Risk registers describe what could go wrong. Controls are what you actually do about it. A risk without a control is a worry; a control without a risk is overhead. The discipline that connects the two - consistently, across an entire organisation - is the control framework.
In short
An internal control is any process, check, approval or system setting that reduces the likelihood or impact of a risk. A control framework is the structured set of controls - and the principles behind them - that lets you manage risk the same way everywhere.
- Types - preventive (stop it), detective (catch it), corrective (fix it); manual vs automated; key vs non-key.
- Effectiveness - a control must pass two tests: design effectiveness and operating effectiveness.
- Good controls - specific, owned, risk-linked, evidenced, proportionate and testable.
- Frameworks - COSO, COBIT, ISO 27001, NIST give you a shared taxonomy so controls are defined and tested consistently.
What Is an Internal Control?
An internal control is a deliberate action, rule or mechanism that an organisation uses to keep a risk within appetite. Controls take many forms - a segregation of duties, a system that blocks an action, a reconciliation, an approval workflow, a policy, a training requirement, a monitoring report. What they share is intent: each one exists to change the likelihood or the impact of a specific risk.
This is why controls sit at the heart of every risk methodology. In the language of inherent, residual and appetite, controls are precisely what moves a risk from its inherent (uncontrolled) position to its residual (controlled) position. Assess the controls and you can defend the residual number; ignore them and the register is just opinion.
What Is a Control Framework?
A control framework is a structured, principle-based system for organising controls so they are defined, owned and tested consistently across the organisation. Rather than every team inventing its own controls in its own words, a framework provides a shared taxonomy: standard control categories, standard language for design and effectiveness, and a standard way to evidence that a control works.
Most organisations adopt or map to one or more established frameworks rather than starting from scratch. The best-known are:
| Framework | Primary focus | Typically used for |
|---|---|---|
| COSO Internal Control | Financial and enterprise controls | SOX, UK Provision 29, board assurance |
| COBIT | IT governance and management | Technology and data controls |
| ISO 27001 (Annex A) | Information security | InfoSec certification, customer assurance |
| NIST CSF / SP 800-53 | Cybersecurity | US federal, security programmes |
| PCI DSS | Payment card security | Anyone handling card data |
You do not need to boil the ocean. A mid-sized regulated firm might anchor its financial controls to COSO, its security controls to ISO 27001, and stop there. The point of a framework is not the badge - it is the discipline of a consistent, defensible control library.

