Information, Communication, and Reporting
Information, communication, and reporting refers to how an organization obtains or generates relevant, quality information and shares it internally and externally so that people can carry out their responsibilities and support the functioning of internal control. It covers the flow of information up, down, and across the organization, as well as reporting to and from external parties such as regulators and stakeholders. This entry is educational and not legal, audit, or compliance advice.
Information, communication, and reporting is generally treated as a component of an internal control framework concerned with identifying, capturing, and communicating relevant, quality information in a form and timeframe that enables personnel and stakeholders to fulfill their responsibilities and to support the other components of internal control. It encompasses internal communication of objectives, roles, and control-related information across the organization, as well as external communication and reporting with parties such as regulators, owners, and other stakeholders. Assurance functions typically assess and validate the key controls over these information and communication processes, for example through an audit work program, while accountability for the design and operation of the underlying processes rests with management. The precise treatment of this concept depends on the framework applied and the entity's jurisdiction, sector, and circumstances, and it should be distinguished from information and communications technology (ICT), which refers to the tools and platforms that facilitate information exchange rather than the control component itself.
Why it matters
Information, communication, and reporting is typically treated as a component of an internal control framework because internal control cannot function without relevant, quality information reaching the people who need it in a usable form and timeframe. When objectives, roles, and control-related information do not flow reliably up, down, and across an organization, personnel may be unable to carry out their responsibilities, and weaknesses in one control component can go undetected. Effective communication is generally what connects the other components of internal control into a coherent whole.
The reporting dimension extends this concern outward. Organizations generally must communicate with external parties such as regulators, owners, and other stakeholders, and the approaches used to report should be tailored to meet the requirements of those key stakeholders. Deficiencies in the quality, timeliness, or accuracy of information shared externally can undermine stakeholder confidence and, in many jurisdictions, may carry regulatory consequences, though the specific requirements depend on the entity's jurisdiction, sector, and circumstances.
It is important to distinguish this control component from information and communications technology (ICT). ICT refers to the tools, applications, networks, and platforms that facilitate the exchange of information, whereas information, communication, and reporting as a control component concerns whether relevant, quality information is identified, captured, and communicated to support internal control. Technology can enable the process, but the presence of sophisticated ICT does not by itself establish that the control component is functioning as intended.
Who it's relevant to
Inside Information, Communication, and Reporting
Common questions
Answers to the questions practitioners most commonly ask about Information, Communication, and Reporting.