Auditing & Assurance
Internal Controls Evaluation
Internal control is the process, designed and operated by those charged with governance, management, and staff, to provide reasonable assurance about the achievement of objectives in financial reporting reliability, operational effectiveness/efficiency, and compliance with laws. For auditors, the focus is controls relevant to reliable financial reporting.
Real-world example
Approval limits, reconciliations, and segregation of duties together form the internal control over financial reporting.
Audit Risk & Materiality
Audit Evidence & Procedures
Internal Controls Evaluation
COSO's five components are: the control environment (governance, integrity, tone at the top), risk assessment (identifying and analyzing risks), control activities (policies/procedures like approvals and reconciliations), information and communication (relevant, timely information flow), and monitoring activities (ongoing/separate evaluations). Together they form an integrated system supporting reliable reporting.
COSO: Control Environment, Risk Assessment, Control Activities,
Information & Communication, Monitoring.
Real-world example
The auditor assesses each COSO component to understand the client's control system before testing specific controls.
Audit Risk & Materiality
ISA Standards
Internal Controls Evaluation
Segregation of duties splits key responsibilities—authorization, custody of assets, recording, and reconciliation—among different people so no single individual can both perpetrate and conceal an error or fraud. It's a fundamental control activity; its absence (e.g., one person handling and recording cash) is a common significant deficiency.
Real-world example
The person who approves payments is different from the one who sets up vendors and the one who reconciles the bank, preventing fraud.
Fraud & Error Responsibilities
Audit Risk & Materiality
Internal Controls Evaluation
Preventive controls stop errors or fraud before they occur (e.g., approval limits, access restrictions, segregation of duties). Detective controls identify errors or fraud after they occur (e.g., reconciliations, exception reports, physical counts). A good system combines both; detective controls catch what preventive controls miss and support timely correction.
Real-world example
Approval limits prevent unauthorized spend (preventive), while bank reconciliations detect any that slips through (detective).
Audit Risk & Materiality
Audit Evidence & Procedures
Internal Controls Evaluation
The auditor gains understanding through inquiry of personnel, observation of controls in operation, inspection of documents and reports, and walkthroughs (tracing a transaction from initiation through the system to the financial statements). This identifies the controls relevant to the audit and whether they're designed effectively and implemented.
Real-world example
A walkthrough of one sales order from entry to cash receipt confirms how the controls are designed and operate.
Audit Evidence & Procedures
Audit Risk & Materiality
Internal Controls Evaluation
Design effectiveness means a control, if operating as intended, would prevent or detect material misstatements. Operating effectiveness means the control actually operated as designed throughout the relevant period. The auditor first evaluates design (and implementation), then, if relying on the control, tests operating effectiveness across the period.
Real-world example
A well-designed approval control (design) is then tested across many transactions to confirm it consistently operated (operation).
Audit Evidence & Procedures
Audit Sampling
Internal Controls Evaluation
What is the difference between a deficiency, a significant deficiency, and a material weakness?
AdvancedA control deficiency exists when a control doesn't prevent or detect misstatements timely. A significant deficiency is a deficiency (or combination) important enough to merit attention by those charged with governance. A material weakness is a deficiency (or combination) creating a reasonable possibility that a material misstatement won't be prevented or detected—the most severe, and reportable in ICFR audits.
Severity: deficiency < significant deficiency < material weakness.
Real-world example
A missing bank reconciliation that could hide a material error is escalated as a material weakness in the ICFR audit.
Audit Report & Opinions
ISA Standards
Internal Controls Evaluation
Entity-level controls operate broadly across the organization—tone at the top, governance, policies, monitoring, IT general controls—and influence many processes. Process/transaction-level controls operate within specific processes (e.g., matching, approvals) over particular assertions. Strong entity-level controls can affect the extent of testing of process controls; weak ones increase risk pervasively.
Real-world example
A strong control environment and effective monitoring (entity-level) support reliance on the day-to-day process controls.
Audit Risk & Materiality
Audit Evidence & Procedures
Internal Controls Evaluation
ITGCs are controls over the IT environment that support reliable functioning of application controls—covering access security, change management, program development, and computer operations. If ITGCs are weak (e.g., poor access controls), automated application controls and system-generated data can't be relied upon, increasing risk and required substantive work.
Real-world example
Weak access controls mean the auditor can't rely on the system's automated three-way match, so more substantive testing is needed.
Audit Evidence & Procedures
Audit Risk & Materiality
Internal Controls Evaluation
Manual controls are performed by people (e.g., a manager reviewing a reconciliation) and are flexible but prone to human error, override, and inconsistency. Automated controls are performed by the system (e.g., a system-enforced credit limit) and operate consistently, but depend on reliable ITGCs and correct configuration. Auditors test each differently.
Real-world example
A system-enforced matching control operates consistently, while a manual review may be skipped when staff are busy.
Audit Evidence & Procedures
Audit Sampling
Internal Controls Evaluation