Framework overlap

Does ISO 13485 cover COSO Internal Control?

You hold ISO 13485 and have been told to do COSO Internal Control. Here is how much overlaps, control by control.

8% of COSO Internal Control you already have

ISO 13485 already covers about 8% of COSO Internal Control, leaving 44 of 48 controls as genuinely new work.

Already covered 0 Likely covered 4 New work 44

No control in ISO 13485 maps directly to one in COSO Internal Control. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in ISO 13485 reaches these. This is the list to scope.

CA-11
Selects and Develops General Controls over Technology
CE-1
Demonstrates Commitment to Integrity and Ethical Values
CE-2
Exercises Oversight Responsibility
CE-3
Establishes Structure, Authority, and Responsibility
CE-4
Demonstrates Commitment to Competence
CE-5
Enforces Accountability
COSO-IC-CA-10
The organization selects and develops control activities for asset safeguarding and mitigating risks to the achievement of objectives
COSO-IC-CA-11
The organization selects and develops general controls over technology
COSO-IC-CA-12
The organization deploys control activities through policies and procedures
COSO-IC-CE-01
The organization demonstrates commitment to integrity and ethical values
COSO-IC-CE-02
The board demonstrates independence from management and exercises oversight of internal control
COSO-IC-CE-03
Management establishes structures, reporting lines, authorities, and responsibilities
COSO-IC-CE-04
The organization demonstrates commitment to attract, develop, and retain competent individuals
COSO-IC-CE-05
The organization holds individuals accountable for their internal control responsibilities
COSO-IC-IC-13
The organization obtains or generates and uses relevant quality information
COSO-IC-IC-14
The organization internally communicates information including internal control objectives
COSO-IC-IC-15
The organization communicates with external parties regarding internal control matters
COSO-IC-MA-16
The organization selects and performs ongoing and/or separate evaluations
COSO-IC-MA-17
The organization evaluates and communicates internal control deficiencies in a timely manner
COSO-IC-OV-01
COSO Internal Control Framework - integrated operation of all five components (Control Environment, Risk Assessment, Control Activities, Information & Communication, Monitoring Act
IC-13
Uses Relevant Information
IC-14
Communicates Internally
IC-15
Communicates Externally
MON-16
Conducts Ongoing and/or Separate Evaluations
MON-17
Evaluates and Communicates Deficiencies
P10
Selects and Develops Control Activities
P11
Selects and Develops General Controls over Technology
P12
Deploys through Policies and Procedures
P13
Uses Relevant Information
P14
Communicates Internally
P15
Communicates Externally
P16
Conducts Ongoing and/or Separate Evaluations
P17
Evaluates and Communicates Deficiencies
P2
Exercises Oversight Responsibility
P3
Establishes Structure, Authority, and Responsibility
P4
Demonstrates Commitment to Competence
P5
Enforces Accountability
P6
Specifies Suitable Objectives
P8
Assesses Fraud Risk
P9
Identifies and Analyzes Significant Change
RA-6
Specifies Suitable Objectives
RA-7
Identifies and Analyzes Risk
RA-8
Assesses Fraud Risk
RA-9
Identifies and Analyzes Significant Change
Show the 4 you already have
CA-10
Selects and Develops Control Activities
CA-12
Deploys Through Policies and Procedures
P1
Demonstrates Commitment to Integrity and Ethical Values
P7
Identifies and Analyzes Risk

How this is calculated

Already covered means a mapping runs from a control in ISO 13485 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition