es
en

Internal Control and the Role of the Statutory Auditor: Reference Models and Professional Practice


The assessment of internal control is one of the central pillars of statutory auditing (revisoría fiscal) in Colombia. Article 207 of the Commercial Code requires the statutory auditor to promptly report, in writing, to the shareholders’ assembly or partners’ meeting, to the administrators, and, when applicable, to the relevant inspection, oversight, or control authority, any irregularities found in the operation of the company and the conduct of its business. This obligation is reinforced by Law 43 of 1990 and by the Information Assurance Standards adopted through Decree 2420 of 2015 and its amendments, which require the statutory auditor to obtain an adequate understanding of the entity and its internal control system as part of the planning and execution of the engagement, in accordance with the International Standards on Auditing applicable in the country.

Meeting these obligations requires a rigorous understanding of the audited organization’s internal control systems and of the methodological frameworks available for evaluating them in a technical and objective manner. Statutory auditors typically rely on several of these models at once, since each one addresses a different angle and none of them fully covers an organization’s assessment needs on its own.

COSO Model

The COSO framework is the most widely used internal control model internationally. It seeks to identify events that could affect the achievement of an organization’s objectives and to manage business risk in an integrated way, based on five components: the control environment, risk assessment, control activities, information and communication, and monitoring activities.

Applying this model leads the statutory auditor to examine how genuine management’s commitment to the integrity and ethical values it claims to promote actually is, rather than simply how well-written the code of ethics happens to be. It also involves checking whether the risk matrix is updated at the same pace as changes in the business and the regulatory environment, and evaluating whether the control activities designed for significant processes actually work in day-to-day operations, not just on paper in a manual. On top of this comes a review of the quality of the information that supports management’s decisions and of the monitoring mechanisms that allow deficiencies to be caught before they turn into audit findings.

The Enterprise Risk Management (ERM) version of COSO becomes especially relevant when it is necessary to assess management’s ability to anticipate strategic risks and not only financial or operational ones — something increasingly relevant in a business and regulatory environment as changeable as today’s.

COCO Model

The COCO model, developed by the Canadian Institute of Chartered Accountants, provides guidance for designing, evaluating, and reporting on internal control systems. Its key difference from COSO is that it does not treat internal control as a relatively fixed structure of components, but as a living process that depends on the purpose, commitment, capability, and continuous learning of the people who carry it out.

Working with this model means asking whether staff genuinely understand the purpose of each control they perform, not just whether they perform it. It also means asking whether they have the training and resources needed to do it well, and whether real feedback channels exist that allow the system to be corrected over time. It is a particularly useful model in organizations where internal control is still maturing or where there is cultural resistance to compliance, because it makes it possible to go beyond pointing out missing controls and to explain why the organization has not internalized them.

Standard Model for Internal Control (MECI)

The Standard Model for Internal Control (Modelo Estándar de Control Interno, MECI) is mandatory for Colombian public-sector entities under Law 87 of 1993 and its subsequent regulatory developments, now integrated into the Integrated Planning and Management Model (MIPG) through Decree 1499 of 2017. It is organized into subsystems, components, and control elements aimed at ensuring compliance with administrative functions and the proper management of state resources.

When a statutory audit engagement covers mixed-ownership entities, state industrial and commercial companies, or entities that manage public funds, familiarity with MECI is no longer optional. The statutory auditor must verify that the strategic control, management, and evaluation subsystems exist and are aligned with the MIPG framework applicable to the entity. The key issue is not so much confirming that the documentation exists — it usually does — but confirming that these controls actually operate in day-to-day management; the gap between what is documented and what is truly operational tends to be the greatest risk in this type of entity. The auditor must also review the role of the internal control office within the evaluation subsystem and promptly report any significant weakness to management and to the relevant oversight bodies.

COBIT Internal Control Model

COBIT, developed by ISACA, is the reference framework for auditing the management and control of information systems and technology. It takes on particular importance in light of the information security obligations set out in Law 1581 of 2012 and its implementing decrees.

Today, virtually all financial information is processed and stored in ERP systems and accounting software, so evaluating internal control only over manual processes leaves out a critical part of the risk. With COBIT, the statutory auditor reviews general IT controls (access management), segregation of duties within the systems, information security, and the change-management procedures applied to those systems. The auditor also verifies backup mechanisms and business continuity arrangements for events that could affect the technology infrastructure. When weaknesses appear in these general controls, the problem rarely stays confined to a single process: it ends up affecting the reliability of all the financial information that depends on that platform.

Control Self-Assessment (CSA) Model

The Control Self-Assessment (CSA) model, known in Spanish as Autoevaluación de Control (AEC), consists of having the people responsible for each process identify and assess their own risks and controls, typically through workshops, surveys, or interviews. Unlike the other models, it does not start from an external, independent perspective but from an internal exercise.

The statutory auditor does not replace this exercise, but does make use of it: when an organization has a mature self-assessment program, that information becomes additional evidence of how aware operational staff are of the risks in their own process, and it can be cross-checked against the auditor’s independent testing. When this exercise does not exist or is still incipient — something common in companies that are only beginning to strengthen their corporate governance — it is usually recommended as a low-cost complementary tool, without this ever replacing the independent function that belongs to the statutory auditor.

Conclusion

No single model is enough, on its own, to support the statutory auditor’s professional judgment. Each framework contributes a different piece of the analysis:

  • COSO provides the enterprise risk management structure.
  • COCO provides the perspective on organizational adaptation and learning.
  • MECI is essential whenever a public or mixed-ownership entity is involved.
  • COBIT is indispensable given the technology component that now underpins all financial information.
  • CSA provides valuable evidence of the control culture from within operations themselves.

The statutory auditor’s real skill lies in knowing how to combine these frameworks according to the type of entity, its sector, and its level of technological complexity, in order to reach an assessment that not only fulfills the legal duty to report irregularities, but also gives management concrete, prioritized recommendations. That combination of technical rigor and professional judgment is, ultimately, what distinguishes a statutory audit that merely complies with formal requirements from one that genuinely strengthens an organization’s corporate governance.


Prepared by: Fredy Alexander Pérez – Lead Audit Assistant.

THIS DOCUMENT REFLECTS THE OPINION OF OUR FIRM. TAX AUTHORITIES MAY DISAGREE WITH OUR POSITION. IF YOU WOULD LIKE TO EXPLORE THIS TOPIC FURTHER OR REQUIRE SPECIALIZED ADVICE, PLEASE DO NOT HESITATE TO CONTACT US; WE ARE HERE TO HELP.