Skip to main content
Category: Internal Controls

Monitoring Activities

Also known as: Monitoring, Ongoing and Separate Evaluations
Simply put

Monitoring activities are the ways an organization checks over time whether its internal controls are actually working as intended. Rather than assuming controls remain effective, the organization periodically collects and reviews information to confirm that controls are present and functioning, and to identify and address any weaknesses. This is generally treated as one of the components of an effective internal control system.

Formal definition

Monitoring activities comprise the ongoing evaluations, separate evaluations, or a combination of both used to assess whether each component of internal control is present and functioning over time. In internal control frameworks, monitoring is the process of periodically collecting, analyzing, and using information to determine whether internal control is adequately designed and operating effectively, and to communicate deficiencies to parties responsible for corrective action. Ownership typically differs by role: management is generally accountable for designing and performing monitoring embedded in operations, while assurance functions (such as internal audit) may provide independent, separate evaluations, and the board and its committees exercise oversight. Monitoring activities inform, but are distinct from, the evaluation of control design versus operating effectiveness, and the specific requirements and terminology vary by the framework adopted, jurisdiction, sector, and entity type. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Internal controls are not static. A control that operates effectively when it is first designed can degrade over time as processes change, personnel turn over, systems are updated, or business conditions shift. Monitoring activities exist because an organization cannot simply assume its controls remain effective; it must periodically collect and review information to confirm that controls are present and functioning, and to surface weaknesses before they result in errors, losses, or compliance failures. Under most internal control frameworks, monitoring is treated as one of the components of an effective internal control system rather than an optional add-on.

Monitoring also connects the internal control system to accountability. When deficiencies are identified, they need to be communicated to the parties responsible for corrective action, which creates a feedback loop that keeps the control environment current. Without monitoring, deficiencies can persist undetected, and the board and management may operate with false assurance that controls are working when they are not.

Because the specific requirements and terminology vary by the framework adopted, the jurisdiction, the sector, and the type of entity, organizations should be careful not to treat any single approach to monitoring as universally mandatory. This entry is educational and not legal, audit, or compliance advice.

Who it's relevant to

Management
Management is generally accountable for designing and performing the monitoring embedded in day-to-day operations. This includes establishing ongoing evaluations that provide timely information on whether controls are present and functioning, and ensuring that identified deficiencies are routed to the parties responsible for corrective action.
Internal Audit and Assurance Functions
Assurance functions such as internal audit may provide independent, separate evaluations of whether internal control is adequately designed and operating effectively. These periodic, independent assessments complement the ongoing monitoring performed within operations and help provide objective information about control performance over time.
The Board and Its Committees
The board and its committees exercise oversight of the internal control system, including whether monitoring is taking place and whether deficiencies are being addressed. Their role is generally one of oversight rather than performing monitoring activities directly, and they rely on information from management and assurance functions to inform that oversight.
Compliance and Risk Officers
Compliance and risk professionals have an interest in monitoring because it provides the information needed to determine whether controls remain effective as conditions change. The specific requirements and terminology that apply to any given organization depend on the framework adopted, the jurisdiction, the sector, and the entity type, so these professionals should apply their own judgment rather than assuming a single standard approach applies.

Inside Monitoring Activities

Ongoing Evaluations
Monitoring activities built into routine business processes that provide near real-time information about whether internal control is functioning as intended. Under the COSO Internal Control-Integrated Framework, these are typically embedded in normal operations rather than performed as separate exercises, and are generally the responsibility of operational management (the first line).
Separate Evaluations
Periodic, standalone assessments conducted independently of day-to-day operations, often by internal audit or other assurance functions. Their scope, frequency, and rigor generally vary with the assessed level of risk, the results of ongoing evaluations, and management's judgment. These typically provide a fresh, more objective perspective.
Evaluation and Communication of Deficiencies
The process of assessing identified control deficiencies for severity and communicating them to parties positioned to take corrective action, including senior management and the board or its relevant committee where warranted. This component focuses on timely reporting and follow-up rather than the detection step itself.
Baseline of Expected Performance
An understanding of how controls should operate, against which ongoing and separate evaluations are compared. Monitoring generally depends on a defined baseline so that deviations can be recognized; without it, evaluators may lack a reference point for identifying breakdowns.
Distinction Between Design and Operating Effectiveness
Monitoring generally considers both whether a control is designed appropriately to address a risk and whether it is operating as designed over time. These are separate questions, and a control that is well-designed may still fail in operation, or vice versa.
Role Allocation Across the Lines
Monitoring responsibilities are typically distributed: operational management performs and oversees ongoing evaluations (first line); risk and compliance functions may monitor within their mandates (second line); internal audit provides independent assurance (third line); and the board oversees the overall system without performing operational monitoring itself.

Common questions

Answers to the questions practitioners most commonly ask about Monitoring Activities.

Is monitoring activities the same thing as internal audit?
No. Under frameworks such as COSO's Internal Control-Integrated Framework, monitoring activities is a broad component of internal control that includes both ongoing monitoring built into routine operations and separate evaluations. Internal audit is one source of separate evaluations, but it is not the whole of monitoring. Management typically performs ongoing monitoring as part of its day-to-day operational responsibilities, while internal audit provides independent assurance over the system of internal control. Treating the two as identical conflates a management-owned control component with an assurance function that reports, in many organizations, to the audit committee. The distinction matters for accountability: management owns and operates monitoring, whereas internal audit evaluates it.
Does monitoring confirm that controls are effective on its own?
Not by itself. Monitoring is a process for evaluating whether controls are present and functioning over time and for identifying and communicating deficiencies; it supports a conclusion about effectiveness but does not substitute for the underlying assessment. It is also useful to keep control design and operating effectiveness distinct: a control can be well designed yet fail to operate as intended, and monitoring may surface either type of issue. Whether a given monitoring result is sufficient to conclude that a control is effective depends on the scope, nature, and rigor of the monitoring performed, and ultimately involves professional judgment. Monitoring flags where attention is needed rather than guaranteeing an outcome.
How should an organization decide between ongoing monitoring and separate evaluations?
Under COSO, the two are generally complementary rather than mutually exclusive. Ongoing monitoring is built into normal business processes and tends to provide timely feedback, while separate evaluations are conducted periodically and can offer a more objective, in-depth look. Many organizations calibrate the balance based on the pace of change in the process, the level of risk involved, and the results of prior monitoring: the more effective and mature the ongoing monitoring, the less extensive separate evaluations may need to be. The appropriate mix depends on the entity's specific facts, risk profile, and resources, and reflects management's judgment.
Who is responsible for acting on deficiencies identified through monitoring?
Accountability generally sits with management to evaluate identified deficiencies, determine appropriate corrective action, and remediate on a timely basis. Depending on severity, deficiencies may also need to be communicated upward, and in many governance structures significant matters are reported to the board or its audit committee for oversight. The board's role is typically oversight of the remediation process rather than performing the operational fixes itself. Assurance functions may track and report on remediation status, but responsibility for the response rests with the accountable management owners. How escalation thresholds are set depends on the organization's own policies and applicable requirements.
How can an organization judge whether its monitoring activities are adequate?
Common considerations include whether monitoring covers the risks and controls that matter most, whether it is timely enough to catch issues before they cause harm, whether those performing it have sufficient knowledge and objectivity, and whether results are actually communicated to parties who can act. Organizations often also weigh the balance of ongoing monitoring and separate evaluations and whether prior deficiencies have been addressed. There is no single universal standard; adequacy is a judgment that depends on the entity's risks, structure, sector, and any applicable requirements. This is a matter for professional assessment rather than a fixed checklist.
How do monitoring activities relate to management's assertions about internal control over financial reporting?
In jurisdictions and regimes that require management to assess internal control over financial reporting, monitoring activities generally provide part of the evidence supporting that assessment by evaluating whether relevant controls operate as intended over the period. However, the specific obligations, scope, and documentation expectations vary by jurisdiction, entity type, and the applicable regulatory regime, and monitoring is one component supporting such assertions rather than the entire basis for them. Whether and how these requirements apply to a particular organization depends on its circumstances, and this entry is educational rather than legal, audit, or compliance advice.

Common misconceptions

Monitoring activities are the same as internal audit.
Internal audit is one contributor to monitoring, typically performing separate, independent evaluations as part of the third line. Monitoring is broader and includes ongoing evaluations embedded in operations that are generally owned by management. Treating the two as identical conflates an independent assurance function with the wider set of monitoring responsibilities distributed across the lines.
The board is responsible for carrying out monitoring activities.
In many governance models, the board and its committees oversee the adequacy of the monitoring system and receive reporting on deficiencies, but they do not typically perform operational monitoring. Executing ongoing and separate evaluations generally sits with management and assurance functions; the board's role is oversight, not operational execution.
Monitoring only detects control failures after they occur.
While some monitoring is detective, ongoing evaluations are generally designed to surface deviations from expected performance on a continuous basis, which can enable timely correction. The component also encompasses evaluating and communicating deficiencies so that action can be taken, rather than merely recording past failures.

Best practices

Clarify who owns each monitoring activity by mapping ongoing and separate evaluations to the appropriate line, so that management execution, second-line oversight, and independent assurance are not confused or duplicated.
Establish and maintain a documented baseline of expected control performance, so that evaluators have a clear reference point for identifying deviations in both design and operation.
Calibrate the frequency and rigor of separate evaluations to assessed risk levels and to the results of ongoing evaluations, rather than applying a uniform schedule to all controls.
Assess identified control deficiencies for severity and route them promptly to parties able to take corrective action, including escalation to senior management and the board or relevant committee where warranted.
Distinguish clearly between control design and operating effectiveness when evaluating results, and document findings for each so that a well-designed but failing control is not overlooked.
Provide the board or its oversight committee with periodic reporting on the state of monitoring and unresolved deficiencies, recognizing that entry-level guidance here is educational and that specific obligations vary by jurisdiction, sector, entity type, and applicable framework, and may warrant professional advice.