You do notmhave to usemthat framework. The auditing papers use a different, but similar, set of headings.
COSO is relevant here becausemdown the ‘front’ of the cube (see P99 of our notes) you have the steps that set out risk management, which is very bound up with internal control.