Control Environment
Complete guide to CC1 Control Environment controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.
COSO Principles and Commitment to Integrity
Plain English
Your company has a documented Code of Conduct, ethics policy, and clear expectations for employee behavior. This applies to executives and all employees.
View official AICPA language
The entity demonstrates a commitment to integrity and ethical values.
What auditors look for
Code of Conduct document, employee onboarding acknowledgement records, ethics training completion records
Board Independence and Oversight
Plain English
Your board (or equivalent governance body) actively oversees your security and compliance program, not just financial performance. Board meeting minutes should show security was discussed.
View official AICPA language
The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
What auditors look for
Board meeting minutes referencing security/compliance, risk committee charter, board composition documentation
Organizational Structure and Accountability
Plain English
Your org chart, reporting lines, and who is responsible for security are clearly documented. The security team or security owner has explicit authority.
View official AICPA language
Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
What auditors look for
Org chart, job descriptions for security roles, RACI matrix for security responsibilities
Commitment to Competence
Plain English
You hire qualified security personnel, provide security training, and have a process to assess whether employees have the skills needed for their security-related roles.
View official AICPA language
The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
What auditors look for
Security training completion records, job descriptions requiring security qualifications, performance review templates
Accountability for Internal Control
Plain English
Employees know they are responsible for following security policies. Violations have consequences. Security responsibilities appear in performance reviews.
View official AICPA language
The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.
What auditors look for
Disciplinary policy, security responsibilities in performance review templates, acknowledgement of security policies
Track all 5 controls in your free checklist
Assign owners, collect evidence, and get your readiness score — no credit card required.
Start Free Today