Controls are the practical mechanism of risk management. They are what stands between a risk existing in the risk register and that risk materialising into a loss, a regulatory breach, or an operational failure. Understanding what makes a control genuinely effective, and how internal audit provides independent assurance that controls are doing what they are supposed to do, is fundamental to any serious approach to governance.
The COSO Internal Control Framework, the most widely used framework for internal control assessment, defines internal control as a process effected by the entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.
The key word in that definition is "process." A control is not a document, a policy statement, or a training certificate. It is something that happens: a check that is performed, a segregation of duty that is maintained, an authorisation that is required, a reconciliation that is completed. Controls exist only to the extent that they are actually operating.
The COSO framework organises internal control around five interrelated components: the control environment, which is the cultural and structural foundation; risk assessment; control activities, which are the specific mechanisms that address identified risks; information and communication; and monitoring. All five must be present and functioning for internal control to be genuinely effective.
Understanding the different types of controls, and what each is designed to do, is the starting point for assessing whether a control environment is appropriately designed.
Preventive controls are designed to stop a risk event from occurring before it happens. They act upstream of the potential failure. A dual authorisation requirement for payments above a defined threshold is a preventive control: it makes it impossible for a single individual to commit an error or fraud without a second person's involvement. Access controls that prevent unauthorised users from viewing or modifying sensitive data are preventive. Input validation rules that reject incorrect data before it enters a system are preventive.
Preventive controls are generally preferable to detective ones where they are practical, because they stop the problem rather than identifying it after it has occurred. However, no set of preventive controls can address every possible failure mode, which is why preventive and detective controls are designed to work together.
Detective controls are designed to identify that a risk event has occurred, or is occurring, so that it can be investigated and corrected. A bank reconciliation that compares two independent data sets and flags discrepancies is a detective control. Management review of exception reports, transaction monitoring systems that flag unusual activity, and variance analysis comparing actual to budget are all detective controls.
The value of a detective control is only realised if detection leads to timely investigation and remediation. A detective control that consistently identifies exceptions but triggers no meaningful response has not reduced risk. It has documented failures efficiently.
Directive controls set out what people are expected to do: policies, procedures, and standards that define expected behaviour. They are the foundation on which other controls are built, but they are not themselves sufficient. A well-written policy that nobody follows is not a functioning control.
Corrective controls come into play after a failure has been identified: root cause analysis, remediation plans, and process changes designed to prevent recurrence. Their effectiveness determines whether the same failure keeps happening.
Manual controls depend on human action: a manager performing a review, an operator completing a checklist, a staff member reconciling two records. They are inherently susceptible to inconsistency, particularly under time pressure, high workload, or when the consequences of bypassing the control seem low.
Automated controls are embedded in technology systems and operate without human discretion. They are generally more reliable than manual controls because they do not depend on an individual remembering to perform a step correctly every time. However, automated controls introduce their own risks: they can be misconfigured, they can be bypassed by users with appropriate system access, and their reliability depends on the IT general control environment that governs access to and change of the underlying systems.
Design effectiveness is the first question in any control assessment: if this control operates exactly as described, would it actually prevent or detect the risk it is intended to manage?
A control can be formally documented, approved at the appropriate level, and consistently followed, and still fail the design test. This happens when the control's logic does not genuinely address the underlying risk. A monthly management review of summarised financial data is not an adequate preventive control for the risk of daily transaction fraud in a high-volume processing environment. A password complexity policy does not address the risk of authorised users sharing credentials. An annual policy attestation does not control the risk that staff apply the policy incorrectly in their day-to-day work.
Assessing design effectiveness requires mapping each control to the specific risk it is intended to address and the specific financial statement assertion or business objective it supports. The COSO Framework's principle that control activities must be selected and developed to address risks to the achievement of objectives is the standard being applied.
Controls that have not kept pace with changes in the risk environment are a common design failure. A process that was once manual may have been automated, eliminating the risk the original control addressed and introducing new risks around system access and change management that the original control does not cover.
Controls that address only part of the risk are another common problem. A control over the approval of new suppliers does not address the risk of approved suppliers being impersonated. A control over payment initiation does not address the risk of fraud in the master vendor file.
Operating effectiveness asks whether the control, regardless of how well it is designed, has been consistently applied as intended over the period under review. This is where the evidential standard matters.
A risk owner's assertion that a control is working is not evidence of operating effectiveness. What the IIA's Global Internal Audit Standards expect is independent verification, based on actual evidence that the control operated as described during the relevant period. The nature of that evidence depends on the control type.
For a control that requires a manager to review and approve a report before it is submitted, the evidence of operating effectiveness is the record of that approval: a sign-off, a dated email, a system-generated approval record. For a reconciliation, the evidence is the completed reconciliation document showing that exceptions were identified and followed up. The evidence must exist; it must be dated within the period being assessed; and it must demonstrate that the control was performed by the right person, using the right information, at the right frequency.
Gaps in evidence, approvals without dates, reconciliations completed but not demonstrably reviewed, or review documentation that shows a pattern of items signed off without genuine engagement, are findings in their own right.
For automated controls, operating effectiveness evidence is primarily the IT general control environment. If access to the system is adequately controlled, changes are properly authorised and tested, and the system operates reliably, then automated controls within that system can be presumed to operate consistently. If IT general controls are weak, automated controls may have been modified, bypassed, or may operate incorrectly without detection.
This is why the PCAOB's auditing standards treat the IT general control environment as foundational to the assessment of automated controls: the reliability of automated controls is only as good as the governance of the systems they run on.
The relationship between inherent risk (before controls) and residual risk (after controls) is one of the most important signals in a risk register. The gap between them represents what the control environment is actually achieving.
When inherent risk is rated high and residual risk is also rated high, the controls are either absent, inadequate, or not functioning. When inherent risk is high and residual risk is low, the controls should be doing significant work, and that claim deserves scrutiny. A risk rated as low residual risk is often accepted by the board without challenge, when the question that should be asked is: what evidence do we have that the controls achieving that reduction are actually working?
Internal audit's role is precisely to test this assumption. The risk register shows what management believes the risk position to be. Internal audit shows whether that belief is supported by evidence.
Internal audit uses a range of techniques to assess both design and operating effectiveness, calibrated to the nature and significance of the control being tested.
Inquiry, speaking with control owners about how a control operates in practice, is a starting point but not on its own sufficient as operating effectiveness evidence. What people say they do and what they demonstrably did may not be the same. Observation, watching a control being performed, is more direct but only captures a single point in time.
Reviewing the records that a control produces is typically the most substantive form of operating effectiveness evidence for controls that leave a documentary trail. This involves selecting a sample from the population of control instances during the period, reviewing the evidence for each, and concluding whether the control operated as described.
Sample size matters. The IIA's guidance on sampling and the PCAOB's standards provide direction on appropriate sample sizes based on control frequency and the level of assurance required. An assessor who reviews three instances of a daily control and concludes it operated effectively throughout the year is not providing meaningful assurance.
Re-performance involves the auditor independently repeating the control procedure and comparing the result to what was actually done. It is particularly useful for calculation-based controls, where accuracy of output matters as much as evidence that the process was followed.
Data analytics applied to complete transaction populations can test controls that operate at high volume far more comprehensively than sampling allows. Testing every transaction in a period for the presence of a required approval, or analysing the full payment population for patterns inconsistent with the control framework, identifies exceptions that sample-based testing would not reliably detect.
When control testing identifies a problem, the severity of the finding determines the appropriate response. The COSO Framework and the PCAOB's standards both use a consistent classification.
A control deficiency exists where the design or operation of a control does not allow timely prevention or detection of a misstatement or failure. Not all deficiencies are equally serious. A control that failed once in unusual circumstances is different from a control that fails routinely.
A significant deficiency is a control deficiency, or combination of deficiencies, that is important enough to merit attention by those responsible for oversight. It falls short of a material weakness but warrants communication to senior management and the audit committee.
A material weakness is a deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement or significant loss would not be prevented or detected on a timely basis. Material weaknesses require immediate escalation, executive ownership, and board visibility.
The test of whether findings are being taken seriously is what happens after they are reported. Findings tracked to genuine resolution, with independent verification that remediation has been effective, indicate a governance culture that takes control effectiveness seriously. Findings acknowledged in writing and then left unaddressed indicate the opposite.