Skip to main content
Category: Enterprise Risk Management

Information, Communication, and Reporting

Also known as: Information and Communication
Simply put

Information, communication, and reporting refers to how an organization obtains or generates relevant, quality information and shares it internally and externally so that people can carry out their responsibilities and support the functioning of internal control. It covers the flow of information up, down, and across the organization, as well as reporting to and from external parties such as regulators and stakeholders. This entry is educational and not legal, audit, or compliance advice.

Formal definition

Information, communication, and reporting is generally treated as a component of an internal control framework concerned with identifying, capturing, and communicating relevant, quality information in a form and timeframe that enables personnel and stakeholders to fulfill their responsibilities and to support the other components of internal control. It encompasses internal communication of objectives, roles, and control-related information across the organization, as well as external communication and reporting with parties such as regulators, owners, and other stakeholders. Assurance functions typically assess and validate the key controls over these information and communication processes, for example through an audit work program, while accountability for the design and operation of the underlying processes rests with management. The precise treatment of this concept depends on the framework applied and the entity's jurisdiction, sector, and circumstances, and it should be distinguished from information and communications technology (ICT), which refers to the tools and platforms that facilitate information exchange rather than the control component itself.

Why it matters

Information, communication, and reporting is typically treated as a component of an internal control framework because internal control cannot function without relevant, quality information reaching the people who need it in a usable form and timeframe. When objectives, roles, and control-related information do not flow reliably up, down, and across an organization, personnel may be unable to carry out their responsibilities, and weaknesses in one control component can go undetected. Effective communication is generally what connects the other components of internal control into a coherent whole.

The reporting dimension extends this concern outward. Organizations generally must communicate with external parties such as regulators, owners, and other stakeholders, and the approaches used to report should be tailored to meet the requirements of those key stakeholders. Deficiencies in the quality, timeliness, or accuracy of information shared externally can undermine stakeholder confidence and, in many jurisdictions, may carry regulatory consequences, though the specific requirements depend on the entity's jurisdiction, sector, and circumstances.

It is important to distinguish this control component from information and communications technology (ICT). ICT refers to the tools, applications, networks, and platforms that facilitate the exchange of information, whereas information, communication, and reporting as a control component concerns whether relevant, quality information is identified, captured, and communicated to support internal control. Technology can enable the process, but the presence of sophisticated ICT does not by itself establish that the control component is functioning as intended.

Who it's relevant to

Management
Management typically holds accountability for designing and operating the processes that identify, capture, and communicate relevant, quality information across the organization, as well as for external reporting to regulators, owners, and other stakeholders. This is an operational responsibility rather than an oversight one.
Internal Audit and Assurance Functions
Assurance functions generally assess and validate the key controls over information and communication processes, for example, through an audit work program that reviews these controls at a high level, rather than owning or operating the processes themselves. Their role is to provide independent evaluation, not to run the underlying flows of information.
The Board and Its Committees
The board and committees such as the audit committee generally rely on information generated through this component to exercise their oversight responsibilities. The quality, timeliness, and accuracy of the information they receive directly affects their ability to oversee internal control, though the board's role is oversight rather than operation.
Compliance and Risk Functions
Compliance and risk professionals typically depend on relevant, quality information reaching the right people to carry out their responsibilities and to support the functioning of internal control, including external communication and reporting with regulators. The specific reporting requirements vary by jurisdiction, sector, and entity type.
External Stakeholders and Regulators
Regulators, owners, and other stakeholders are recipients of external reporting, and reporting approaches are generally tailored to meet their requirements. What must be reported, and in what form and timeframe, depends on applicable law and the entity's circumstances; this entry is educational and not legal, audit, or compliance advice.

Inside Information, Communication, and Reporting

Information Requirements
The identification and generation of relevant, quality information needed to support the functioning of governance, risk, and control activities. Under frameworks such as COSO, information should be timely, accurate, complete, and accessible to those who need it, though the specific requirements depend on the entity's objectives, size, and complexity.
Internal Communication
The flow of information across, up, and down the organization, including how management conveys objectives, responsibilities, and risk-related information to personnel and how information flows back to management and, where appropriate, the board. This typically includes channels for reporting concerns, such as whistleblower mechanisms, though the design varies by jurisdiction and entity type.
External Communication
The exchange of relevant information with external parties such as regulators, shareholders, auditors, customers, and other stakeholders. Certain external disclosures are legally mandated (for example, periodic financial reporting under applicable securities laws and listing rules), while others are voluntary and depend on the framework or jurisdiction.
Reporting Lines and Escalation
The defined pathways through which risk, control, and compliance information reaches management, board committees, and the board. These lines generally distinguish operational reporting owned by management from assurance reporting provided by functions such as internal audit, and they support the board's oversight role rather than substituting for it.
Reporting to the Board and Committees
The provision of information that enables the board and its committees (such as audit or risk committees) to exercise oversight. The board typically relies on reporting from management and assurance functions; the adequacy of such reporting is a matter of the board's judgment and is not itself an operational control.
Information Quality and Systems
The processes, controls, and technology used to capture, process, and maintain data integrity so that reported information is reliable. This encompasses both the design of information systems and their operating effectiveness, which are distinct considerations when evaluating whether reporting can be relied upon.

Common questions

Answers to the questions practitioners most commonly ask about Information, Communication, and Reporting.

Is information and communication the same thing as the board's reporting obligations to regulators?
No. Information, communication, and reporting as a governance concept refers broadly to the internal and external flows of relevant, timely, and reliable information that support decision-making, oversight, and accountability across an entity. Regulatory reporting to authorities is one external output within that broader concept, but it is not the whole of it. Internal communication among management, assurance functions, committees, and the board, as well as communication with other stakeholders, all fall within the concept. Treating it solely as regulatory filing understates its role. This entry is educational and not legal, audit, or compliance advice; specific reporting obligations vary by jurisdiction, sector, and entity type.
Does more information automatically mean better governance and stronger oversight?
Not necessarily. The objective is relevant, reliable, and appropriately timed information rather than volume. Under frameworks such as COSO's internal control model, the quality attributes of information generally matter more than quantity; excessive or poorly filtered reporting can obscure the signals a board or committee needs and can dilute accountability. Effective communication typically involves tailoring the level of detail to the audience and the decision at hand. What constitutes sufficient and appropriate information depends on facts, the entity's circumstances, and professional judgment.
Who is accountable for the quality of information that reaches the board?
Accountability is generally shared but distinct by role. Management typically owns the design and operation of processes that generate, aggregate, and communicate information, and is responsible for its accuracy and completeness. The board and its committees are generally responsible for oversight, including setting expectations for the information they require and challenging what they receive. Assurance functions, such as internal audit under the third line, may provide independent assurance over the reliability of certain information but do not own the underlying processes. The precise allocation depends on the entity's governance structure and applicable requirements.
How can a board assess whether the information it receives is fit for purpose?
Boards often evaluate information against attributes such as relevance to the decisions and risks in scope, reliability of the source and process, timeliness, and clarity of presentation. Practical steps may include agreeing on standing reporting formats, requesting management to identify assumptions and data limitations, and periodically reviewing whether the reporting suite still aligns with the entity's risk profile and strategy. Some boards ask assurance functions to comment on the robustness of key information flows. The appropriate approach depends on the entity's context and remains a matter of judgment; this is not prescriptive guidance.
How should information flow between the three lines and the board on risk and compliance matters?
Under the widely referenced three lines model, information generally flows from operational management (first line), through risk and compliance functions (second line), and independent assurance such as internal audit (third line), each providing a different perspective to the board and its relevant committees. In many entities, the audit committee, risk committee, or a combined body receives this reporting. The model is a framework rather than a universal mandate, and entities adapt reporting lines to their size, sector, and structure. Clear escalation protocols and defined roles help avoid gaps or duplication, but the specific design varies.
What practical measures support reliable external communication and reporting?
Common measures include defined ownership for each external report, review and approval controls proportionate to the information's significance, reconciliation between externally reported information and underlying records, and consistency between different disclosures. Where financial reporting is involved, controls over the reliability of that reporting are emphasized in certain regimes, though the specific requirements vary by jurisdiction and entity type. Entities also often align the timing and content of external communications to avoid selective or inconsistent disclosure. These are illustrative practices, not legal requirements, and appropriate controls depend on applicable law and professional judgment.

Common misconceptions

More reporting always means better governance and oversight.
Volume of information does not equate to quality or usefulness. Frameworks generally emphasize relevant, timely, and appropriately summarized information; excessive or poorly targeted reporting can obscure the matters the board and management most need to see. What is 'sufficient' is a matter of judgment and depends on the entity's objectives and risk profile.
Communication and reporting are the responsibility of a single function, such as compliance or internal audit.
Information, communication, and reporting cut across multiple parties. Management typically owns operational information flows and internal communication, assurance functions such as internal audit provide independent reporting, and the board and its committees are recipients exercising oversight. Conflating these roles obscures where accountability sits.
Meeting external disclosure requirements confirms that internal communication is effective.
External reporting obligations (which are legally mandated in many jurisdictions) address a different purpose than internal communication. Compliant external disclosures do not demonstrate that information flows effectively within the organization or that escalation channels operate as designed; the two require separate evaluation.

Best practices

Define clear reporting lines and escalation pathways that distinguish management's operational reporting from independent assurance reporting, so the board understands the source and objectivity of the information it receives.
Tailor information provided to the board and its committees to be relevant, timely, and appropriately summarized, focusing on the matters most significant to objectives and risk rather than maximizing volume.
Establish and periodically test communication channels for raising concerns, such as whistleblower mechanisms, consistent with applicable legal requirements in the relevant jurisdiction.
Assess both the design and the operating effectiveness of the systems and controls that produce reported information, since reliable reporting depends on both.
Distinguish external disclosure obligations (which are legally mandated in many jurisdictions and vary by sector and entity type) from internal communication practices, and evaluate each on its own terms.
Periodically review whether the information reaching management and the board remains fit for purpose as objectives, risks, and the regulatory environment change, recognizing that adequacy is ultimately a matter of professional judgment.