud
Lost through cybersecurity compromise
Used for an unauthorized purpose
4. Information and Communication
Internal control depends on relevant, reliable, and timely information.
Both frameworks require information to move:
Upward to management and governing bodies
Downward to employees performing controls
Across departments
Externally when required
The COSO emphasis
COSO applies information and communication across operational, financial, nonfinancial, and compliance environments.
The Green Book emphasis
The Green Book applies these concepts to public accountability, program reporting, legislative requirements, public transparency, grant administration, and regulatory communication.
Government organizations frequently depend on complex information flows among:
Program departments
Finance
Procurement
Information technology
Governing boards
Grantors
Regulators
The public
A control system can fail even when individual controls exist if decision-makers receive information that is:
Incomplete
Late
Inaccurate
Poorly explained
Not escalated
5. Monitoring Activities
Monitoring determines whether controls continue to operate effectively.
Monitoring may include:
Supervisory review
Management certifications
Internal audit
Compliance testing
Exception reporting
Data analytics
Corrective-action tracking
Independent evaluations
The COSO emphasis
COSO allows organizations to use ongoing evaluations, separate evaluations, or both.
The Green Book emphasis
The Green Book connects monitoring to public accountability and requires management to evaluate identified internal control issues and complete corrective action.
This is especially important in government organizations where audit findings may remain unresolved for several years.
A control deficiency is not resolved because management writes a response.
It is resolved when:
The corrective action is implemented
The revised control operates
Evidence supports effectiveness
Residual risk is appropriately addressed
The Most Important Structural Difference: Principles and Attributes
COSO establishes its framework through the five components and seventeen principles.
The Green Book uses those same components and principles but supplements each principle with attributes.
GAO describes the attributes as application guidance explaining the principle. Attributes may also contain minimum documentation requirements.
This makes the Green Book more prescriptive for managers and auditors working in government.
A COSO practitioner may ask:
Does the organization demonstrate a commitment to integrity and ethical values?
A Green Book practitioner asks the same question but also evaluates the government-specific attributes and documentation needed to demonstrate compliance.
This distinction affects:
Management assessments
Audit programs
Internal control documentation
Findings
Corrective-action plans
Government accountability reports
The attributes help translate broad principles into expectations that can be evaluated more consistently.
Framework vs. Standards
Another important difference involves the nature of the documents.
COSO Is a Framework
COSO provides an internationally recognized structure that organizations may adopt to design and evaluate internal control.
Its authority may arise because:
Management selects it
Regulators recognize it
External auditors accept it
Governance documents require it
It is used for Sarbanes-Oxley compliance
COSO itself is not a federal law or regulation.
The Green Book Establishes Standards
The Green Book establishes internal control standards for federal agencies under federal statutory authority.
Federal executive branch agencies are required to establish controls in accordance with it. State and local entities may adopt it voluntarily or may be required to follow it through state rules, grant provisions, or other requirements.
This creates a difference in tone.
COSO generally says:
Here is the framework for an effective system.
The Green Book effectively says:
These are the standards federal management must satisfy.
Public Accountability Is the Green Book’s Defining Feature
The strongest difference between the two frameworks is not their components or principles.
It is their accountability environment.
A private company’s internal control system supports:
Shareholder interests
Financial reporting
Operations
Compliance
Strategic objectives
A government organization’s system supports those objectives but also must address:
Stewardship of public money
Statutory authority
Public transparency
Legislative oversight
Program eligibility
Grant restrictions
Improper payments
Public trust
Equity and consistency in program administration
Government management cannot simply decide that a control is not worth the cost when the control is required by law or necessary to protect public funds.
The Green Book therefore places internal control within the broader obligation of government accountability.
The 2025 Green Book Is More Explicit About Documentation
The 2025 revision requires documentation of risk assessment results, including the identification, analysis, and response to risks. It also requires documentation of the process used to identify, analyze, and respond to significant change.
This addresses a common weakness in public-sector internal control programs.
Management may state that it considered:
Fraud
Cybersecurity
Improper payments
Staffing changes
System implementations
New legislation
But there may be little evidence showing:
Which risks were identified
How likelihood and impact were analyzed
Who participated
What response was selected
Which controls were created
Who accepted residual risk
The Green Book expects management to create an audit trail supporting those decisions.
COSO also recognizes the importance of documentation, but the Green Book’s attributes and public-sector standards make the expectation more explicit.
Fraud Risk Is Important Under Both Frameworks
Both COSO and the Green Book require management to consider fraud.
Possible fraud risks include:
Procurement fraud
Payroll fraud
Grant fraud
Benefits fraud
Financial reporting fraud
Management override
Conflicts of interest
Cyber-enabled fraud
Vendor collusion
Theft of assets
The Green Book’s government orientation makes fraud especially significant because losses involve public resources.
The 2025 revision provides additional requirements and resources for addressing fraud and improper payments.
Government entities should not treat their annual fraud risk assessment as a generic checklist.
They should consider:
Incentives
Opportunities
Override authority
Decentralized operations
Cash handling
Vendor access
Emergency procurement
Eligibility determinations
Information-system weaknesses
Changes in program funding
Improper Payments Are a Distinct Green Book Concern
Improper payments may result from:
Fraud
Administrative mistakes
Ineligible recipients
Duplicate payments
Insufficient documentation
Incorrect calculations
Payments made before required verification
Not every improper payment is fraudulent.
However, every improper payment represents a failure to ensure that public funds were paid:
To the correct recipient
In the correct amount
For an authorized purpose
At the proper time
The 2025 Green Book explicitly requires management to consider improper-payment risk when identifying, analyzing, and responding to risks.
This is one of the clearest areas where the Green Book is more specifically tailored to government programs than the general COSO framework.
Information Security Is Now an Explicit Green Book Priority
Cybersecurity and information security have become central internal control concerns.
Government entities depend on technology to administer:
Payroll
Grants
Student records
Public benefits
Tax collections
Procurement
Financial reporting
Public safety
Infrastructure
The 2025 Green Book expressly strengthens the treatment of information-security risks.
This means government management should integrate information security into the complete internal control system rather than treating it as a separate IT issue.
Questions should include:
Which information supports critical programs?
Who can access it?
How is it protected?
Are system-generated reports reliable?
How are technology changes controlled?
Can operations continue after a cyberattack?
Are vendors adequately monitored?
How does management know security controls are operating?
COSO can support the same analysis, but the updated Green Book makes the government requirement unmistakable.
How Each Framework Defines an Effective System
Under both frameworks, all five components must be:
Designed
Implemented
Operating
Working together in an integrated manner
An organization cannot claim an effective system merely because it has policies covering all seventeen principles.
Effectiveness requires operation.
For example, an entity may have:
An ethics policy
A risk-assessment template
Approval procedures
A communication policy
An internal audit function
The system may still be ineffective when:
Leadership overrides policy
Risk assessments are copied forward
Approvals are undocumented
Significant issues are not communicated
Audit findings remain unresolved
The components must function together.
Neither Framework Makes Internal Audit Responsible for Internal Control
A persistent governance mistake is assigning ownership of the internal control system to Internal Audit.
That is wrong under both COSO and the Green Book.
Management is responsible for:
Establishing objectives
Identifying risks
Designing controls
Operating controls
Monitoring performance
Correcting deficiencies
Internal Audit is responsible for providing independent assurance.
Internal Audit may:
Facilitate risk discussions
Advise on framework implementation
Evaluate control design
Test operating effectiveness
Report deficiencies
Monitor remediation
Internal Audit should not:
Own business controls
Approve management transactions
Accept risks
Implement corrective actions
Certify management’s system on management’s behalf
The 2025 Green Book reinforces management responsibility at all organizational levels.
Which Framework Should a Private Company Use?
For most private-sector organizations, COSO is the natural choice.
It offers:
Broad applicability
Recognition by auditors and regulators
Alignment with financial reporting
Flexibility across industries
Extensive implementation guidance
Compatibility with enterprise risk management
A private company may still consult the Green Book when it:
Receives federal funds
Administers government programs
Contracts extensively with government
Wants more prescriptive documentation
Needs stronger guidance on improper payments
Operates in a highly accountable public-service environment
The Green Book can supplement COSO even when it is not mandatory.
Which Framework Should a Government Entity Use?
Federal executive branch agencies must use the Green Book.
State, local, and quasi-governmental organizations should carefully evaluate whether:
State law requires it
Grant agreements require it
The governing board adopted it
The external auditor uses it as criteria
The organization administers federal programs
The entity wants a framework designed for public accountability
For many government entities, the Green Book is the stronger primary framework because it speaks directly to:
Government missions
Public funds
Improper payments
Fraud
Compliance
Program operations
Documentation
Oversight
COSO remains relevant because the Green Book is harmonized with it.
Using the Green Book does not mean rejecting COSO.
It means applying COSO’s architecture through government-specific standards.
Which Framework Should a School District Use?
School districts occupy a particularly important position.
They manage:
State funding
Federal grants
Student activity funds
Payroll
Procurement
Transportation
Food programs
Construction
Technology
Student information
Special education funding
A school district could use COSO effectively.
However, the Green Book often offers the stronger fit because school districts are public entities responsible for public funds and extensive legal compliance.
The 2025 Green Book’s greater attention to:
Fraud
Improper payments
Information security
Preventive controls
Change assessment
Documentation
is directly relevant to the risks faced by school districts.
For example, a district implementing a new payroll or student-information system should document:
What changed
What new risks were identified
How those risks were analyzed
Which controls were redesigned
How management confirmed the controls operated
That is not simply good audit practice.
It is responsible public governance.
Can an Organization Use Both?
Yes.
In many cases, the most practical approach is:
Use COSO as the broad conceptual framework.
Use the Green Book for government-specific requirements and application.
Use industry guidance for specialized risks.
Use audit standards to evaluate the system.
A public authority might map:
COSO components
COSO principles
Green Book principles and attributes
State requirements
Organizational policies
Key controls
Evidence
Control owners
Testing results
This produces one integrated control system rather than competing compliance programs.
Because the structures are harmonized, organizations should avoid maintaining separate “COSO controls” and “Green Book controls” unless a genuine requirement differs.
A Practical Comparison
Area | COSO Internal Control Framework | GAO Green Book |
Primary users | Private companies, public companies, nonprofits and other organizations | Federal agencies; also usable by state, local, quasi-governmental and nonprofit entities |
Current core version | 2013 Internal Control—Integrated Framework | 2025 Standards for Internal Control in the Federal Government |
Effective date | Framework refreshed in 2013 | Effective beginning fiscal year 2026 |
Authority | Voluntary framework unless required by regulation, governance or contractual criteria | Required for federal executive branch agencies under federal authority |
Components | Five | Five |
Principles | Seventeen | Seventeen |
Detailed guidance | Points of focus and implementation guidance | Attributes, including application guidance and some minimum documentation requirements |
Objectives | Operations, reporting and compliance | Operations, reporting and compliance |
Main orientation | Broad organizational and business application | Government missions, public funds and accountability |
Fraud | Required consideration | Required consideration, with enhanced government-focused guidance |
Improper payments | May be addressed as part of risk assessment | Explicitly emphasized in the 2025 revision |
Information security | Addressed through risk and control structure and supplemental guidance | Explicitly emphasized in the 2025 revision |
Change assessment | Required through the principle addressing significant change | Explicit documentation of a change-assessment process emphasized in 2025 |
Preventive controls | Selected based on risk | Greater emphasis on prioritizing preventive control activities |
Documentation | Flexible and scalable | More explicit through attributes and 2025 documentation requirements |
The table reflects the current COSO framework and the 2025 Green Book.
Common Implementation Mistakes Under Either Framework
Treating the Framework as a Checklist
The objective is an effective system—not seventeen completed boxes.
Documenting Controls That Do Not Operate
A control narrative does not prove performance.
Assigning the Program to Finance Alone
Internal control belongs to every manager.
Ignoring Information Technology
Business and financial controls increasingly depend on systems, reports, access, and interfaces.
Failing to Reassess After Change
Acquisitions, new systems, reorganizations, emergencies, and new programs create new risks.
Confusing Internal Audit with Management
Internal Audit evaluates the control system. It does not own it.
Correcting Exceptions Without Addressing Root Cause
A late reconciliation may signal weak staffing, ownership, supervision, or system design.
Allowing Findings to Remain Open Indefinitely
An uncorrected deficiency is an accepted exposure, whether management admits it or not.
Questions Governing Boards and Audit Committees Should Ask
Which framework has the organization formally adopted?
Why is that framework appropriate?
Have all five components been designed and implemented?
Are the seventeen principles operating in practice?
Who owns the internal control system?
How are risks documented?
How does management assess significant change?
How are fraud and improper-payment risks addressed?
How are cybersecurity and information-security risks integrated?
What evidence demonstrates that controls operate?
Which deficiencies remain unresolved?
Does Internal Audit independently evaluate the system?
Does the governing body receive meaningful internal control reporting?
Would the organization’s documentation withstand an external audit or regulatory review?
A board should be concerned when management’s answer is:
“Internal Audit handles COSO.”
That response indicates that the organization does not understand control ownership.
The Bottom Line
COSO and the Green Book should not be treated as rival frameworks.
They share the same basic internal control structure.
The difference lies in application and authority.
COSO is the broad, widely recognized internal control framework used across industries and organizational types.
The Green Book applies that architecture to federal government operations and strengthens it with public-sector standards, attributes, documentation expectations, and specific attention to fraud, improper payments, information security, preventive controls, and significant organizational change.
For private-sector organizations, COSO will usually remain the primary framework.
For federal agencies, the Green Book is mandatory.
For state and local governments, school districts, public authorities, and nonprofit organizations administering public funds, the Green Book frequently provides the more appropriate standard—even when its use is voluntary.
The choice of framework matters.
What matters more is whether management actually operates the system.
A beautifully documented framework cannot compensate for:
Weak leadership
Unassessed risk
Unperformed controls
Unreliable information
Unresolved findings
Internal control is not the framework sitting on a shelf.
It is what management and employees do every day to help the organization achieve its objectives, protect its resources, produce reliable information, and comply with its obligations.
Comments