Skip to main content
Category: Controls Management

Information and Communication

Simply put

In a governance and internal control context, Information and Communication refers to how an organization obtains or generates relevant information and shares it, both internally and with outside parties, so that people can carry out their responsibilities. It is one of the components commonly discussed within internal control and enterprise risk management frameworks. Note that this differs from the similarly worded technology concept known as Information and Communications Technology (ICT), which describes the tools and infrastructure used to gather, store, transmit, and process information.

Formal definition

Information and Communication is typically treated as a component of internal control and enterprise risk management, concerning the identification, capture, and exchange of information in a form and timeframe that enable personnel to fulfill their control and governance responsibilities. It addresses both internal communication, flowing across and up and down the organization to support decision-making and accountability, and external communication with regulators, customers, and other stakeholders. This governance/risk usage should not be conflated with Information and Communications Technology (ICT), which the evidence describes as the technologies and infrastructure used for gathering, storing, transmitting, retrieving, or processing information; ICT is an enabling technology domain rather than an internal control component. The evidence packet provided does not contain the internal control framework text (for example, from a specific issuing body) that would allow attribution of particular components, principles, or clause references, so those specifics are omitted here.

Why it matters

Information and Communication underpins the ability of an organization's people to carry out their control and governance responsibilities. If relevant information is not identified, captured, and shared in a usable form and timeframe, decision-makers may act on incomplete or stale data, and accountability across the organization can break down. In governance and internal control terms, this component connects the other elements of a control environment to the people who must operate controls, escalate issues, and respond to emerging risks.

The distinction between this governance concept and Information and Communications Technology (ICT) matters in practice. ICT, as described in the evidence, refers to the technologies and infrastructure used for gathering, storing, transmitting, retrieving, or processing information. Treating the two as identical can lead an organization to assume that investing in technology alone satisfies the internal control need, when the control component is concerned with whether the right information actually reaches the right people to support responsibilities and decisions. Technology may enable communication, but it does not by itself ensure that communication is relevant, timely, or acted upon.

Effective information flows, both internally across and up and down the organization, and externally with regulators, customers, and other stakeholders, support decision-making and accountability. Weaknesses in this component can contribute to failures elsewhere in a control system, though the specific consequences depend on the organization's context, sector, and jurisdiction.

Who it's relevant to

Governance professionals
Those responsible for organizational structures and decision rights rely on this component to ensure that relevant information reaches the people accountable for control and governance responsibilities, and that internal and external communication channels function as intended.
Internal auditors and assurance functions
Assurance providers may evaluate whether information and communication arrangements support the operation of controls, keeping in mind the independence and objectivity that distinguish assurance activity from the management activities being reviewed.
Risk managers
Professionals identifying and treating risk depend on timely and relevant information flows to support decision-making, and may consider weaknesses in this component as a factor affecting the effectiveness of the broader control system.
Compliance and regulatory specialists
Those managing adherence to laws, regulations, and internal policies are concerned with external communication with regulators and other stakeholders, though specific reporting obligations vary by jurisdiction, industry, and organization size.

Inside Information and Communication

Relevant, quality information
Information that is timely, current, accurate, complete, accessible, and sufficiently reliable to support the functioning of governance, risk, and control activities. Quality attributes are commonly emphasized because decisions and control operation depend on the integrity of the underlying information.
Internal communication
The flow of information within the organization, downward, upward, and across functions, that conveys objectives, responsibilities, policies, standards, and procedures, and that enables personnel to understand and carry out their control-related duties. This typically includes channels for reporting concerns, sometimes independent of the normal reporting line.
External communication
The exchange of information with outside parties such as regulators, customers, suppliers, shareholders, and other stakeholders. This encompasses both inbound information that may affect risk and control assessments and outbound reporting to meet obligations and stakeholder expectations. The specific external reporting required varies by jurisdiction, sector, and organization size.
Information systems and sources
The mechanisms, which may be manual or automated, and may draw on internal and external data, that capture, process, and distribute information used to support governance, risk management, and compliance. This entry does not cover specific tooling, system architecture, or implementation detail.
Communication of roles and responsibilities
The conveyance of individual accountabilities within the control environment, so that personnel understand how their activities relate to the work of others and to organizational objectives. This spans the governance pillar (decision rights and roles) and control operation.

Common questions

Answers to the questions practitioners most commonly ask about Information and Communication.

Is Information and Communication just another way of saying an organization's IT systems or communication tools?
No. Although the name can suggest technology, Information and Communication as a control component refers to the processes by which relevant information is identified, captured, and exchanged so that people can carry out their responsibilities. Information systems and tooling may support it, but the component itself concerns the quality, flow, and relevance of information rather than any particular technology. Reducing it to IT infrastructure is a common misreading.
Does Information and Communication only mean reporting information upward to management and the board?
Not solely. Communication in this context is commonly understood to flow in multiple directions, downward to convey expectations and responsibilities, upward to escalate issues and results, and across the organization to coordinate. It also typically encompasses communication with external parties where relevant. Treating it as purely upward reporting overlooks the internal cross-functional and external dimensions.
How can an organization assess whether the information supporting its controls is of adequate quality?
Organizations commonly evaluate information against attributes such as relevance, timeliness, accuracy, completeness, accessibility, and whether it reaches the people who need it. The specific criteria and how rigorously they are applied vary by organization, sector, and objective. This entry does not prescribe a particular assessment method or tooling; approaches should be tailored to context.
What is the practical distinction between the information and the communication aspects when designing controls?
In general usage, the information aspect concerns generating or obtaining data that is relevant and of sufficient quality to support the functioning of controls and decision-making, while the communication aspect concerns conveying that information to the appropriate internal and external parties. Distinguishing them helps identify whether a weakness lies in the data itself or in how it is shared.
How does Information and Communication relate to the other components of an internal control or ERM framework?
It is commonly described as supporting the operation of the other components rather than standing alone. Reliable information and effective communication typically enable activities such as risk assessment, control activities, and monitoring to function. The precise relationships depend on the framework in use, and this entry does not detail any specific framework's structure.
What are common signs that Information and Communication may be deficient in practice?
Indicators may include responsibilities that are unclear because expectations were not communicated, issues that are not escalated on a timely basis, decisions made on incomplete or outdated data, or external reporting obligations that are missed. These are illustrative rather than exhaustive, and their significance depends on the organization's context and objectives. This entry does not provide remediation guidance or legal advice.

Common misconceptions

Information and Communication is essentially the same as an organization's IT systems.
It is broader than technology. It concerns the identification, capture, quality, and flow of relevant information, by manual or automated means, and the communication of that information internally and externally. IT systems are one enabling mechanism, not the component itself, and this concept does not address specific tools or system design.
Communication under this component is a one-way, top-down flow of policies and directives.
Effective communication is commonly described as multi-directional: downward, upward, and lateral internally, as well as inbound and outbound externally. Upward channels, including avenues to report concerns, are typically emphasized so that management receives information about how controls are operating.
Producing more information automatically improves control and decision-making.
The emphasis is on relevant, quality information rather than volume. Information that lacks timeliness, accuracy, completeness, or accessibility may not support control activities effectively, and the presence of information does not guarantee that risks are addressed or objectives achieved.

Best practices

Define the quality attributes expected of information used in governance, risk, and control processes, such as timeliness, accuracy, completeness, and accessibility, and periodically assess whether information sources meet them.
Establish and communicate roles and responsibilities clearly so that personnel understand their control-related duties and how their activities relate to organizational objectives.
Maintain multi-directional internal communication channels, including upward avenues for personnel to raise concerns, where appropriate independent of the normal reporting line.
Identify external communication obligations and stakeholder expectations relevant to the organization's jurisdiction, sector, and size, and ensure outbound reporting and inbound information flows are addressed accordingly.
Assess information sources for both internal and external data, and confirm that mechanisms, whether manual or automated, reliably capture and distribute what governance, risk, and compliance functions require.
Periodically review communication channels and information flows to confirm they remain relevant as objectives, risks, and reporting requirements change.
Application Security Isn’t Optional Anymore.