The Strategic Positioning of Internal Control and Compliance Frameworks in Corporate Governance: From Risk Prevention to Value Creation

By: QTank Published: 7/31/2026 Views: 105
Current rating: ★★★☆☆ Rate this Equivalent to 8 ratings

1. Strategic Positioning of Internal Control and Compliance Frameworks in Corporate Governance

The core issue in corporate governance is addressing the agency problem caused by the separation of ownership and management—how to ensure that management actions align with the interests of shareholders and other stakeholders. In this context, internal control and compliance frameworks play an indispensable foundational role.

The concept of internal control (Internal Control) was first systematically proposed in the 1992 publication "Internal Control—Integrated Framework" by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). It defines internal control as "a process implemented by an organization's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the areas of operational effectiveness and efficiency, financial reporting reliability, and compliance with laws and regulations." Two key points in this definition are worth delving into: first, internal control is a "process" rather than a static set of institutional documents, and it is embedded in the organization's daily operations; second, it aims to provide "reasonable assurance" rather than absolute assurance—no control system can completely eliminate risk, but it can manage risk to an acceptable level.

Compliance management (Compliance Management), on the other hand, focuses more on the consistency between organizational behavior and external rules. From the perspective of corporate governance, compliance management is not just the responsibility of the legal department but is a hierarchical organizational responsibility from the board of directors to frontline employees. The "Guidelines for Compliance Management in Central Enterprises (Trial)" issued by the State-owned Assets Supervision and Administration Commission (SASAC) of the State Council in 2018 clearly states that compliance management is "a management activity aimed at effectively preventing compliance risks, involving the formulation of systems, risk identification, compliance review, risk response, accountability, evaluation, and compliance training, among others."

In practice, internal control and compliance frameworks are often understood as two interrelated but distinct systems: internal control focuses on the "reasonableness of processes"—whether transactions are properly authorized, records are complete and accurate, and assets are protected; compliance management focuses on the "legality of actions"—whether business operations comply with laws, regulations, industry standards, and internal rules. The intersection of the two lies in "risk orientation": whether it is an internal control deficiency or a compliance deviation, both can ultimately lead to financial losses, legal sanctions, or reputational damage.

From the evolution trend of corporate governance, the positioning of internal control and compliance frameworks is undergoing changes at three levels:

First Level: Compliance Defense. Viewing internal control and compliance as a "firewall"—as long as nothing goes wrong. The typical characteristic of this stage is that institutional construction revolves around the minimum regulatory requirements, with the internal control and compliance departments operating independently, primarily using inspection, audit, and punishment as management tools.

Second Level: Risk Management. Integrating internal control and compliance into the enterprise risk management (ERM) system, emphasizing the identification, assessment, and response to risks. At this stage, internal control and compliance are no longer isolated functions but are linked with strategic decision-making and operational management.

Third Level: Value Creation. Viewing a robust internal control and compliance system as a source of competitive advantage for the enterprise. An excellent compliance record helps reduce financing costs, win customer trust, and gain regulatory convenience, ultimately translating into tangible business value. This is the advanced goal pursued by first-class corporate governance.

2. Integration Path of COSO Framework and Corporate Governance

2.1 Five Elements of COSO Internal Control and Their Governance Implications

The 2013 updated version of "Internal Control—Integrated Framework" by COSO proposed five core elements of internal control, each of which has a profound correspondence with corporate governance:

Control Environment (Control Environment)—This is the foundation of internal control, determining the organization's attitude and emphasis on internal control. At the corporate governance level, the control environment is directly reflected in the board's oversight function, management's business philosophy and style, the rationality of organizational structure, human resource policies and practices, and the promotion of integrity and ethical values. A typical negative example is the Enron scandal—on the surface, it had a comprehensive internal control system, but the moral failure of senior management rendered the entire control environment ineffective.

Risk Assessment (Risk Assessment)—The organization must identify and analyze various risks in achieving its goals and determine risk response strategies. In corporate governance, the starting point of risk assessment is the clear definition of strategic objectives—only by clarifying "where to go" can one judge "what risks may be encountered on the way." Risk assessment should cover four major categories: financial risk, operational risk, compliance risk, and strategic risk.

Control Activities (Control Activities)—Policies and procedures to ensure that management directives are executed. Control activities span all levels and functions of the organization, including authorization and approval, separation of duties, asset protection, performance evaluation, and information processing controls. At the corporate governance level, the most critical design principle for control activities is "separation of incompatible duties"—the three functions of decision-making, execution, and supervision must be carried out by different entities, which is a basic institutional arrangement to prevent abuse of power.

Information and Communication (Information & Communication)—The organization should identify, obtain, and communicate information related to internal control, enabling employees to fulfill their responsibilities. For corporate governance, the upward flow of information (from frontline to management to the board) and the downward flow of information (from strategic direction to operational instructions) are equally important. An effective whistleblowing mechanism is a concentrated manifestation of the information and communication element in corporate governance.

Monitoring Activities (Monitoring Activities)—Continuous and specific assessments of the effectiveness of the internal control system. Monitoring activities at the corporate governance level include: the board's review of management's internal control reports, independent evaluations by internal audit, internal control assurance by external auditors, and feedback from regulatory authorities.

2.2 From COSO to ISO 37301: A New Paradigm for Compliance Management Systems

In 2021, the International Organization for Standardization (ISO) released ISO 37301:2021 "Compliance Management Systems—Requirements and Guidance for Use," the first certifiable management system standard in the compliance management field, marking the transition of compliance management from "best practices" to "standardized systems."

ISO 37301 adopts the same High-Level Structure (HLS) as ISO 9001:2015, meaning that organizations can integrate quality management, environmental management, and compliance management within the same management framework. Its core elements include:

Governance Structure and Leadership—The highest governance body (board of directors) and the highest management should demonstrate their commitment to compliance management, establish independent compliance management functions, and provide adequate resources for compliance management.

Compliance Policy and Objectives—The organization should formulate a compliance policy consistent with its strategic direction and set compliance objectives at relevant functions and levels.

Compliance Risk Identification and Assessment—Establish a systematic mechanism for identifying compliance risks, covering sources such as changes in laws and regulations, changes in business models, regulatory dynamics, and whistleblowing leads.

Compliance Controls and Procedures—Embed compliance requirements into business processes, including compliance reviews, due diligence, third-party management, and conflict of interest management.

Compliance Training and Communication—Develop differentiated training plans based on risk levels to ensure that employees at all levels understand their compliance obligations related to their positions.

Compliance Monitoring, Auditing, and Reporting—Establish compliance monitoring indicators, conduct regular compliance audits, and report compliance performance to the governance body.

Nonconformity and Corrective Actions—Initiate root cause analysis and corrective actions upon discovering compliance deviations to prevent recurrence.

Continuous Improvement—Promote the continuous optimization of the compliance management system through management reviews and compliance performance assessments.

2.3 Application of the Three Lines of Defense Model in Corporate Governance

The Three Lines of Defense Model (Three Lines of Defense Model) is the most classic organizational design model for internal control and compliance frameworks in corporate governance.

First Line of Defense: Business Units. Each business unit and functional department is the owner of risks and the primary responsible party for control. The production department is responsible for product quality compliance, the procurement department for supplier compliance, and the sales department for market behavior compliance. The first line of defense should establish job operation norms and department-level self-inspection mechanisms.

Second Line of Defense: Risk and Compliance Functions. This includes functions such as risk management, compliance management, legal affairs, and financial control. They formulate internal control and compliance policies and standards, provide professional guidance, and monitor the effectiveness of the first line of defense. The independence of the second line of defense is crucial—compliance departments should not report to business heads but should report directly to the Chief Risk Officer or the CEO.

Third Line of Defense: Internal Audit. The internal audit is independent of management and reports to the board of directors or the audit committee, providing independent evaluations of the effectiveness of the first and second lines of defense. The findings and recommendations of the internal audit should be directly delivered to the governance body to ensure the independence and authority of oversight.

In practice, clear information sharing and work collaboration mechanisms need to be established between the three lines of defense to avoid a situation where each line operates in isolation and shirks responsibility. An effective approach is to establish a "unified risk language" and a "joint risk review" mechanism, allowing the three lines of defense to work collaboratively on the same risk map.

3. Evolution and Regulatory Practices of Internal Control and Compliance in Chinese Listed Companies

The evolution of internal control systems in Chinese listed companies has gone through three stages:

2008 Foundation: The Ministry of Finance, the China Securities Regulatory Commission (CSRC), and four other ministries jointly issued the "Basic Standards for Enterprise Internal Control" (China's version of the SOX Act), establishing the five objectives and five elements of internal control, and requiring listed companies to disclose internal control self-assessment reports. The accompanying guidelines in 2010 further covered 18 core business processes.

2018 Deepening: The State-owned Assets Supervision and Administration Commission (SASAC) of the State Council issued the "Guidelines for Compliance Management in Central Enterprises (Trial)," extending compliance management to all central enterprises. In 2019, it explicitly proposed a "triple control" goal of "strengthening internal control, preventing risks, and promoting compliance."

2022 Standardization: The SASAC issued the "Compliance Management Measures for Central Enterprises," requiring central enterprises to appoint a Chief Compliance Officer to conduct compliance reviews of major decisions and issue written opinions. This marks the entry of Chinese enterprises' compliance management into a "senior management responsibility, dedicated personnel" standardized stage.

4. Practical Methods for Building Internal Control and Compliance Frameworks

4.1 Six-Step Method for System Construction

Combining the requirements of the COSO framework and ISO 37301, enterprises can follow these six steps to build internal control and compliance frameworks:

Step One: Top-Level Design and Organizational Structure Adjustment. Establish an audit and risk committee at the board level and a Chief Risk Officer or Chief Compliance Officer position at the management level. Clarify the governance responsibilities at each level—the board is responsible for "supervision," management for "execution," business units for "implementation," and the internal audit department for "evaluation."

Step Two: System Review and Improvement. Benchmark against regulatory requirements and best practices, and conduct a comprehensive "compliance health check" of the existing system. Focus on: ① Are there any gaps in the system? ② Are existing systems consistent with regulatory requirements? ③ Are there any contradictions or conflicts between systems? ④ How operable are the systems?

Step Three: Risk Identification and Assessment. Establish a risk matrix covering four major categories: strategic, operational, financial, and compliance risks. Risk identification should follow a "top-down" (from strategic goals) and "bottom-up" (based on business scenarios) dual approach. Risk assessment uses a "inherent risk × control effectiveness" model to calculate residual risk levels and determine the priority of controls in high-risk areas.

Step Four: Control Measure Design and Embedding. For high-risk areas identified in the assessment, design a combination of preventive controls (Preventive Controls) and detective controls (Detective Controls). Preventive controls include pre-approval, qualification access, and limit management; detective controls include regular reconciliation, monitoring of abnormal transactions, and special audits. Control measures should be embedded in business processes to form an integrated operation model where "business is control, and control is business."

Step Five: Monitoring and Reporting Mechanism Construction. Establish a "red-yellow-green light" risk warning mechanism to monitor key risk indicators (KRIs) in real time. Compliance reports should be presented in a hierarchical manner: daily/weekly reports at the operational level, monthly/quarterly reports at the management level, and semi-annual/annual reports at the board level. The reports should include risk trend analysis, control effectiveness evaluation, and progress tracking of corrective actions.

Step Six: Evaluation, Improvement, and Culture Cultivation. Conduct at least one internal control self-assessment (CSA) and compliance management review annually to identify weak points and develop improvement plans. Simultaneously, integrate internal control and compliance culture into the company's values through training, evaluation, incentives, and accountability mechanisms, transforming compliance behavior from "passive compliance" to "voluntary action."

4.2 Empowering Internal Control and Compliance Management with Digital Tools

As enterprises grow in scale and business complexity, traditional manual internal control and compliance management models can no longer meet the requirements for efficiency and coverage. Digital transformation provides new capabilities for internal control and compliance management:

Process Automation and Compliance Embedding. Through OA, ERP, and other information systems, embed compliance approval nodes into key business processes—payments must be reviewed for compliance, contracts must be approved by legal, and supplier changes must undergo due diligence—eliminating the possibility of "bypassing procedures" at the system level.

Data Analysis and Anomaly Detection. Use big data analysis technology to identify abnormal patterns in large volumes of transaction data. For example, automatically alert on transactions where procurement prices deviate from the average, investigate abnormal concentrated payment behaviors, and conduct network analysis of the relationships between employees and suppliers. These methods significantly enhance the coverage and precision of internal control monitoring.

Compliance Knowledge Base and Intelligent Q&A. Structure information on laws, regulations, industry standards, regulatory guidelines, and internal systems to build a compliance knowledge base, and use AI technology to enable intelligent search and automatic Q&A, helping employees quickly obtain compliance guidance in their daily work.

Continuous Monitoring and Automatic Reporting. Establish an internal control and compliance data dashboard to automatically capture key data from various systems (such as control point execution rate, compliance training coverage, number of nonconformities, and closure rate), achieving real-time visual management of internal control and compliance status.

5. Common Governance Challenges and Breakthrough Paths

Challenge One: Board "Focuses on Strategy, Neglects Internal Control"

In many enterprises, the board focuses its main efforts on strategic direction, investment decisions, and personnel appointments, with insufficient attention to the supervision of internal control and compliance systems. Audit committee meetings are often formalities, internal audit reports are rarely discussed in depth, and compliance issues are only taken seriously after "something goes wrong."

Breakthrough Path: Incorporate internal control and compliance performance into the evaluation metrics of the board and audit committee. Specific practices include: regularly inviting the Chief Risk Officer to attend board meetings and report on risk conditions; establishing a "risk accountability" system, requiring business line leaders to report their risk management situations to the audit committee; and linking internal control ratings to executive compensation.

Challenge Two: Compliance and Business "Two Separate Entities"

Compliance manuals written by the compliance department can stack up to a meter high, but business departments have "never heard of them." The disconnect between compliance rules and business realities directly leads to the common phenomenon of "rules are rules, execution is execution."

Breakthrough Path: Promote the "integration of compliance into business" mechanism design. The compliance department should proactively engage with business frontlines, understand business models and operational pain points, and build a "translation bridge" between business language and compliance requirements. Additionally, set compliance weights in business performance evaluations to transform business department leaders from "passive compliance" to "active control."

Challenge Three: More Post-Event Punishments, Fewer Pre-Event Preventions

Many enterprises' internal control and compliance work primarily follows a "identify problems → hold accountable → criticize" model, lacking the ability to prevent risks at the source. This "firefighting" management not only fails to reduce the probability of risk occurrence but also easily leads to opposition and distrust between departments.

Breakthrough Path: Shift from "post-event accountability" to "process empowerment." Move compliance training to the first stages of new employee onboarding, new business launches, and new product rollouts; establish a "compliance consultation" mechanism to encourage business departments to seek compliance advice before making decisions; and use nonconformities as inputs for management system improvement, rather than just as grounds for accountability.

Challenge Four: Shortage of Internal Control and Compliance Talent

Internal control and compliance management require composite talents who understand both business and law, as well as finance and processes, which are extremely scarce in the market. Small and medium-sized enterprises (SMEs) particularly face the dilemma of "no one to use."

Breakthrough Path: Establish a tiered talent development system. For the board and senior management, focus on training in "governance responsibilities and compliance judgment"; for middle managers, focus on training in "process control and risk management methods"; and for frontline employees, focus on training in "job-specific compliance requirements and nonconformity identification capabilities." Additionally, consider outsourcing some internal control and compliance functions to professional institutions, such as internal control evaluation outsourcing and compliance audit outsourcing.

6. Conclusion: From Compliance Baseline to Governance High Ground

Internal control and compliance frameworks are never a "cost center" for enterprises but are important indicators of governance capabilities. In an increasingly complex and uncertain business environment, a robust internal control and compliance system provides three levels of value to the enterprise:

Baseline Value—Avoiding fines, injunctions, lawsuits, and reputational damage due to noncompliance, which is the most direct protective role.

Boundary Value—Helping the enterprise clarify "what can be done and what cannot be done," providing a clear boundary framework for management decisions, thereby improving decision-making efficiency and the predictability of execution outcomes.

High-Value—An excellent internal control and compliance record is itself a "governance calling card." In investor relations, customer relationships, supplier relationships, and government relations, a well-governed enterprise gains more trust and development opportunities compared to a "wildly growing" enterprise.

From "compliance defense" to "risk management" and then to "value creation," the upgrade path of internal control and compliance frameworks is essentially the path to the maturity of corporate governance. For every corporate governance practitioner, systematically building and continuously optimizing the internal control and compliance framework is not an optional "bonus question" but a mandatory "passing question."


Internal control and compliance are not costs for the enterprise but the infrastructure of governance capabilities—only by holding the baseline can one go further.

Knowledge code: 1.2.1

Version: v20260731

Author: Quality Think Tank Quality Think Tank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping enterprises continuously improve their quality capabilities.