CC1 Security Required

Control Environment

Complete guide to CC1 Control Environment controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.

5 Controls
0 Critical
0 High
CC1.1 medium

COSO Principles and Commitment to Integrity

Your company has a documented Code of Conduct, ethics policy, and clear expectations for employee behavior. This applies to executives and all employees.

View official AICPA language

The entity demonstrates a commitment to integrity and ethical values.

What auditors look for

Code of Conduct document, employee onboarding acknowledgement records, ethics training completion records

CC1.2 medium

Board Independence and Oversight

Your board (or equivalent governance body) actively oversees your security and compliance program, not just financial performance. Board meeting minutes should show security was discussed.

View official AICPA language

The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.

What auditors look for

Board meeting minutes referencing security/compliance, risk committee charter, board composition documentation

CC1.3 low

Organizational Structure and Accountability

Your org chart, reporting lines, and who is responsible for security are clearly documented. The security team or security owner has explicit authority.

View official AICPA language

Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.

What auditors look for

Org chart, job descriptions for security roles, RACI matrix for security responsibilities

CC1.4 low

Commitment to Competence

You hire qualified security personnel, provide security training, and have a process to assess whether employees have the skills needed for their security-related roles.

View official AICPA language

The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.

What auditors look for

Security training completion records, job descriptions requiring security qualifications, performance review templates

CC1.5 medium

Accountability for Internal Control

Employees know they are responsible for following security policies. Violations have consequences. Security responsibilities appear in performance reviews.

View official AICPA language

The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.

What auditors look for

Disciplinary policy, security responsibilities in performance review templates, acknowledgement of security policies

Track all 5 controls in your free checklist

Assign owners, collect evidence, and get your readiness score — no credit card required.

Start Free Today