Information and Communication
In a governance and internal control context, Information and Communication refers to how an organization obtains or generates relevant information and shares it, both internally and with outside parties, so that people can carry out their responsibilities. It is one of the components commonly discussed within internal control and enterprise risk management frameworks. Note that this differs from the similarly worded technology concept known as Information and Communications Technology (ICT), which describes the tools and infrastructure used to gather, store, transmit, and process information.
Information and Communication is typically treated as a component of internal control and enterprise risk management, concerning the identification, capture, and exchange of information in a form and timeframe that enable personnel to fulfill their control and governance responsibilities. It addresses both internal communication, flowing across and up and down the organization to support decision-making and accountability, and external communication with regulators, customers, and other stakeholders. This governance/risk usage should not be conflated with Information and Communications Technology (ICT), which the evidence describes as the technologies and infrastructure used for gathering, storing, transmitting, retrieving, or processing information; ICT is an enabling technology domain rather than an internal control component. The evidence packet provided does not contain the internal control framework text (for example, from a specific issuing body) that would allow attribution of particular components, principles, or clause references, so those specifics are omitted here.
Why it matters
Information and Communication underpins the ability of an organization's people to carry out their control and governance responsibilities. If relevant information is not identified, captured, and shared in a usable form and timeframe, decision-makers may act on incomplete or stale data, and accountability across the organization can break down. In governance and internal control terms, this component connects the other elements of a control environment to the people who must operate controls, escalate issues, and respond to emerging risks.
The distinction between this governance concept and Information and Communications Technology (ICT) matters in practice. ICT, as described in the evidence, refers to the technologies and infrastructure used for gathering, storing, transmitting, retrieving, or processing information. Treating the two as identical can lead an organization to assume that investing in technology alone satisfies the internal control need, when the control component is concerned with whether the right information actually reaches the right people to support responsibilities and decisions. Technology may enable communication, but it does not by itself ensure that communication is relevant, timely, or acted upon.
Effective information flows, both internally across and up and down the organization, and externally with regulators, customers, and other stakeholders, support decision-making and accountability. Weaknesses in this component can contribute to failures elsewhere in a control system, though the specific consequences depend on the organization's context, sector, and jurisdiction.
Who it's relevant to
Inside Information and Communication
Common questions
Answers to the questions practitioners most commonly ask about Information and Communication.
