top of page
Search

COSO vs. the GAO Green Book: Which Internal Control Framework Should Your Organization Use?

They Share the Same Architecture, but They Serve Different Governance Environments

Organizations often speak about COSO and the GAO Green Book as though they are competing internal control frameworks.


That is not an accurate way to view them.


The two frameworks share the same fundamental internal control architecture:

  • Five components of internal control

  • Seventeen principles

  • Objectives involving operations, reporting, and compliance

  • An entity-wide approach to designing, implementing, operating, and evaluating internal control


The principal difference is their intended environment.


The COSO Internal Control—Integrated Framework is broadly designed for businesses, nonprofit organizations, public companies, and other entities seeking a recognized system for internal control. COSO issued the original framework in 1992 and refreshed it in 2013. It remains one of the most widely used internal control frameworks in the United States and internationally.


The GAO Standards for Internal Control in the Federal Government, commonly called the Green Book, establishes internal control standards for federal agencies. Federal executive branch agencies are required to establish controls in accordance with it, while state, local, quasi-governmental, and nonprofit organizations may also adopt it. GAO issued a major revision in May 2025, effective beginning with fiscal year 2026.


The practical conclusion is straightforward:

COSO provides the broad internal control framework. The Green Book adapts and strengthens that framework for public-sector accountability.

For government entities, school districts, grant recipients, public authorities, and organizations administering public funds, that difference matters.


What Is the COSO Internal Control Framework?

The Committee of Sponsoring Organizations of the Treadway Commission—COSO—developed the Internal Control—Integrated Framework to help organizations design, implement, and evaluate internal control.


COSO’s mission extends across:

  • Internal control

  • Enterprise risk management

  • Governance

  • Fraud deterrence

  • Organizational performance


The current core internal control framework was refreshed in 2013. COSO explains that the framework was developed to improve confidence in all types of information and to help organizations address operations, reporting, and compliance objectives.


COSO is used extensively by:

  • Public companies

  • Private companies

  • Financial institutions

  • Insurance companies

  • Healthcare organizations

  • Nonprofit organizations

  • Internal audit departments

  • External auditors

  • Compliance functions


It is also closely associated with management assessments of Internal Control over

Financial Reporting under the Sarbanes-Oxley Act.


However, COSO is not limited to financial reporting.


Its structure can support controls over:

  • Operations

  • Regulatory compliance

  • Cybersecurity

  • Sustainability reporting

  • Data quality

  • Fraud risk

  • Information technology

  • Strategic execution


COSO has continued to publish supplemental guidance applying the framework to developing areas, including sustainability reporting, robotic process automation, and generative artificial intelligence.


What Is the GAO Green Book?

The Green Book is GAO’s Standards for Internal Control in the Federal Government.


The Federal Managers’ Financial Integrity Act requires the Comptroller General to issue internal control standards for the federal government. Federal executive branch agencies must establish controls consistent with those standards and periodically review and report on their systems.


GAO describes internal control as a management process used to help an agency:

  • Operate efficiently and effectively

  • Produce reliable information

  • Comply with applicable laws and regulations


The Green Book applies directly to federal agencies, but it may also be adopted by:

  • State governments

  • Local governments

  • School districts

  • Public authorities

  • Quasi-governmental organizations

  • Nonprofit organizations

  • Entities administering federal awards


It is also an important source of criteria for:

  • Inspectors general

  • Government auditors

  • Performance auditors

  • Independent public accountants

  • Grant compliance reviewers

  • Program managers

  • Financial managers


The 2025 Green Book superseded the 2014 version and became effective beginning with fiscal year 2026. Early implementation was permitted.


The Green Book Is Deliberately Harmonized with COSO

The similarities between COSO and the Green Book are not accidental.


GAO has intentionally aligned the Green Book with COSO’s Internal Control—Integrated Framework. The 2025 revision continued that harmonization while adding requirements and guidance tailored to government operations and public accountability.


Both frameworks use five integrated components:

  1. Control Environment

  2. Risk Assessment

  3. Control Activities

  4. Information and Communication

  5. Monitoring Activities


Both also organize those components through seventeen principles.


This common structure allows professionals familiar with one framework to understand the other relatively quickly.


The terminology may differ in certain areas, and the Green Book includes more explicit government-focused requirements, but the conceptual foundation is substantially the same.


The Five Components Compared

1. Control Environment

The control environment provides the foundation for the internal control system.


It includes matters such as:

  • Integrity and ethical values

  • Oversight

  • Organizational structure

  • Authority and responsibility

  • Competence

  • Accountability


Under both frameworks, the tone established by leadership influences the effectiveness of every other control.


A technically sound reconciliation process will not remain effective in an organization where:

  • Deadlines are routinely ignored

  • Managers override controls

  • Employees fear reporting concerns

  • Responsibility is unclear

  • Poor performance has no consequence


The COSO emphasis

COSO presents the control environment as the organizational foundation supporting effective internal control across business and reporting objectives.


The Green Book emphasis

The Green Book applies these concepts to public-sector governance, emphasizing stewardship of public resources, accountability, ethical conduct, and management responsibility throughout the organization.


The 2025 revision specifically highlighted that internal control is management’s responsibility at every organizational level—not merely the responsibility of finance, compliance, or Internal Audit.


2. Risk Assessment

Risk assessment identifies and evaluates threats to the achievement of objectives.


Both frameworks expect management to:

  • Establish suitable objectives

  • Identify risks

  • Analyze risks

  • Consider fraud

  • Evaluate significant changes


The COSO emphasis

COSO allows organizations to tailor risk assessment to their strategy, industry, reporting environment, operations, and compliance obligations.


The Green Book emphasis

The Green Book applies risk assessment to government missions, programs, public funds, statutory responsibilities, and changing operating environments.


The 2025 revision strengthened requirements involving:

  • Fraud risk

  • Improper payments

  • Information security

  • New or substantially changed programs

  • Significant changes

  • Documentation of risk assessment results

  • Documentation of management’s change-assessment process


This additional specificity is particularly important for government entities managing:

  • Emergency assistance

  • Federal grants

  • Benefit programs

  • Public procurement

  • Student funding

  • Healthcare payments

  • Infrastructure projects


3. Control Activities

Control activities are the policies, procedures, and actions used to respond to risk.


Examples include:

  • Approvals

  • Reconciliations

  • Segregation of duties

  • Access controls

  • Physical safeguards

  • Exception reports

  • Supervisory reviews

  • Data validation

  • System controls


The COSO emphasis

COSO provides a flexible framework for selecting control activities appropriate to the entity’s objectives and identified risks.


The Green Book emphasis

The Green Book places stronger attention on the public-sector consequences of control failures, including waste, fraud, abuse, improper payments, and failure to fulfill legislative or program responsibilities.


The 2025 revision emphasizes the prioritization of preventive control activities. It also adds appendixes with examples of preventive and detective controls and potential sources of data that management can use when designing its system.


That does not mean detective controls are unimportant.


It means government entities should avoid relying exclusively on identifying errors after public money has already been:

  • Improperly spent

  • Paid to an ineligible recipient

  • Diverted through fraud

  • Lost through cybersecurity compromise

  • Used for an unauthorized purpose


4. Information and Communication

Internal control depends on relevant, reliable, and timely information.


Both frameworks require information to move:

  • Upward to management and governing bodies

  • Downward to employees performing controls

  • Across departments

  • Externally when required


The COSO emphasis

COSO applies information and communication across operational, financial, nonfinancial, and compliance environments.


The Green Book emphasis

The Green Book applies these concepts to public accountability, program reporting, legislative requirements, public transparency, grant administration, and regulatory communication.


Government organizations frequently depend on complex information flows among:

  • Program departments

  • Finance

  • Procurement

  • Information technology

  • Governing boards

  • Grantors

  • Regulators

  • The public


A control system can fail even when individual controls exist if decision-makers receive information that is:

  • Incomplete

  • Late

  • Inaccurate

  • Poorly explained

  • Not escalated


5. Monitoring Activities

Monitoring determines whether controls continue to operate effectively.


Monitoring may include:

  • Supervisory review

  • Management certifications

  • Internal audit

  • Compliance testing

  • Exception reporting

  • Data analytics

  • Corrective-action tracking

  • Independent evaluations


The COSO emphasis

COSO allows organizations to use ongoing evaluations, separate evaluations, or both.


The Green Book emphasis

The Green Book connects monitoring to public accountability and requires management to evaluate identified internal control issues and complete corrective action.


This is especially important in government organizations where audit findings may remain unresolved for several years.


A control deficiency is not resolved because management writes a response.


It is resolved when:

  • The corrective action is implemented

  • The revised control operates

  • Evidence supports effectiveness

  • Residual risk is appropriately addressed


The Most Important Structural Difference: Principles and Attributes

COSO establishes its framework through the five components and seventeen principles.

The Green Book uses those same components and principles but supplements each principle with attributes.


GAO describes the attributes as application guidance explaining the principle. Attributes may also contain minimum documentation requirements.


This makes the Green Book more prescriptive for managers and auditors working in government.


A COSO practitioner may ask:

Does the organization demonstrate a commitment to integrity and ethical values?

A Green Book practitioner asks the same question but also evaluates the government-specific attributes and documentation needed to demonstrate compliance.


This distinction affects:

  • Management assessments

  • Audit programs

  • Internal control documentation

  • Findings

  • Corrective-action plans

  • Government accountability reports


The attributes help translate broad principles into expectations that can be evaluated more consistently.


Framework vs. Standards

Another important difference involves the nature of the documents.


COSO Is a Framework

COSO provides an internationally recognized structure that organizations may adopt to design and evaluate internal control.


Its authority may arise because:

  • Management selects it

  • Regulators recognize it

  • External auditors accept it

  • Governance documents require it

  • It is used for Sarbanes-Oxley compliance


COSO itself is not a federal law or regulation.


The Green Book Establishes Standards

The Green Book establishes internal control standards for federal agencies under federal statutory authority.


Federal executive branch agencies are required to establish controls in accordance with it. State and local entities may adopt it voluntarily or may be required to follow it through state rules, grant provisions, or other requirements.


This creates a difference in tone.


COSO generally says:

Here is the framework for an effective system.

The Green Book effectively says:

These are the standards federal management must satisfy.

Public Accountability Is the Green Book’s Defining Feature

The strongest difference between the two frameworks is not their components or principles.


It is their accountability environment.


A private company’s internal control system supports:

  • Shareholder interests

  • Financial reporting

  • Operations

  • Compliance

  • Strategic objectives


A government organization’s system supports those objectives but also must address:

  • Stewardship of public money

  • Statutory authority

  • Public transparency

  • Legislative oversight

  • Program eligibility

  • Grant restrictions

  • Improper payments

  • Public trust

  • Equity and consistency in program administration


Government management cannot simply decide that a control is not worth the cost when the control is required by law or necessary to protect public funds.


The Green Book therefore places internal control within the broader obligation of government accountability.


The 2025 Green Book Is More Explicit About Documentation

The 2025 revision requires documentation of risk assessment results, including the identification, analysis, and response to risks. It also requires documentation of the process used to identify, analyze, and respond to significant change.


This addresses a common weakness in public-sector internal control programs.


Management may state that it considered:

  • Fraud

  • Cybersecurity

  • Improper payments

  • Staffing changes

  • System implementations

  • New legislation


But there may be little evidence showing:

  • Which risks were identified

  • How likelihood and impact were analyzed

  • Who participated

  • What response was selected

  • Which controls were created

  • Who accepted residual risk


The Green Book expects management to create an audit trail supporting those decisions.


COSO also recognizes the importance of documentation, but the Green Book’s attributes and public-sector standards make the expectation more explicit.


Fraud Risk Is Important Under Both Frameworks

Both COSO and the Green Book require management to consider fraud.


Possible fraud risks include:

  • Procurement fraud

  • Payroll fraud

  • Grant fraud

  • Benefits fraud

  • Financial reporting fraud

  • Management override

  • Conflicts of interest

  • Cyber-enabled fraud

  • Vendor collusion

  • Theft of assets


The Green Book’s government orientation makes fraud especially significant because losses involve public resources.


The 2025 revision provides additional requirements and resources for addressing fraud and improper payments.


Government entities should not treat their annual fraud risk assessment as a generic checklist.


They should consider:

  • Incentives

  • Opportunities

  • Override authority

  • Decentralized operations

  • Cash handling

  • Vendor access

  • Emergency procurement

  • Eligibility determinations

  • Information-system weaknesses

  • Changes in program funding


Improper Payments Are a Distinct Green Book Concern

Improper payments may result from:

  • Fraud

  • Administrative mistakes

  • Ineligible recipients

  • Duplicate payments

  • Insufficient documentation

  • Incorrect calculations

  • Payments made before required verification


Not every improper payment is fraudulent.


However, every improper payment represents a failure to ensure that public funds were paid:

  • To the correct recipient

  • In the correct amount

  • For an authorized purpose

  • At the proper time


The 2025 Green Book explicitly requires management to consider improper-payment risk when identifying, analyzing, and responding to risks.


This is one of the clearest areas where the Green Book is more specifically tailored to government programs than the general COSO framework.


Information Security Is Now an Explicit Green Book Priority

Cybersecurity and information security have become central internal control concerns.

Government entities depend on technology to administer:

  • Payroll

  • Grants

  • Student records

  • Public benefits

  • Tax collections

  • Procurement

  • Financial reporting

  • Public safety

  • Infrastructure


The 2025 Green Book expressly strengthens the treatment of information-security risks.


This means government management should integrate information security into the complete internal control system rather than treating it as a separate IT issue.


Questions should include:

  • Which information supports critical programs?

  • Who can access it?

  • How is it protected?

  • Are system-generated reports reliable?

  • How are technology changes controlled?

  • Can operations continue after a cyberattack?

  • Are vendors adequately monitored?

  • How does management know security controls are operating?


COSO can support the same analysis, but the updated Green Book makes the government requirement unmistakable.


How Each Framework Defines an Effective System

Under both frameworks, all five components must be:

  • Designed

  • Implemented

  • Operating

  • Working together in an integrated manner


An organization cannot claim an effective system merely because it has policies covering all seventeen principles.


Effectiveness requires operation.


For example, an entity may have:

  • An ethics policy

  • A risk-assessment template

  • Approval procedures

  • A communication policy

  • An internal audit function


The system may still be ineffective when:

  • Leadership overrides policy

  • Risk assessments are copied forward

  • Approvals are undocumented

  • Significant issues are not communicated

  • Audit findings remain unresolved


The components must function together.


Neither Framework Makes Internal Audit Responsible for Internal Control

A persistent governance mistake is assigning ownership of the internal control system to Internal Audit.


That is wrong under both COSO and the Green Book.


Management is responsible for:

  • Establishing objectives

  • Identifying risks

  • Designing controls

  • Operating controls

  • Monitoring performance

  • Correcting deficiencies


Internal Audit is responsible for providing independent assurance.


Internal Audit may:

  • Facilitate risk discussions

  • Advise on framework implementation

  • Evaluate control design

  • Test operating effectiveness

  • Report deficiencies

  • Monitor remediation


Internal Audit should not:

  • Own business controls

  • Approve management transactions

  • Accept risks

  • Implement corrective actions

  • Certify management’s system on management’s behalf


The 2025 Green Book reinforces management responsibility at all organizational levels.


Which Framework Should a Private Company Use?

For most private-sector organizations, COSO is the natural choice.


It offers:

  • Broad applicability

  • Recognition by auditors and regulators

  • Alignment with financial reporting

  • Flexibility across industries

  • Extensive implementation guidance

  • Compatibility with enterprise risk management


A private company may still consult the Green Book when it:

  • Receives federal funds

  • Administers government programs

  • Contracts extensively with government

  • Wants more prescriptive documentation

  • Needs stronger guidance on improper payments

  • Operates in a highly accountable public-service environment


The Green Book can supplement COSO even when it is not mandatory.


Which Framework Should a Government Entity Use?

Federal executive branch agencies must use the Green Book.


State, local, and quasi-governmental organizations should carefully evaluate whether:

  • State law requires it

  • Grant agreements require it

  • The governing board adopted it

  • The external auditor uses it as criteria

  • The organization administers federal programs

  • The entity wants a framework designed for public accountability


For many government entities, the Green Book is the stronger primary framework because it speaks directly to:

  • Government missions

  • Public funds

  • Improper payments

  • Fraud

  • Compliance

  • Program operations

  • Documentation

  • Oversight


COSO remains relevant because the Green Book is harmonized with it.


Using the Green Book does not mean rejecting COSO.


It means applying COSO’s architecture through government-specific standards.


Which Framework Should a School District Use?

School districts occupy a particularly important position.


They manage:

  • State funding

  • Federal grants

  • Student activity funds

  • Payroll

  • Procurement

  • Transportation

  • Food programs

  • Construction

  • Technology

  • Student information

  • Special education funding


A school district could use COSO effectively.


However, the Green Book often offers the stronger fit because school districts are public entities responsible for public funds and extensive legal compliance.


The 2025 Green Book’s greater attention to:

  • Fraud

  • Improper payments

  • Information security

  • Preventive controls

  • Change assessment

  • Documentation

is directly relevant to the risks faced by school districts.


For example, a district implementing a new payroll or student-information system should document:

  • What changed

  • What new risks were identified

  • How those risks were analyzed

  • Which controls were redesigned

  • How management confirmed the controls operated


That is not simply good audit practice.


It is responsible public governance.


Can an Organization Use Both?

Yes.


In many cases, the most practical approach is:

  • Use COSO as the broad conceptual framework.

  • Use the Green Book for government-specific requirements and application.

  • Use industry guidance for specialized risks.

  • Use audit standards to evaluate the system.


A public authority might map:

  • COSO components

  • COSO principles

  • Green Book principles and attributes

  • State requirements

  • Organizational policies

  • Key controls

  • Evidence

  • Control owners

  • Testing results


This produces one integrated control system rather than competing compliance programs.


Because the structures are harmonized, organizations should avoid maintaining separate “COSO controls” and “Green Book controls” unless a genuine requirement differs.


A Practical Comparison

Area

COSO Internal Control Framework

GAO Green Book

Primary users

Private companies, public companies, nonprofits and other organizations

Federal agencies; also usable by state, local, quasi-governmental and nonprofit entities

Current core version

2013 Internal Control—Integrated Framework

2025 Standards for Internal Control in the Federal Government

Effective date

Framework refreshed in 2013

Effective beginning fiscal year 2026

Authority

Voluntary framework unless required by regulation, governance or contractual criteria

Required for federal executive branch agencies under federal authority

Components

Five

Five

Principles

Seventeen

Seventeen

Detailed guidance

Points of focus and implementation guidance

Attributes, including application guidance and some minimum documentation requirements

Objectives

Operations, reporting and compliance

Operations, reporting and compliance

Main orientation

Broad organizational and business application

Government missions, public funds and accountability

Fraud

Required consideration

Required consideration, with enhanced government-focused guidance

Improper payments

May be addressed as part of risk assessment

Explicitly emphasized in the 2025 revision

Information security

Addressed through risk and control structure and supplemental guidance

Explicitly emphasized in the 2025 revision

Change assessment

Required through the principle addressing significant change

Explicit documentation of a change-assessment process emphasized in 2025

Preventive controls

Selected based on risk

Greater emphasis on prioritizing preventive control activities

Documentation

Flexible and scalable

More explicit through attributes and 2025 documentation requirements

The table reflects the current COSO framework and the 2025 Green Book.


Common Implementation Mistakes Under Either Framework


Treating the Framework as a Checklist

The objective is an effective system—not seventeen completed boxes.


Documenting Controls That Do Not Operate

A control narrative does not prove performance.


Assigning the Program to Finance Alone

Internal control belongs to every manager.


Ignoring Information Technology

Business and financial controls increasingly depend on systems, reports, access, and interfaces.


Failing to Reassess After Change

Acquisitions, new systems, reorganizations, emergencies, and new programs create new risks.


Confusing Internal Audit with Management

Internal Audit evaluates the control system. It does not own it.


Correcting Exceptions Without Addressing Root Cause

A late reconciliation may signal weak staffing, ownership, supervision, or system design.


Allowing Findings to Remain Open Indefinitely

An uncorrected deficiency is an accepted exposure, whether management admits it or not.


Questions Governing Boards and Audit Committees Should Ask

  1. Which framework has the organization formally adopted?

  2. Why is that framework appropriate?

  3. Have all five components been designed and implemented?

  4. Are the seventeen principles operating in practice?

  5. Who owns the internal control system?

  6. How are risks documented?

  7. How does management assess significant change?

  8. How are fraud and improper-payment risks addressed?

  9. How are cybersecurity and information-security risks integrated?

  10. What evidence demonstrates that controls operate?

  11. Which deficiencies remain unresolved?

  12. Does Internal Audit independently evaluate the system?

  13. Does the governing body receive meaningful internal control reporting?

  14. Would the organization’s documentation withstand an external audit or regulatory review?

A board should be concerned when management’s answer is:

“Internal Audit handles COSO.”

That response indicates that the organization does not understand control ownership.


The Bottom Line

COSO and the Green Book should not be treated as rival frameworks.


They share the same basic internal control structure.


The difference lies in application and authority.


COSO is the broad, widely recognized internal control framework used across industries and organizational types.


The Green Book applies that architecture to federal government operations and strengthens it with public-sector standards, attributes, documentation expectations, and specific attention to fraud, improper payments, information security, preventive controls, and significant organizational change.


For private-sector organizations, COSO will usually remain the primary framework.


For federal agencies, the Green Book is mandatory.


For state and local governments, school districts, public authorities, and nonprofit organizations administering public funds, the Green Book frequently provides the more appropriate standard—even when its use is voluntary.


The choice of framework matters.


What matters more is whether management actually operates the system.


A beautifully documented framework cannot compensate for:

  • Weak leadership

  • Unassessed risk

  • Unperformed controls

  • Unreliable information

  • Unresolved findings


Internal control is not the framework sitting on a shelf.


It is what management and employees do every day to help the organization achieve its objectives, protect its resources, produce reliable information, and comply with its obligations.

 
 
 

Recent Posts

See All
How Arizona CPAs Actually Get in Trouble

Lessons From the Arizona State Board of Accountancy Most CPAs do not begin their careers expecting to face professional discipline. They pass the CPA examination. They satisfy experience requirements.

 
 
 

Comments


Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page