§6.1 Relationship to COSO IC 2013
The five structural governance disciplines map to COSO IC 2013's five components. This is not a forced alignment — it reflects a shared structural insight: any system of internal control requires authority, risk identification, control activities, information, and monitoring. The world model governance framework specifies the connective tissue that makes COSO's components interact reliably in AI-native contexts.
| Governance Discipline | COSO IC 2013 Component | COSO Principles | What WMGF Adds |
|---|---|---|---|
| Authority Mapping | Control Environment | P1-P5 | Three-layer behavioral-contract architecture; actor taxonomy with authority ceilings; model-provider non-existence rule |
| Decision Boundary | Risk Assessment | P6-P9 | Named decision surfaces at three scales; decision provenance enforcement; classification as structural decision |
| Constraint Propagation | Control Activities | P10-P12 | Six propagation patterns; tighten-only inheritance; constraint-first validation; effective constraint set computation |
| Evidence Obligations | Information & Communication | P13-P15 | Re-performance standard; five-element finding structure; three follow-up obligations; truth-type meta-evidence |
| Accountability Resolution | Monitoring | P16-P17 | Finding lifecycle with carry-forward; governance-health indicators; self-referential closure; commitment-breach protocol |
§6.2 COSO IC 2013 Principle Mapping
Control Environment (Principles 1-5) — Authority Mapping
Principle 1: The organization demonstrates a commitment to integrity and ethical values. In a governed world model, ethical commitments are traced to the constituting authority through CO-PU-AUT and constrained through CO-PU-CST (negation clause inheritance). Ethical positions are structural bindings, not aspirational statements — they produce governance findings when violated. An implementation's Controls charter record would house these bindings as named, testable constraints.
Principle 2: The board of directors demonstrates independence from management and exercises oversight. CO-OB-AUT separates interpretive authority from observation and action authority. CO-TL-AUT separates work-definition authority from operational authority. The structural guarantee is that the authority that evaluates outcomes is not the same authority that produces them.
Principle 3: Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities. CO-EN-AUT requires every authority chain to terminate at a registered entity through the three-layer behavioral-contract architecture. CO-RE-AUT requires authority to flow through the relation structure. Together, they make reporting lines and authorities structural rather than organizational-chart artifacts.
Principle 4: The organization demonstrates a commitment to attract, develop, and retain competent individuals. CO-EN-DEC includes capacity assessment as a governed decision surface. For computational actors, CO-EN-EVD requires registration records specifying underlying model — a structural analog to competence assessment.
Principle 5: The organization holds individuals accountable for their internal control responsibilities. CO-EN-ACT makes accountability deterministic through entity chains. CO-PU-ACT provides self-referential closure at the apex. The accountability architecture is structural — it follows delegation chains, not narrative.
Risk Assessment (Principles 6-9) — Decision Boundary Specification
Principle 6: The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives. CO-PU-EVD requires the apex to carry empirically anchored success criteria. CO-PU-DEC makes apex revision the most tightly governed surface. Every objective is a directive record (§2.2) with structural fields enabling risk identification.
Principle 7: The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed. The governance matrix itself is a risk identification tool — each control objective names a structural requirement whose absence is a risk. CO-OB-DEC makes every interpretation of an ambiguous signal a governed decision where alternatives are documented.
Principle 8: The organization considers the potential for fraud in assessing risks to the achievement of objectives. CO-UN-CST requires truth types to constrain derivation — authoritative findings cannot issue from opaque inputs. CO-DI-AUT separates namespace authority from content authority. Together, these prevent the epistemic analogs of fraud: claims that present uncertain inputs as verified conclusions.
Principle 9: The organization identifies and assesses changes that could significantly impact the system of internal control. CO-TI-DEC makes every cycle transition a governed decision boundary. CO-TL-DEC makes every activation and state transition governed. CO-RE-DEC makes every relation modification governed. Significant changes to the system are named decision surfaces.
Control Activities (Principles 10-12) — Constraint Propagation
Principle 10: The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels. CO-CO-CST specifies six propagation patterns. The effective constraint set computation (the union of inherited, class-membership, and local constraints with precedence rules) is the structural mechanism for ensuring that selected controls actually reach the point of operation.
Principle 11: The organization selects and develops general controls over technology. CO-EN-CST requires entity-level constraints to propagate through role envelopes and behavioral contracts under tighten-only rules. For computational actors, the actor type's authority ceiling (CO-EN-AUT) is a general technology control — it determines what a computational actor can ever be authorized to do, regardless of the specific engagement.
Principle 12: The organization deploys control activities through policies that establish what is expected and procedures that put policies into action. CO-CO-EVD requires every constraint to specify an observable violation condition and a detection mechanism. CO-TL-CST requires work to inherit its effective constraint set from the parent objective. Policies become structural constraints with testable violation conditions — not aspirational statements.
Information & Communication (Principles 13-15) — Evidence Obligations
Principle 13: The organization obtains or generates and uses relevant, quality information to support the functioning of internal control. CO-ME-EVD requires the evidence-retention discipline to be reflexively evidenced. CO-UN-EVD requires truth-type classification as meta-evidence. Evidence quality is structural — it is tested through truth-type propagation (CO-UN-CST), not through subjective assessment.
Principle 14: The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control. CO-RE-EVD requires every relation to be auditable. CO-DI-EVD requires every operative term to resolve through an auditable chain. Internal communication is testable through relation navigability and term resolution.
Principle 15: The organization communicates with external parties regarding matters affecting the functioning of internal control. CO-OB-EVD requires capture-time immutability for observations. CO-UN-AUT requires truth-type authority to be separated from content authority. External communication is constrained by the evidence obligations and truth-type disciplines — claims made externally carry the same epistemic classification as internal claims.
Monitoring (Principles 16-17) — Accountability Resolution
Principle 16: The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning. CO-TI-DEC makes every cycle transition a governed decision boundary. CO-ME-DEC makes every learning-lifecycle transition a governed decision. The governance-health indicators (§3.5) are the mechanism for ongoing evaluation — they track whether mechanisms are functioning, not just existing.
Principle 17: The organization evaluates and communicates deficiencies in internal control on a timely basis to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate. CO-TI-ACT establishes temporal causation — whether corrective action was timely. CO-PU-ACT provides self-referential closure to the constituting authority. The finding lifecycle (open, in progress, addressed, verified, closed) with carry-forward at each cycle is the structural mechanism for timely communication.
§6.3 Entity-Wide Controls
Entity-wide controls are those that operate across the governed world model regardless of which ingredient they test. They correspond to OMB Compliance Supplement Part 6, Appendix 1 — controls that are pervasive rather than ingredient-specific.
The governance matrix identifies seven entity-wide controls that emerge from the primitive patterns (§5.5):
EWC-1: Authority Separation Discipline. Every ingredient requires separation of at least two authority surfaces (Authority Mapping discipline, §3.1; CO-{*}-AUT). The entity-wide control is: no single authority surface can span governance and operational functions for the same ingredient. Test: for each ingredient, confirm that at least two distinct authority holders are identified.
EWC-2: Named Decision Surface Discipline. Every ingredient contributes decision surfaces to the system's total decision map (Decision Boundary discipline, §3.2; CO-{*}-DEC). The entity-wide control is: the system shall maintain a complete inventory of its governed decision surfaces, and every decision shall produce a named artifact. Test: enumerate decision surfaces per ingredient; confirm each produces a decision record.
EWC-3: Tighten-Only Propagation Discipline. Every ingredient's constraint architecture operates under tighten-only directionality (Constraint Propagation discipline, §3.3; CO-{*}-CST). The entity-wide control is: no downstream record in any ingredient's constraint chain shall loosen a constraint inherited from a parent or apex. Test: for each ingredient, trace one constraint from apex to operational surface; confirm no loosening.
EWC-4: Named Evidence Artifact Discipline. Every ingredient's evidence obligation names a specific artifact type (Evidence Obligations discipline, §3.4; CO-{*}-EVD). The entity-wide control is: every evidence obligation in the matrix shall produce a named, retrievable artifact — not a general documentation goal. Test: for each ingredient, confirm the evidence artifact exists and is retrievable.
EWC-5: Structural Accountability Chain Discipline. Every ingredient's accountability resolution requires a deterministic structural path (Accountability Resolution discipline, §3.5; CO-{*}-ACT). The entity-wide control is: accountability for every ingredient shall be traceable through structural relations alone, without narrative interpretation. Test: for each ingredient, follow the accountability chain from a hypothetical failure to the responsible authority using only the relation graph.
EWC-6: Cycle-Over-Cycle Examination. Every ingredient's finding lifecycle requires re-examination at each governance cycle (CO-TI-DEC, CO-ME-DEC). The entity-wide control is: the system shall re-examine every open finding, re-calculate every governance indicator, and re-disposition every corrective action at each annual cycle. Test: confirm cycle-over-cycle disposition records exist.
EWC-7: Self-Referential Closure. The governance system must be able to examine itself (CO-PU-ACT, CO-ME-EVD, CO-ME-ACT). The entity-wide control is: the governance system's own records shall be subject to the same structural discipline as the records it governs. Test: apply the governance matrix to the governance system's own artifacts; confirm all 190 control objectives are addressed.
§6.4 Specific Controls by Governance Discipline
Specific controls correspond to OMB Compliance Supplement Part 6, Appendix 2 — controls organized by compliance type. In this framework, the compliance types map to the five governance disciplines as COSO overlay groups. Each discipline groups a subset of the nineteen primitives; reading those primitives across all ten ingredients produces the discipline's specific control set (see §3.6 for the grouping and §5.5 for primitive navigation).
Authority Mapping specific controls (CO-{}-AUT, CO-{}-ENT, CO-{*}-NSP — 30 COs across three primitives). Test that every ingredient has explicitly mapped authority surfaces, that delegation chains terminate at registered entities, that no authority is accumulated through practice rather than through grant, and that computational actors operate within their type ceiling. The entity and namespace primitives contribute the structural substrate on which authority operates.
Decision Boundary specific controls (CO-{}-DEC, CO-{}-ACV, CO-{*}-ITP — 30 COs across three primitives). Test that every ingredient's decision surfaces are named and inventoried, that every resolved question produces a decision artifact, that classification decisions are auditable, and that lifecycle transitions carry recorded alternatives. Activation and interpretation primitives contribute the precondition and resolution mechanisms that frame decisions.
Constraint Propagation specific controls (CO-{}-CST, CO-{}-CMT, CO-{*}-EIF — 30 COs across three primitives). Test that every ingredient's constraint architecture implements tighten-only inheritance, that composition rules are explicit, that conflicts halt-and-escalate rather than resolving silently, and that the effective constraint set is computable at every operational point. Commitment and environment-interface primitives contribute the binding and boundary mechanisms through which constraints operate.
Evidence Obligations specific controls (CO-{}-EVD, CO-{}-CTX, CO-{}-ORI, CO-{}-LRN — 40 COs across four primitives). Test that every ingredient's evidence obligation names a specific artifact, that artifacts meet the re-performance standard, that evidence quality is structurally assessed (not subjectively judged), and that the evidence-retention discipline is reflexively evidenced. Context, orientation, and learning primitives contribute the conditions of capture, epistemic stance, and knowledge evolution that qualify evidence.
Accountability Resolution specific controls (CO-{}-ACT, CO-{}-IDN, CO-{*}-CYC — 30 COs across three primitives). Test that every ingredient's accountability path is deterministic, that finding lifecycles are maintained with carry-forward, that disposition tracking covers cycle-over-cycle history, and that the system's accountability for its own governance is reflexive. Identifier and cycle primitives contribute the traceability and temporal forcing functions that sustain accountability.
Note: These five discipline groups are a COSO-bridged navigational overlay, not a partition of all nineteen primitives. They group the sixteen primitives that map onto a COSO component (3+3+3+4+3 = 16 distinct primitives, each in exactly one discipline → 160 COs); the remaining three primitives — intent, work, and capacity — carry no COSO-component home and are tested directly through Mechanical conformance (M-intent, M-work, M-capacity → 30 COs). The authoritative, non-overlapping test surface is the full nineteen-primitive matrix (Part 5); its 190 control objectives stand independent of this overlay. See §3.6 for the overlay mapping table.
§6.5 Risk Assessment Connection
The governance matrix connects to risk assessment through an internal risk assessment instrument that operates at the organization's own grain — its research universe, operational domain, or governed system as the subject of assessment. The governance matrix's 190 control objectives provide the control-objective input to the assessment methodology. Each control objective can be tested for design effectiveness (is the control designed to address the risk?) and operating effectiveness (is the control functioning as designed?).
The internal risk assessment follows the organization's governance cycle. Period instances of the assessment evaluate the 190 control objectives across the specific risk items identified for that period. The assessment pipeline — control objectives, controls inventory, testing, findings, corrective actions, tracking — is the operational execution of the evidence pipeline described in §3.4. Governance-health indicators (§3.5) provide measurement of whether the governance mechanisms are functioning, not just existing.
§6.6 Control-Readiness Boundary
Not all ten ingredients will be equally ready for detailed control testing at any given time. The control-readiness boundary is the line between ingredients whose charter records deliver sufficient depth to support full control testing and ingredients whose charter records are still maturing.
§6.6.1 The Assessment
An implementing organization should conduct an ingredient-record audit against its charter records. For each of the ten ingredients, the audit assesses the ingredient delivery score — how completely the charter record populates the ingredient's structural requirements (definition, absence condition, implementation guidance, and the nineteen primitive governance surfaces from the matrix). A charter record specification or equivalent structural standard provides the scoring criteria.
The audit produces a two-tier classification:
Full-depth charter records deliver their ingredient at sufficient depth to test all nineteen primitives at the implementation level. Control objectives governing these ingredients are testable at both design effectiveness (is the control designed to address the risk?) and operating effectiveness (is the control functioning as designed?).
Structural-only charter records deliver their ingredient's definition and absence condition but lack the implementation depth to support detailed control testing. Control objectives governing the ingredients these records serve are testable at the design level but not yet fully at the operating level.
§6.6.2 Illustrative Example
An organization completing its initial ingredient-record audit might find a distribution such as the following (figures illustrative):
| Tier | Ingredients | Score | Count |
|---|---|---|---|
| Full depth | ingredients with mature governing records | 18–20/20 | 7 |
| Structural only | ingredients whose records are still maturing | 9–12/20 | 3 |
In this illustration, 133 of the 190 control objectives are fully testable (the seven full-depth ingredients × nineteen primitives). The remaining 57 — those governing the three still-maturing ingredients — are testable at design level only until the underlying records reach full depth. The implication is not that those ingredients are ungoverned, but that their governance testing operates at reduced resolution until their records mature. The boundary recedes as records are upgraded (§6.6.3).
§6.6.3 Boundary Movement
The control-readiness boundary is not permanent. As charter records mature — through rewrites, version upgrades, or accumulated implementation evidence — the boundary recedes and more control objectives become fully testable. The assessment should be refreshed at each governance cycle or whenever a charter record undergoes a major version change.
The ingredient-to-charter-record mapping that determines which specific COs are affected is maintained in the compliance matrix (Matrix A) and the implementing organization's charter record specification.
§6.7 Governing a Resource Flow
Resources — money, compute, materiel, any consumable the system allocates — are among the most heavily governed objects in any organization, and the object class the internal-control tradition is built around. The framework governs a resource flow not as a special case but as an ordinary governed object, through three recurring patterns.
The resource as a governed object. A unit of resource carries the same primitives as any governed record: intent (what it is for), authority (who may commit it), constraint (what bounds its use), evidence (what proves it was used as intended), account (who answers for it), and context (the period and purpose it is bound to). Treating a unit of resource as a governed object, rather than as an untracked side effect of activity, is what makes expenditure auditable.
Nested expenditure gates (explicit composition). An expenditure passes two nested constraint gates: an outer activity gate (is this an activity the system is authorized to pursue?) and an inner cost gate (is this cost allowable, allocable, and reasonable for that activity?). Both must pass; neither subsumes the other. This is a concrete instance of the constraint-composition discipline (§3.3): two constraint sources interact, and their composition rule — both gates pass, in order — is stated explicitly rather than left implicit.
Consistency as a behavioral invariant. Like costs are treated alike across time and across objectives; an item expensed in one period and capitalized the next, with no governing decision recording the change, is drift. Consistency is therefore a behavioral invariant: a departure from consistent treatment is a finding (§3.6 deviation governance) unless a governed decision authorizes it.
These map to COSO's Control Activities (the two gates) and Information & Communication (the provenance and consistency obligations that make resource governance auditable).