The Five Components of Internal Control
Written by: Joe Ward
Effective internal control is essential for federal agencies to achieve their objectives, protect resources, and maintain public trust. Federal managers play a key role in this process, and compliance is not optional. Agencies are required to establish internal control systems under the Budget and Accounting Procedures Act of 1950, and the Federal Managers Financial Integrity Act of 1982 reinforced these requirements by mandating annual reporting on internal controls, in accordance with standards from the Government Accountability Office (GAO) and the Office of Management and Budget (OMB).
Internal control is organized into five components, supported by 17 principles and 47 attributes. This blog focuses on the five components while providing examples, checklists, and templates designed to help federal managers strengthen their internal control programs and achieve mission success in 2026.
1. Control Environment
The control environment sets the foundation for all internal control efforts. It includes five principles that guide agency culture and management practices:
- Setting the tone at the top
- Demonstrating a commitment to competence
- Establishing oversight and organizational structure
- Assigning responsibility
- Enforcing accountability
A strong control environment ensures that ethical behavior and effective management are prioritized across the agency.
Example: Agency leadership conducts regular ethics briefings and maintains clear reporting channels for financial and operational compliance.
Checklist for Control Environment:
- Communicate ethical standards regularly
- Maintain a clear organizational structure
- Define roles and responsibilities
- Enforce accountability measures
2. Risk Assessment
Risk assessment enables agencies to identify, analyze, and respond to potential challenges. It is guided by four principles:
- Defining objectives
- Identifying risks
- Analyzing risks
Federal managers must not only identify risks but also define acceptable risk levels, also known as risk tolerance.
Example: If an agency goal is 85 percent customer satisfaction, a 15 percent level of dissatisfaction represents the accepted risk.
Checklist for Risk Assessment:
- Identify agency objectives
- List potential operational, financial, and compliance risks
- Determine likelihood and impact of each risk
- Define risk tolerance and mitigation strategies
3. Control Activities
Control activities are the policies, procedures, and mechanisms designed to help agencies achieve objectives. These activities are guided by three principles:
- Designing control activities
- Implementing control activities
- Maintaining and documenting control activities
Example: To protect sensitive information, an agency might implement multi-factor authentication, encryption, and periodic audits of access logs.
Templates and Tools:
- Policy templates for approving financial transactions
- Procedure checklists for IT security compliance
- Audit logs for recurring monitoring
4. Information and Communication
This component emphasizes the importance of processing data into quality information and communicating it effectively to both internal and external stakeholders. It is guided by three principles:
- Ensuring information quality
- Communicating internally and externally
- Engaging stakeholders for understanding
Example: Managers may use townhall meetings, intranet posts, emails, focus groups, and surveys to provide updates and gather feedback.
Checklist for Effective Communication:
- Identify key stakeholders
- Select appropriate communication channels
- Schedule recurring updates
- Track and measure engagement
5. Monitoring
Monitoring ensures that internal control systems remain effective and deficiencies are addressed. This component follows two principles:
- Establishing baseline measures
- Conducting ongoing and periodic evaluations
Example: If an agency sets a goal to reduce processing errors by 20 percent over a year, monitoring involves baseline measurement, periodic review, and adjustments to meet the target.
Monitoring Templates:
- Quarterly performance tracking forms
- Internal audit schedules
- Corrective action tracking logs
Where to Begin
Federal managers can strengthen internal control programs in 2026 by leveraging the following resources:
- OMB Circular A-123 – Management’s Responsibility for Enterprise Risk Management and Internal Control: Provides guidance for establishing, assessing, correcting, and reporting on internal controls to improve program accountability.
- GAO – Standards for Internal Control in the Federal Government (Green Book): The most comprehensive reference on internal controls for federal agencies.
- AGA – The Internal Controls Workgroup of the Association of Government Accountants (AGA) has developed numerous resources that provide detailed information about internal control business processes, individual components developed by The Committee of Sponsoring Organizations of the Treadway Commission (COSO), principles, attributes, and best practices.
- Management Concepts: Offers numerous internal control courses, many accredited and applicable toward certification programs. Private group training is available to meet agency-specific needs.
Sign Up For Our Blog