Auditing & Assurance

Internal Controls Evaluation

18 question(s)

What is internal control?

Beginner
Internal control is the process, designed and operated by those charged with governance, management, and staff, to provide reasonable assurance about the achievement of objectives in financial reporting reliability, operational effectiveness/efficiency, and compliance with laws. For auditors, the focus is controls relevant to reliable financial reporting.
Real-world example Approval limits, reconciliations, and segregation of duties together form the internal control over financial reporting.

Common follow-ups: What objectives do internal controls serve? | Which controls do auditors focus on?

Audit Risk & Materiality Audit Evidence & Procedures Internal Controls Evaluation

What are the five components of internal control (COSO framework)?

Beginner
COSO's five components are: the control environment (governance, integrity, tone at the top), risk assessment (identifying and analyzing risks), control activities (policies/procedures like approvals and reconciliations), information and communication (relevant, timely information flow), and monitoring activities (ongoing/separate evaluations). Together they form an integrated system supporting reliable reporting.
COSO: Control Environment, Risk Assessment, Control Activities,
Information & Communication, Monitoring.
Real-world example The auditor assesses each COSO component to understand the client's control system before testing specific controls.

Common follow-ups: What is the control environment? | How do the components interrelate?

Audit Risk & Materiality ISA Standards Internal Controls Evaluation

What is segregation of duties?

Beginner
Segregation of duties splits key responsibilities—authorization, custody of assets, recording, and reconciliation—among different people so no single individual can both perpetrate and conceal an error or fraud. It's a fundamental control activity; its absence (e.g., one person handling and recording cash) is a common significant deficiency.
Real-world example The person who approves payments is different from the one who sets up vendors and the one who reconciles the bank, preventing fraud.

Common follow-ups: Which duties should be separated? | Why is poor segregation a red flag?

Fraud & Error Responsibilities Audit Risk & Materiality Internal Controls Evaluation

What is the difference between preventive and detective controls?

Intermediate
Preventive controls stop errors or fraud before they occur (e.g., approval limits, access restrictions, segregation of duties). Detective controls identify errors or fraud after they occur (e.g., reconciliations, exception reports, physical counts). A good system combines both; detective controls catch what preventive controls miss and support timely correction.
Real-world example Approval limits prevent unauthorized spend (preventive), while bank reconciliations detect any that slips through (detective).

Common follow-ups: Give an example of each. | Why combine both types?

Audit Risk & Materiality Audit Evidence & Procedures Internal Controls Evaluation

How does the auditor obtain an understanding of internal control?

Intermediate
The auditor gains understanding through inquiry of personnel, observation of controls in operation, inspection of documents and reports, and walkthroughs (tracing a transaction from initiation through the system to the financial statements). This identifies the controls relevant to the audit and whether they're designed effectively and implemented.
Real-world example A walkthrough of one sales order from entry to cash receipt confirms how the controls are designed and operate.

Common follow-ups: What is a walkthrough? | What does understanding controls achieve?

Audit Evidence & Procedures Audit Risk & Materiality Internal Controls Evaluation

What is the difference between design effectiveness and operating effectiveness?

Intermediate
Design effectiveness means a control, if operating as intended, would prevent or detect material misstatements. Operating effectiveness means the control actually operated as designed throughout the relevant period. The auditor first evaluates design (and implementation), then, if relying on the control, tests operating effectiveness across the period.
Real-world example A well-designed approval control (design) is then tested across many transactions to confirm it consistently operated (operation).

Common follow-ups: Can a control be well-designed but not operating? | When must operating effectiveness be tested?

Audit Evidence & Procedures Audit Sampling Internal Controls Evaluation

What is the difference between a deficiency, a significant deficiency, and a material weakness?

Advanced
A control deficiency exists when a control doesn't prevent or detect misstatements timely. A significant deficiency is a deficiency (or combination) important enough to merit attention by those charged with governance. A material weakness is a deficiency (or combination) creating a reasonable possibility that a material misstatement won't be prevented or detected—the most severe, and reportable in ICFR audits.
Severity: deficiency < significant deficiency < material weakness.
Real-world example A missing bank reconciliation that could hide a material error is escalated as a material weakness in the ICFR audit.

Common follow-ups: What distinguishes a material weakness? | Who must significant deficiencies be reported to?

Audit Report & Opinions ISA Standards Internal Controls Evaluation

What are entity-level controls versus process-level (transaction) controls?

Intermediate
Entity-level controls operate broadly across the organization—tone at the top, governance, policies, monitoring, IT general controls—and influence many processes. Process/transaction-level controls operate within specific processes (e.g., matching, approvals) over particular assertions. Strong entity-level controls can affect the extent of testing of process controls; weak ones increase risk pervasively.
Real-world example A strong control environment and effective monitoring (entity-level) support reliance on the day-to-day process controls.

Common follow-ups: How do entity-level controls affect the audit? | Give an example of each level.

Audit Risk & Materiality Audit Evidence & Procedures Internal Controls Evaluation

What are IT general controls (ITGCs) and why do they matter?

Advanced
ITGCs are controls over the IT environment that support reliable functioning of application controls—covering access security, change management, program development, and computer operations. If ITGCs are weak (e.g., poor access controls), automated application controls and system-generated data can't be relied upon, increasing risk and required substantive work.
Real-world example Weak access controls mean the auditor can't rely on the system's automated three-way match, so more substantive testing is needed.

Common follow-ups: What areas do ITGCs cover? | How do weak ITGCs affect application controls?

Audit Evidence & Procedures Audit Risk & Materiality Internal Controls Evaluation

What is the difference between manual and automated controls?

Intermediate
Manual controls are performed by people (e.g., a manager reviewing a reconciliation) and are flexible but prone to human error, override, and inconsistency. Automated controls are performed by the system (e.g., a system-enforced credit limit) and operate consistently, but depend on reliable ITGCs and correct configuration. Auditors test each differently.
Real-world example A system-enforced matching control operates consistently, while a manual review may be skipped when staff are busy.

Common follow-ups: What are the risks of manual controls? | What do automated controls depend on?

Audit Evidence & Procedures Audit Sampling Internal Controls Evaluation