AS · Certificate Level
Internal Controls
The components of internal control under the COSO framework (control environment, entity's risk assessment process, information system and communication, control activities, monitoring of controls), control objectives and typical controls for each major transaction cycle (revenue/receivables, purchases/payables, payroll, inventory, cash and bank), the distinction between tests of controls and substantive procedures, methods of recording and evaluating internal controls (internal control questionnaires, flowcharts, narrative notes), and communicating internal control deficiencies to management and those charged with governance.
Learning Objectives
- •Explain the purpose and inherent limitations of a system of internal control
- •Describe the five components of internal control under the COSO framework as adopted in ISA 315
- •Identify control objectives and give examples of typical controls for the revenue, purchases, payroll, inventory, and cash cycles
- •Distinguish between tests of controls and substantive procedures and explain when each is appropriate
- •Describe methods of recording internal controls: internal control questionnaires (ICQs), flowcharts, and narrative notes
- •Explain the auditor's responsibilities for communicating internal control deficiencies to management and those charged with governance under ISA 265
Purpose and Limitations of Internal Controls
A system of internal control is the set of policies, procedures, and processes designed by management (and those charged with governance) to provide reasonable assurance that the entity's objectives are achieved in the following categories:
- Reliability of financial reporting: Financial statements are prepared reliably and in accordance with the applicable framework
- Effectiveness and efficiency of operations: Operations are conducted in an orderly and efficient manner
- Compliance with applicable laws and regulations: The entity adheres to laws, regulations, and internal policies
- Safeguarding of assets: Assets are protected from loss, theft, or unauthorised use
Inherent limitations of internal control:
No system of internal control can provide absolute assurance. Limitations include:
- Human error: Mistakes in judgement, misunderstandings, fatigue, carelessness
- Management override: Senior management can override controls they themselves established — this is a key fraud risk (ISA 240)
- Collusion: Two or more individuals working together can circumvent controls (e.g., segregation of duties is defeated if the people involved collude)
- Cost vs benefit: Controls must be economically justifiable — the cost of a control should not exceed the benefit of the risk it mitigates
- Unusual or unforeseen transactions: Controls are typically designed for routine, recurring transactions. Non-routine or unexpected transactions may not be adequately controlled
- Obsolescence: Controls may become outdated as processes, systems, or the business environment change
The COSO Framework — Five Components of Internal Control
ISA 315 (Revised 2019) requires the auditor to obtain an understanding of the entity's system of internal control. The framework is based on the COSO Internal Control — Integrated Framework (Committee of Sponsoring Organizations of the Treadway Commission). It identifies five interrelated components:
1. The Control Environment
The control environment is the foundation of the entire internal control system. It sets the tone of the organisation and influences the control consciousness of its people. Key elements include:
- Commitment to integrity and ethical values: Management's attitude towards ethical conduct — is there a code of ethics? Is it enforced? Does management lead by example?
- Governance structure: The oversight role of those charged with governance (e.g., the board of directors, audit committee). Active, independent oversight strengthens the control environment.
- Organisational structure: Lines of authority and responsibility. Are roles and reporting lines clearly defined?
- Commitment to competence: Recruitment, training, and retention policies. Are employees qualified for their roles?
- Accountability: Performance evaluation and incentive structures. Do they encourage appropriate behaviour or create perverse incentives (e.g., aggressive revenue targets that encourage manipulation)?
- Human resource policies: Policies for hiring, training, evaluation, promotion, compensation, and remediation
A strong control environment reduces the risk of fraud and material misstatement. A weak control environment (e.g., dominant CEO who overrides controls, lack of audit committee, insufficient segregation of duties) significantly increases risk — the auditor must respond by increasing the extent of substantive testing.
2. The Entity's Risk Assessment Process
This is the entity's own process for identifying and assessing risks relevant to its objectives, including risks of material misstatement of the financial statements. The auditor evaluates whether management has a process for:
- Identifying business risks relevant to financial reporting objectives
- Estimating the significance and likelihood of those risks
- Deciding how to manage the risks (accept, mitigate, transfer, avoid)
If the entity has no formal risk assessment process (common in smaller entities), the auditor must discuss with management how business risks are identified and addressed, even informally.
3. The Information System (Including Business Processes) and Communication
The information system encompasses the procedures and records that:
- Initiate, record, process, and report the entity's transactions
- Maintain accountability for assets, liabilities, and equity
- Resolve incorrect processing of transactions
- Process and account for system overrides or bypasses of controls
- Transfer information from transaction-processing systems to the general ledger
- Capture information relevant to financial reporting for events and conditions other than transactions (e.g., estimates, fair value measurements)
Communication involves ensuring that all personnel understand their roles within the internal control system and how their activities relate to others' work. Management communicates responsibilities clearly (policies, procedures manuals, job descriptions) and establishes channels for reporting exceptions and irregularities.
4. Control Activities
Control activities are the specific policies and procedures that help ensure management's directives are carried out and that necessary actions are taken to address risks. They operate at all levels and across all functions. Major categories:
- Authorisation: Transactions are approved by appropriate personnel before processing. Higher-value transactions require higher-level authorisation.
- Segregation of duties: No single individual should control all aspects of a transaction. The key functions that should be separated are:
- Authorisation (approving a transaction)
- Custody (physical possession of the asset)
- Recording (entering the transaction in the accounting records)
- Physical controls: Safeguarding assets through locks, security cameras, restricted access, safes, security guards, password-protected systems
- Reconciliations: Regular comparison of one set of records with another — e.g., bank reconciliation (cash book to bank statement), receivables ledger to control account, physical inventory count to book records
- Arithmetic and accounting checks: Checking calculations, checking sequential numbering of documents (to detect omissions), checking batch totals
- Performance reviews: Comparing actual results to budgets, forecasts, or prior periods and investigating variances
- Information processing controls: Application controls (input, processing, output controls) and general IT controls (access security, program change controls, backup and recovery)
5. Monitoring of Controls
Monitoring assesses the quality of the internal control system over time. It determines whether controls are operating as intended and are modified as needed for changes in conditions.
- Ongoing monitoring: Built into normal recurring activities — supervisory review, management review of reports and exceptions, reconciliations performed as part of routine processing
- Separate evaluations: Periodic assessments such as internal audit reviews, self-assessments, external regulatory inspections
- Internal audit function: An independent appraisal function within the entity that examines and evaluates internal controls. Where a robust internal audit function exists, the external auditor may be able to place reliance on its work (ISA 610).
The results of monitoring should be reported to management and, where significant, to those charged with governance. Identified deficiencies should be corrected promptly.
Control Objectives and Typical Controls by Transaction Cycle
Each major transaction cycle has specific control objectives — what the controls are designed to achieve. Exam questions frequently ask you to identify control objectives and recommend controls for a given cycle.
Revenue and Receivables Cycle
Control objectives: Goods/services are only supplied to approved customers on authorised terms; all sales are recorded accurately, completely, and in the correct period; receivables are collected promptly and write-offs are authorised.
Typical controls:
- Credit checks on new customers before granting credit terms; credit limits set and monitored
- Customer orders authorised before goods are dispatched
- Sequentially pre-numbered sales invoices and dispatch notes — sequence checked for completeness
- Matching of goods dispatch notes (GDNs) to sales invoices to ensure all dispatched goods are invoiced
- Segregation of duties: the person raising invoices should not also receive cash or record the transactions in the ledger
- Regular reconciliation of the receivables ledger to the receivables control account
- Aged receivables reviews — management follow-up of overdue balances
- Write-offs of irrecoverable debts authorised by a senior person independent of the receivables function
- Cut-off procedures at period end to ensure sales are recorded in the correct period
Purchases and Payables Cycle
Control objectives: Purchases are made only for authorised business purposes from approved suppliers; all purchases are recorded accurately, completely, and in the correct period; payments are made only for goods/services received.
Typical controls:
- Approved supplier list maintained and reviewed periodically
- Purchase orders (POs) required for all purchases above a threshold, authorised by appropriate personnel
- Goods received notes (GRNs) completed on receipt of goods, signed by the receiving department
- Three-way matching: Purchase order, GRN, and supplier invoice matched before payment — ensures only genuine, authorised purchases of goods actually received are paid for
- Segregation of duties: the person ordering goods should not also receive them or authorise payment
- Sequential numbering of POs, GRNs, and payment vouchers — checked for completeness
- Regular reconciliation of the payables ledger to the payables control account and to supplier statements
- Payments authorised by someone independent of the ordering/receiving functions
- Cheque signatories or electronic payment approval by at least two authorised individuals for large payments
Payroll Cycle
Control objectives: Payments are made only to bona fide employees for work actually performed; payroll is calculated accurately (gross pay, deductions, net pay); all payroll transactions are recorded completely and accurately.
Typical controls:
- HR department maintains the payroll master file — additions (new starters), amendments (pay changes), and deletions (leavers) authorised by a person independent of payroll processing
- Timesheets or clock cards approved by supervisors before processing
- Segregation between HR (maintaining employee records), payroll department (processing payroll), and finance/treasury (making payments)
- Independent check of the payroll by someone not involved in its preparation (e.g., comparison of total payroll to prior month, investigation of significant changes)
- Exception reports for unusual items — overtime above a threshold, new starters, large one-off payments
- Bank reconciliation for the payroll bank account
- Restriction of access to payroll systems to authorised personnel only
Inventory Cycle
Control objectives: Inventory is safeguarded from loss, theft, or damage; inventory records are accurate and complete; inventory is valued correctly (lower of cost and NRV).
Typical controls:
- Restricted physical access to warehouses and storage areas
- Regular physical inventory counts (full count at least annually, or continuous/cycle counting throughout the year)
- Independent reconciliation of physical count results to book records — investigation and adjustment of discrepancies
- Goods inwards and goods outwards procedures with documentation (GRNs, dispatch notes)
- Perpetual inventory records maintained and updated for all receipts and issues
- Obsolete, slow-moving, or damaged inventory identified and separately reported for NRV assessment
- Segregation between those authorising purchases/sales, those handling inventory, and those recording inventory transactions
Cash and Bank Cycle
Control objectives: Cash is safeguarded; all cash receipts are recorded and banked promptly; all payments are authorised and for legitimate business purposes; bank balances are accurately recorded.
Typical controls:
- All cash receipts recorded immediately in the cash book, with receipts issued to the payer
- Cash banked daily and intact (no paying expenses from cash receipts — "teeming and lading" prevention)
- Segregation of duties between those handling cash, those recording cash, and those performing bank reconciliations
- Bank reconciliation prepared regularly (at least monthly) by someone independent of the cash handling function, and reviewed by a supervisor
- Cheque signatories or electronic payment authorisation by at least two individuals for amounts above a threshold
- Petty cash on an imprest system with regular reconciliation
- Restricted access to online banking systems with strong password controls and audit trails
- Blank cheques kept securely; cancelled cheques retained and not destroyed
Tests of Controls vs Substantive Procedures
The auditor uses two broad categories of audit procedure to respond to assessed risks:
1. Tests of controls
- Purpose: To evaluate the operating effectiveness of the entity's internal controls in preventing or detecting and correcting material misstatements
- When performed: When the auditor's risk assessment assumes controls are operating effectively (i.e., the auditor plans to rely on controls to reduce the extent of substantive testing), or when substantive procedures alone are not sufficient
- Examples: Reperforming a bank reconciliation prepared by the client; checking that a sample of purchase orders bear an authorised signature; observing that segregation of duties is maintained in the cash receipts process; testing IT access controls
- Outcome: If controls are found to be effective → the auditor can reduce the extent of substantive procedures. If controls are found to be ineffective → the auditor must perform more extensive substantive procedures (and reassess the risk assessment).
2. Substantive procedures
- Purpose: To detect material misstatements at the assertion level — i.e., to test whether the financial statement amounts and disclosures are correct
- Two types:
- Tests of details: Testing individual transactions, balances, or disclosures (e.g., inspecting invoices, confirming receivables, recalculating depreciation, attending the inventory count)
- Substantive analytical procedures: Evaluating financial information through analysis of relationships and trends to identify unexpected amounts (e.g., proof in total of payroll costs, comparison of revenue month by month)
- When performed: Always — ISA 330 requires the auditor to design and perform substantive procedures for every material class of transactions, account balance, and disclosure, regardless of the assessed risk level and regardless of whether the auditor relies on controls
The relationship between the two:
| Controls assessment | Tests of controls | Substantive procedures |
|---|---|---|
| Strong controls, plan to rely | Yes — test controls first | Reduced extent (but still required) |
| Weak controls / no reliance planned | No (or limited) | Extensive — full substantive testing |
This is the combined approach (tests of controls + reduced substantive) vs the fully substantive approach (substantive only, no reliance on controls).
Methods of Recording Internal Controls
The auditor must document their understanding of the entity's internal controls. Common methods include:
1. Internal Control Questionnaires (ICQs)
- A series of predetermined questions about the existence and operation of controls, typically with "Yes / No / N/A" answers
- A "Yes" answer indicates a control exists; a "No" answer indicates a potential weakness
- Advantages: Systematic and comprehensive (ensures no area is overlooked), easy to complete, provides a structured record, facilitates comparison year on year
- Disadvantages: Can become a "tick box" exercise without genuine understanding, may not capture the nuances of the actual system, may not identify controls that exist but are not asked about
2. Flowcharts
- A diagrammatic representation of the flow of documents and processes within a transaction cycle, using standardised symbols
- Shows the sequence of operations, decision points, documents generated, controls applied, and the flow between departments
- Advantages: Provides a clear visual overview of the system, easy to identify where controls exist (and where they are missing), particularly useful for complex systems, helps identify segregation of duties issues
- Disadvantages: Time-consuming to prepare, requires skill to draw accurately, can become complex for large systems, may not capture all details
3. Narrative notes (written descriptions)
- A written description of the system in prose form, describing the procedures, documents, and controls in sequence
- Advantages: Flexible, easy to prepare for simple systems, provides detail and context that diagrams may miss
- Disadvantages: Can be lengthy and hard to follow for complex systems, difficult to identify gaps or weaknesses at a glance, less visual than flowcharts
In practice, auditors often use a combination of these methods — e.g., flowcharts for the main transaction cycles supplemented by narrative notes for non-standard procedures.
Communicating Internal Control Deficiencies (ISA 265)
ISA 265 requires the auditor to communicate deficiencies in internal control identified during the audit to the appropriate parties.
Deficiency: A control deficiency exists when:
- A control is designed, implemented, or operated in a way that it is unable to prevent, or detect and correct, misstatements on a timely basis, OR
- A control necessary to prevent, or detect and correct, misstatements is absent
Significant deficiency: A deficiency (or combination of deficiencies) that, in the auditor's professional judgement, is of sufficient importance to merit the attention of those charged with governance. This is a higher threshold than a normal deficiency.
Communication requirements:
| Type of deficiency | Communicate to | Form | Timing |
|---|---|---|---|
| Significant deficiencies | Those charged with governance (e.g., audit committee, board) | Written (mandatory) | On a timely basis |
| Other deficiencies (not significant but worth communicating) | Management at the appropriate level | Written or oral (written is best practice) | On a timely basis |
Content of the written communication:
- A description of each deficiency and an explanation of its potential effects
- Sufficient information for the recipient to understand the context
- A statement that the purpose of the audit was to express an opinion on the financial statements, not to provide a comprehensive review of all internal controls — i.e., the audit may not have identified all deficiencies
- A statement that the communication is intended solely for those charged with governance and management (restricting distribution)
Typically communicated in a management letter (or "letter of weakness" / "report to management"), issued shortly after the audit is completed.
Important: The auditor is not required to search for all deficiencies — only those identified as part of the normal audit process are communicated. However, if the auditor identifies a significant deficiency, they must communicate it even if management is already aware of it.
Examiner Focus
Common Pitfall
Study Tip
Examiner Focus
Watch Out
Common Pitfall
Key Definitions
Internal control
The process designed, implemented, and maintained by management and those charged with governance to provide reasonable assurance about the achievement of objectives regarding reliable financial reporting, effective operations, and compliance with laws.
Control environment
The overall attitude, awareness, and actions of management and governance regarding internal control. Sets the "tone at the top" and is the foundation of the entire control system.
Risk assessment process (entity's)
The entity's own process for identifying, assessing, and managing business risks relevant to its objectives, including risks of material misstatement in financial reporting.
Control activities
Specific policies and procedures that help ensure management directives are carried out and that risks are addressed. Include authorisation, segregation of duties, physical controls, reconciliations, and information processing controls.
Segregation of duties
The principle that no single individual should be responsible for all aspects of a transaction. The three key functions to separate are: authorisation, custody, and recording.
Monitoring of controls
The process of assessing the quality and effectiveness of internal controls over time, through ongoing monitoring activities and/or separate evaluations such as internal audit.
Tests of controls
Audit procedures designed to evaluate the operating effectiveness of controls in preventing, or detecting and correcting, material misstatements. Performed when the auditor plans to rely on controls.
Substantive procedures
Audit procedures designed to detect material misstatements at the assertion level. Include tests of details and substantive analytical procedures. Required for every material item regardless of controls reliance.
Tests of details
Substantive procedures that test individual transactions, account balances, or disclosures — e.g., inspecting invoices, confirming receivables, attending inventory counts.
Substantive analytical procedures
Substantive procedures that evaluate financial information through analysis of plausible relationships to identify unexpected amounts or trends — e.g., proof in total of payroll costs.
Control deficiency (ISA 265)
A condition where a control is designed, implemented, or operated such that it cannot prevent or detect and correct misstatements on a timely basis, or a necessary control is absent.
Significant deficiency
A deficiency (or combination) that, in the auditor's professional judgement, is sufficiently important to merit the attention of those charged with governance.
Internal Control Questionnaire (ICQ)
A series of predetermined questions about the existence and operation of controls, with Yes/No/N/A answers. "No" answers indicate potential weaknesses.
Flowchart
A diagrammatic representation of the flow of documents, data, and processes through a system, using standardised symbols. Shows controls, decision points, and the flow between departments.
Management letter
A written communication from the auditor to management and those charged with governance reporting internal control deficiencies identified during the audit, along with recommendations for improvement.
Three-way matching
A key purchases cycle control: matching the purchase order, goods received note, and supplier invoice before authorising payment. Ensures only genuine, authorised purchases of goods actually received are paid for.
Key Formulas
Worked Examples
Related Topics
Key Takeaways
- ✓Internal controls provide reasonable (not absolute) assurance over reliable reporting, effective operations, legal compliance, and asset safeguarding. Inherent limitations include management override, collusion, human error, and cost constraints.
- ✓The five COSO components: (1) Control environment (tone at the top), (2) Entity's risk assessment process, (3) Information system and communication, (4) Control activities (authorisation, segregation, physical controls, reconciliations, IT controls), (5) Monitoring.
- ✓Segregation of duties: separate authorisation, custody, and recording. The most frequently tested control principle.
- ✓Revenue cycle controls: credit checks, authorised orders, sequentially numbered invoices, matching GDNs to invoices, aged receivables reviews, write-off authorisation.
- ✓Purchases cycle controls: approved supplier list, authorised POs, GRNs, three-way matching (PO + GRN + invoice), reconciliation to supplier statements, dual payment authorisation.
- ✓Payroll controls: independent maintenance of master file, supervisor-approved timesheets, segregation between HR/payroll/treasury, independent payroll review.
- ✓Cash controls: immediate recording and daily banking, segregation of cash handling and recording, independent bank reconciliation, dual signatories, imprest petty cash.
- ✓Tests of controls evaluate whether controls WORK. Substantive procedures test whether NUMBERS ARE CORRECT. Substantive procedures are always required.
- ✓Controls can be documented using ICQs (systematic questions), flowcharts (visual diagrams), or narrative notes (written descriptions). Combination is common.
- ✓ISA 265: significant deficiencies communicated in writing to those charged with governance. Other deficiencies communicated to management. Typically via a management letter.
Practice Questions
Question 1 of 8
Which of the following is NOT one of the five components of internal control under the COSO framework?
Question 2 of 8
The principle that no single individual should control all aspects of a transaction is known as:
Question 3 of 8
Which of the following is an inherent LIMITATION of internal controls?
Question 4 of 8
In the purchases cycle, "three-way matching" involves matching:
Question 5 of 8
Under ISA 265, significant internal control deficiencies must be communicated to:
Question 6 of 8
Tests of controls are performed to evaluate:
Question 7 of 8
Which method of documenting internal controls uses a diagrammatic representation with standardised symbols to show the flow of documents and processes?
Question 8 of 8
Substantive procedures are:
Source and Version
Syllabus: ICAEW ACA Certificate Level 2026 · Reviewed: 2026-05-04