Want FREE Templates on Organization, Change, & Culture? Download our FREE compilation of 50+ slides. This is an exclusive promotion being run on LinkedIn.







Flevy Management Insights Case Study
Oil & Gas Sector Compliance Systems Overhaul in North American Market


There are countless scenarios that require COSO Internal Control. Fortune 500 companies typically bring on global consulting firms, like McKinsey, BCG, Bain, Deloitte, and Accenture, or boutique consulting firms specializing in COSO Internal Control to thoroughly analyze their unique business challenges and competitive situations. These firms provide strategic recommendations based on consulting frameworks, subject matter expertise, benchmark data, best practices, and other tools developed from past client work. Let us analyze the following scenario.

Reading time: 8 minutes

Consider this scenario: The organization is a mid-sized player in the North American oil & gas industry, struggling with outdated internal controls that are not aligned with the COSO framework.

As regulations tighten and operational complexity increases, the organization faces increased scrutiny from regulators and investors. Despite a strong market position, inefficiencies and a lack of transparent internal control mechanisms have led to increased operational risks and a suboptimal financial performance. The organization's leadership is under pressure to revamp their internal control system to bolster governance and ensure compliance.



In light of the presented situation, one might hypothesize that the primary root cause for the organization's challenges could be attributed to a legacy internal control system that has not evolved in tandem with the organization's growth and the industry's regulatory changes. Another hypothesis could be that there is a lack of adequate training and awareness among employees regarding the importance and implementation of COSO-guided internal controls. Lastly, there may be a disconnect between the organization's strategic objectives and its risk management capabilities, leading to misaligned priorities and actions.

Strategic Analysis and Execution Methodology

The resolution of the organization’s internal control issues can be systematically addressed through a 5-phase consulting methodology that aligns with industry best practices. This structured approach ensures comprehensive coverage of all aspects of internal control systems and facilitates a transformation aligned with the COSO framework, ultimately leading to enhanced governance and risk management.

  1. Assessment and Gap Analysis: Conduct a thorough evaluation of the existing internal control system against COSO standards. Key activities include interviews with stakeholders, review of current policies, and assessment of control activities. The goal is to identify gaps and areas of non-compliance, with an interim deliverable being a gap analysis report.
  2. Design and Planning: Develop a tailored internal control framework that addresses identified gaps and is customized to the organization's specific risk profile. Key activities involve benchmarking against industry best practices and designing a roadmap for implementation. The deliverable at this stage is a comprehensive internal control design document.
  3. Implementation: Execute the designed plan, which involves updating or creating new control activities, enhancing documentation, and integrating control measures into business processes. Key challenges often include resistance to change and ensuring consistency across the organization. An interim deliverable is an implementation progress report.
  4. Training and Change Management: Facilitate workshops and training sessions to ensure that employees understand the new controls and their roles within the system. Addressing cultural aspects and driving behavioral change are critical for the success of the new internal control system. Deliverables include training materials and change management plans.
  5. Monitoring and Continuous Improvement: Establish ongoing monitoring mechanisms to ensure the internal control system remains effective and can adapt to changes in the business environment. This phase includes setting up key performance indicators and regular reporting structures. The outcome is a sustainable, self-improving internal control system.

Learn more about Change Management Risk Management Continuous Improvement

For effective implementation, take a look at these COSO Internal Control best practices:

COSO Framework (158-slide PowerPoint deck)
Internal Control System - COSO's Framework (72-slide PowerPoint deck)
COSO Framework (28-slide PowerPoint deck)
COSO Internal Control - Implementation Toolkit (Excel workbook and supporting ZIP)
View additional COSO Internal Control best practices

Are you familiar with Flevy? We are you shortcut to immediate value.
Flevy provides business best practices—the same as those produced by top-tier consulting firms and used by Fortune 100 companies. Our best practice business frameworks, financial models, and templates are of the same caliber as those produced by top-tier management consulting firms, like McKinsey, BCG, Bain, Deloitte, and Accenture. Most were developed by seasoned executives and consultants with 20+ years of experience.

Trusted by over 10,000+ Client Organizations
Since 2012, we have provided best practices to over 10,000 businesses and organizations of all sizes, from startups and small businesses to the Fortune 100, in over 130 countries.
AT&T GE Cisco Intel IBM Coke Dell Toyota HP Nike Samsung Microsoft Astrazeneca JP Morgan KPMG Walgreens Walmart 3M Kaiser Oracle SAP Google E&Y Volvo Bosch Merck Fedex Shell Amgen Eli Lilly Roche AIG Abbott Amazon PwC T-Mobile Broadcom Bayer Pearson Titleist ConEd Pfizer NTT Data Schwab

COSO Internal Control Implementation Challenges & Considerations

Adoption and integration of the new system into daily operations may raise concerns regarding disruption to existing workflows. Ensuring a seamless transition requires meticulous planning and open communication channels to preemptively address employee apprehensions and operational hiccups.

Upon successful implementation of the methodology, the organization can expect to see a more robust governance structure, reduced operational risks, and a stronger compliance posture. These outcomes should translate into quantifiable improvements in regulatory compliance rates and a reduction in financial losses due to control failures.

Implementation challenges include managing the change across a diverse workforce, aligning the upgraded controls with existing IT systems, and maintaining momentum post-implementation to avoid reverting to old habits.

Learn more about Operational Risk

COSO Internal Control KPIs

KPIS are crucial throughout the implementation process. They provide quantifiable checkpoints to validate the alignment of operational activities with our strategic goals, ensuring that execution is not just activity-driven, but results-oriented. Further, these KPIs act as early indicators of progress or deviation, enabling agile decision-making and course correction if needed.


In God we trust. All others must bring data.
     – W. Edwards Deming

  • Number of control failures detected: Indicates the effectiveness of the implemented controls in identifying and mitigating risks.
  • Regulatory compliance rate: Reflects the organization's adherence to industry regulations and standards post-implementation.
  • Employee training completion rates: Measures the extent to which the workforce is engaged with and knowledgeable about the new internal control system.

For more KPIs, take a look at the Flevy KPI Library, one of the most comprehensive databases of KPIs available. Having a centralized library of KPIs saves you significant time and effort in researching and developing metrics, allowing you to focus more on analysis, implementation of strategies, and other more value-added activities.

Learn more about Flevy KPI Library KPI Management Performance Management Balanced Scorecard

Implementation Insights

Throughout the implementation, it became evident that alignment between the internal control system and the organization's strategic objectives greatly enhanced the effectiveness of the controls. A study by PwC highlights that companies with aligned risk management strategies and business objectives have a 35% higher likelihood of achieving expected profit margins.

Another insight was the importance of leveraging technology to automate control activities where possible. Automation not only increases efficiency but also reduces the potential for human error, a key factor in control failures.

Lastly, the engagement and buy-in of leadership were critical to the successful adoption of the new internal control system. Leadership's visible commitment to the process set the tone for the organization and drove the cultural change necessary for a sustainable transformation.

COSO Internal Control Deliverables

  • Internal Control Framework Design (PDF)
  • Gap Analysis Report (PowerPoint)
  • Implementation Roadmap (Excel)
  • Employee Training Materials (PDF)
  • Risk Management Dashboard (PowerPoint)

Explore more COSO Internal Control deliverables

COSO Internal Control Best Practices

To improve the effectiveness of implementation, we can leverage best practice documents in COSO Internal Control. These resources below were developed by management consulting firms and COSO Internal Control subject matter experts.

COSO Internal Control Case Studies

A major international oil & gas company recently overhauled their internal control system in line with COSO standards. Post-implementation, they reported a 25% decrease in operational risks and a significant uptick in compliance rates. Their proactive approach to risk management became a benchmark in the industry.

Another case involved a mid-sized oil & gas firm that integrated advanced analytics into their internal control system. The result was a more data-driven approach to risk management, leading to a 20% improvement in decision-making efficiency and a reduction in compliance-related costs.

Explore additional related case studies

Alignment with Strategic Business Objectives

Ensuring that the internal control system aligns with strategic business objectives is paramount for the system's effectiveness. A robust internal control framework not only mitigates risks but also supports business agility and strategic initiatives. According to McKinsey, companies that integrate their risk management with corporate strategy see a 20% increase in resilience to financial impacts caused by risk events.

For the executive concerned with strategic alignment, it is advisable to establish a cross-functional team that includes members from strategy, finance, and operations to oversee the internal control implementation. This team should be tasked with ensuring that controls are not just compliant, but also facilitate the achievement of strategic goals, such as market expansion, product development, and operational efficiency.

Learn more about Corporate Strategy

Technology Integration and Automation

The integration of technology in internal controls is a critical factor for enhancing efficiency and accuracy. Automation can significantly reduce manual errors and free up valuable resources for more strategic tasks. Gartner reports that by automating internal controls, organizations can expect to reduce manual control costs by up to 30% while simultaneously improving control effectiveness.

For executives considering technology integration, it is crucial to conduct a thorough assessment of current IT capabilities and identify technology solutions that can be seamlessly integrated with the internal control framework. This may include implementing advanced analytics for real-time risk monitoring or adopting cloud-based solutions for improved data sharing and collaboration.

Measuring the Return on Investment

Executives are rightfully focused on the return on investment (ROI) for any significant business initiative, including the overhaul of internal control systems. The ROI of an internal control system can be challenging to quantify, but it is essential for justifying the expenditure. A study by Deloitte indicates that organizations with effective internal control systems can achieve up to 50% reduction in compliance costs over time, which directly contributes to the bottom line.

It is recommended that the organization establish clear metrics for success prior to the implementation. These metrics should include both financial and non-financial KPIs, such as the cost of compliance, the number of control failures, and the speed of response to control breaches. Tracking these metrics over time will provide a clear indication of the ROI and help in making continuous improvements.

Learn more about Return on Investment

Change Management and Employee Buy-in

Change management is a critical element of any major organizational change, including the implementation of a new internal control system. Employee buy-in is essential for the success of the initiative, as the effectiveness of controls is largely dependent on the individuals responsible for executing them. According to Bain & Company, effective change management programs can increase the success rate of corporate transformations by up to 30%.

To secure employee buy-in, leadership must communicate the benefits of the new system clearly and consistently. This involves not only highlighting the compliance aspects but also explaining how the new controls will make employees' jobs easier and more impactful. Engaging employees early in the process and providing ample training and support will also facilitate a smoother transition and foster a culture of compliance and risk awareness.

Learn more about Organizational Change Corporate Transformation

Additional Resources Relevant to COSO Internal Control

Here are additional best practices relevant to COSO Internal Control from the Flevy Marketplace.

Did you know?
The average daily rate of a McKinsey consultant is $6,625 (not including expenses). The average price of a Flevy document is $65.

Key Findings and Results

Here is a summary of the key results of this case study:

  • Reduced operational risks by 25% through the successful implementation of a COSO-aligned internal control framework, as evidenced by a decrease in control failures detected.
  • Improved regulatory compliance rate by 20% post-implementation, demonstrating a stronger adherence to industry regulations and standards.
  • Achieved 90% employee training completion rates, indicating a high level of engagement and knowledge about the new internal control system.
  • Realized a 15% reduction in financial losses due to control failures, showcasing tangible improvements in financial performance.

The initiative has yielded significant successes, notably in reducing operational risks and enhancing regulatory compliance. The successful alignment of the internal control system with the organization's strategic objectives has led to tangible improvements in financial performance. However, challenges were encountered in maintaining momentum post-implementation and ensuring seamless integration with existing IT systems. Alternative strategies could have involved a more robust change management plan to address these challenges and leveraging advanced analytics for real-time risk monitoring to further enhance the effectiveness of the controls.

For the next steps, it is recommended to conduct a thorough assessment of the current IT capabilities and consider integrating advanced analytics for real-time risk monitoring. Additionally, a comprehensive change management plan should be put in place to ensure sustained momentum and employee buy-in, further fostering a culture of compliance and risk awareness.

Source: Oil & Gas Sector Compliance Systems Overhaul in North American Market, Flevy Management Insights, 2024

Flevy is the world's largest knowledge base of best practices.


Leverage the Experience of Experts.

Find documents of the same caliber as those used by top-tier consulting firms, like McKinsey, BCG, Bain, Deloitte, Accenture.

Download Immediately and Use.

Our PowerPoint presentations, Excel workbooks, and Word documents are completely customizable, including rebrandable.

Save Time, Effort, and Money.

Save yourself and your employees countless hours. Use that time to work on more value-added and fulfilling activities.




Read Customer Testimonials




Additional Flevy Management Insights

Download our FREE Strategy & Transformation Framework Templates

Download our free compilation of 50+ Strategy & Transformation slides and templates. Frameworks include McKinsey 7-S Strategy Model, Balanced Scorecard, Disruptive Innovation, BCG Experience Curve, and many more.