AA · Professional Level

Internal Controls (Advanced)

IT general controls (access security, program change controls, program development, computer operations) and IT application controls (input, processing, output controls), the distinction between automated and manual controls and their audit implications, entity-level controls, testing controls under ISA 330 (nature, timing, and extent of tests of controls), reliance on the work of internal audit (ISA 610), using the work of an auditor's expert (ISA 620), and auditing entities that use service organisations (ISA 402).

40 min read

Learning Objectives

  • Distinguish between IT general controls and IT application controls and give examples of each
  • Explain the differences between automated and manual controls and their implications for audit testing
  • Describe entity-level controls and explain their significance in the audit
  • Explain the ISA 330 requirements for the nature, timing, and extent of tests of controls
  • Describe the conditions under which the external auditor may rely on the work of internal audit (ISA 610)
  • Explain the requirements for using the work of an auditor's expert (ISA 620)
  • Describe the auditor's considerations when an entity uses a service organisation (ISA 402)

IT General Controls and IT Application Controls

In modern business environments, virtually all financial reporting depends on IT systems. The auditor must understand and evaluate both IT general controls (ITGCs) and IT application controls.

IT General Controls (ITGCs)

ITGCs are controls over the IT environment that support the continued proper functioning of information systems. They operate across ALL applications and underpin the reliability of application controls. If ITGCs are weak, the auditor cannot rely on application controls (because the application might have been improperly changed or accessed).

Four categories of ITGCs:

CategoryPurposeExamples
Access securityEnsure only authorised users can access systems and data — prevents unauthorised access, modification, or deletionUser IDs and passwords, multi-factor authentication, role-based access controls (RBAC), privileged access management, automatic lockout after failed attempts, access logging and monitoring, physical security of server rooms
Program change controlsEnsure that changes to programs/systems are properly authorised, tested, and approved before being moved to the live (production) environmentFormal change request and approval process, separation of development/test/production environments, user acceptance testing (UAT), version control, post-implementation review, rollback procedures
Program development controlsEnsure that new systems and programs are developed according to specifications, properly tested, and meet user requirementsSystem development lifecycle (SDLC) methodology, requirements documentation, design reviews, comprehensive testing (unit, integration, system, UAT), data migration controls, sign-off by business owners
Computer operationsEnsure that systems operate reliably and continuouslyJob scheduling and monitoring, backup procedures (frequency, offsite storage, testing restoration), disaster recovery planning, incident management, system performance monitoring, batch processing controls

IT Application Controls

Application controls are controls embedded within specific applications (software programs) that process transactions. They relate to individual business processes and directly prevent or detect misstatements in transactions.

TypePurposeExamples
Input controlsEnsure that data entered into the system is complete, accurate, and authorisedValidation checks (format, range, reasonableness, check digits), mandatory fields, dropdown menus (restricting input to valid options), duplicate detection, sequence checks, authorisation of input (approval workflows), batch totals and hash totals
Processing controlsEnsure that data is processed correctly and completelyRun-to-run totals (comparing input totals to output totals), exception/error reports, automatic calculations (pricing, tax, discounts), master file update checks, processing sequence controls
Output controlsEnsure that output is complete, accurate, and distributed to authorised recipientsOutput reconciliation (output totals agree to input/processing totals), review of reports for reasonableness, distribution lists (output sent only to authorised users), security of output (encrypted transmission, secure printing)

Relationship between ITGCs and application controls: ITGCs are the foundation. If ITGCs are ineffective (e.g., anyone can access the system, programs can be changed without approval), the auditor cannot rely on application controls — because the application controls themselves may have been bypassed, overridden, or improperly modified. The auditor must evaluate ITGCs FIRST before deciding whether to rely on application controls.

Automated vs Manual Controls

FeatureAutomated controlsManual controls
NatureProgrammed into software — operate consistently every time without human interventionPerformed by a person — require human judgement, action, or review
ConsistencyHighly consistent — once programmed correctly, they operate the same way every time. No risk of human error, fatigue, or bias.Less consistent — subject to human error, fatigue, distraction, collusion, and override.
ExamplesThree-way matching (PO, GRN, invoice automated comparison), input validation checks, automated approval workflows based on rules, automatic posting of recurring journal entriesManagement review of reports, physical inventory counts, bank reconciliations, manual authorisation of payments, review and approval of journal entries
Audit testing implicationsIf ITGCs are effective (the program hasn't been changed improperly), a smaller sample is sufficient for testing — because the control operates identically every time. Test that it was designed correctly and that ITGCs ensure it continued to operate correctly throughout the period.Require larger samples — because the control may not operate consistently. Each instance needs to be individually verified. Need to test throughout the period (not just at one point in time).
Key riskThe program is changed without authorisation (hence the importance of ITGCs: program change controls and access security)Human override, error, or collusion. A person can consciously circumvent a manual control.

Practical implication: When automated controls are effective and supported by strong ITGCs, the auditor can test them with very small samples (often just one or two instances) because the control performs identically every time. Manual controls require much larger samples because each instance depends on human performance.

Entity-Level Controls

Entity-level controls operate across the organisation as a whole — they are not tied to a specific process or transaction cycle. They include elements from the control environment (ISA 315 component 1) and the monitoring process (component 3).

Examples:

  • Governance and oversight: Board/audit committee oversight, tone at the top, code of ethics, whistleblowing policies
  • Risk management: Entity-wide risk assessment process, risk appetite statements
  • Management monitoring: Regular review of financial results against budget, KPI dashboards, variance analysis
  • Internal audit function: Systematic evaluation of controls (see ISA 610 below)
  • HR policies: Competence requirements, background checks, performance evaluation, segregation of duties policies
  • IT governance: IT strategy, security policies, business continuity planning

Audit significance: Entity-level controls influence the overall control environment. Strong entity-level controls (active board oversight, effective internal audit, strong tone at the top) reduce the risk of material misstatement across the board. Weak entity-level controls (poor governance, inadequate monitoring, weak ethical culture) increase risks and may require the auditor to increase the extent of substantive procedures across all areas.

Some entity-level controls are precise enough to prevent or detect material misstatements at the assertion level (e.g., detailed management review of a monthly analytical report). These can be directly tested and relied upon. Others are more indirect (e.g., tone at the top) — they influence the environment but cannot be directly linked to specific assertions.

Testing Controls — ISA 330 Requirements

If the auditor's planned approach involves relying on the operating effectiveness of controls, ISA 330 requires tests of controls that address:

Nature (how the control is tested):

  • Inquiry alone is not sufficient — it must be combined with other procedures
  • Inquiry + observation: Watch the control being performed (e.g., observe the warehouse manager checking delivery notes against the GRN)
  • Inspection: Inspect documentary evidence that the control operated (e.g., check for approval signatures on purchase orders, reconciliation tick marks)
  • Reperformance: Independently re-execute the control procedure (e.g., reperform a bank reconciliation, re-run a three-way match)

Timing (when controls are tested):

  • The auditor should test controls for the entire period of intended reliance (usually the whole financial year)
  • If controls are tested at an interim date (before year-end), the auditor must obtain evidence about significant changes to controls after the interim date and perform additional procedures to extend the conclusions to the period-end (e.g., inquiry, observation, and further testing of controls operating after the interim date)
  • For significant risks: controls must be tested in the current period — the auditor cannot rely on prior year testing
  • For other risks: if the auditor intends to rely on controls tested in a prior period, they must: test a proportion of those controls in each audit (on a rotation basis), and perform procedures to confirm that the controls have not changed since they were last tested (inquiry + observation/inspection). This rotation approach is only appropriate if the controls have not changed and are not related to significant risks.

Extent (sample size for testing):

  • The sample size depends on: how frequently the control operates (daily, weekly, monthly, annually), the desired level of assurance, the assessed risk, and whether the control is automated or manual
  • Automated controls: If ITGCs are effective, a very small sample (even 1–2 instances) may suffice because the control operates identically every time
  • Manual controls: Larger samples are needed — the more frequently the control operates, the larger the sample. For daily controls, sample sizes of 20–40 are common; for weekly controls, 5–15; for monthly, 2–5.
  • If deviations (instances where the control did not operate as designed) are found: evaluate the nature and cause, consider the impact on reliance, and potentially increase the sample size or abandon reliance on the control and increase substantive procedures

ISA 610 — Using the Work of Internal Auditors

ISA 610 (Revised 2013) addresses the external auditor's responsibilities regarding the work of the entity's internal audit function.

Two ways the external auditor may use internal audit:

1. Using the work of internal auditors (ISA 610.15-25):

  • The external auditor may use work already performed by internal audit (e.g., their testing of controls, substantive procedures, observations)
  • Before relying on internal audit work, the external auditor must evaluate:
    • Objectivity: Is the internal audit function independent of the operational areas it reviews? Does it report to TCWG or the audit committee? Is it free from management bias?
    • Competence: Do internal auditors have adequate training, qualifications, and experience?
    • Systematic and disciplined approach: Does internal audit follow professional standards (IIA Standards), have quality control, and document its work properly?
  • Even if internal audit work is used, the external auditor must perform sufficient work themselves — they cannot delegate their responsibility for the audit opinion. The external auditor retains sole responsibility for the opinion.
  • Areas of greater judgement or higher risk should be performed directly by the external auditor, not delegated to internal audit

2. Direct assistance from internal auditors (ISA 610.26-35):

  • Internal auditors may provide direct assistance — performing audit procedures under the direction, supervision, and review of the external auditor
  • This is only permitted if not prohibited by law or regulation (note: in the UK, the FRC Ethical Standard generally prohibits direct assistance for PIE audits)
  • If permitted: the external auditor must assess objectivity and competence, provide direction and supervision, review the work performed, and document the nature and extent of internal audit's involvement
  • Direct assistance must NOT be used for areas of significant judgement or significant risk

ISA 620 — Using the Work of an Auditor's Expert

ISA 620 applies when the external auditor uses the work of an expert — an individual or organisation with specialised knowledge in a field other than accounting or auditing (e.g., a property valuer, actuary, geologist, environmental specialist, IT forensics expert, legal specialist).

When is an expert needed? When the audit requires knowledge beyond the auditor's competence — for example: valuing complex financial instruments, assessing environmental liabilities, evaluating mineral reserves, determining the useful life of specialised assets, or assessing pension obligations.

Auditor's expert vs management's expert:

  • Auditor's expert: Engaged by or works for the audit firm. Their work forms part of the audit evidence. ISA 620 applies.
  • Management's expert: Engaged by the entity to help prepare the financial statements (e.g., the actuary who calculates the pension liability). The auditor evaluates the expert's work as part of auditing management's assertions. ISA 500 applies (evaluating evidence).

Requirements when using an auditor's expert (ISA 620):

  • Evaluate competence, capabilities, and objectivity: Does the expert have relevant qualifications and experience? Are they independent of the entity? Any circumstances that might compromise objectivity?
  • Agree the scope and terms: Nature, scope, and objectives of the work, respective roles, communication arrangements, confidentiality requirements
  • Evaluate the adequacy of the expert's work: The auditor must evaluate: the relevance and reasonableness of the expert's findings, the data used (source, completeness, accuracy), the assumptions and methods, and the consistency with other audit evidence
  • The auditor retains responsibility: Using an expert does NOT reduce the auditor's responsibility for the audit opinion. The expert is not mentioned in the audit report (unless required for understanding of a modification or KAM, in which case the report states that mention of the expert does not reduce the auditor's responsibility).

ISA 402 — Audit Considerations for Service Organisations

ISA 402 applies when an entity (the user entity) outsources processes that are relevant to financial reporting to a service organisation. Examples include: outsourced payroll processing, outsourced transaction processing (e.g., credit card processing), outsourced IT hosting (cloud computing), custodian services for investments.

The auditor's responsibilities:

  • The user entity's auditor must obtain an understanding of the nature and significance of the services provided and their effect on the user entity's internal controls
  • If the services are significant: the auditor must obtain sufficient appropriate audit evidence about the design and operating effectiveness of controls at the service organisation

How to obtain evidence about controls at a service organisation:

  1. Type 1 report (SOC 1 / ISAE 3402 Type 1): A report by the service organisation's auditor on the design and implementation of controls at a point in time. Does NOT provide evidence on operating effectiveness.
  2. Type 2 report (SOC 1 / ISAE 3402 Type 2): A report on the design, implementation, AND operating effectiveness of controls over a specified period. More useful — provides assurance that controls actually worked throughout the period.
  3. Direct testing: The user entity's auditor may visit the service organisation and perform their own testing (subject to the agreement with the service organisation).
  4. Alternative procedures: If a Type 1/2 report is not available and direct testing is not possible, the auditor may use: inquiry of the service organisation, inspection of documents, or user entity controls (controls the user entity has over the outsourced process — e.g., reconciliations, output reviews).

Complementary user entity controls: Service organisations often specify controls that the user entity should implement to complement the service organisation's controls (e.g., reviewing output reports, performing reconciliations). The user entity's auditor must evaluate whether these complementary controls are in place and operating effectively.

Sub-service organisations: If the service organisation itself outsources to another organisation (a sub-service organisation), the auditor must consider the inclusive method (the report covers the sub-service organisation) vs the carve-out method (the sub-service organisation is excluded — the user auditor must obtain separate evidence).

Examiner Focus

ITGCs and application controls are tested very frequently. The key insight: ITGCs UNDERPIN application controls. If ITGCs are weak (especially access security and program change controls), the auditor CANNOT rely on automated application controls — because the programs may have been improperly modified. This cascading effect must be explained in your answer.

Common Pitfall

Students often confuse ITGCs with application controls. ITGCs operate across ALL systems (they protect the IT environment itself). Application controls operate within a SPECIFIC application (they process individual transactions). Example: password policy is an ITGC; a three-way match is an application control.

Study Tip

Automated vs manual: automated controls need SMALLER samples (the control performs identically every time IF ITGCs are effective). Manual controls need LARGER samples (human inconsistency). For daily manual controls, expect to test 20-40 instances. For automated controls with effective ITGCs, 1-2 instances may suffice.

Examiner Focus

ISA 610 (internal audit): the external auditor can USE internal audit work or obtain DIRECT ASSISTANCE — but retains SOLE RESPONSIBILITY for the opinion. Before relying: evaluate objectivity (independence from management, reporting line to audit committee), competence (qualifications, experience), and systematic approach (standards, documentation). Areas of significant judgement must be done by the external auditor.

Watch Out

ISA 620 (expert): the auditor retains responsibility — using an expert does NOT reduce the auditor's responsibility. The expert is NOT mentioned in an unmodified audit report. If mentioned in a modified report: the report must state that mention does not reduce the auditor's responsibility. Distinguish auditor's expert (ISA 620) from management's expert (ISA 500).

Study Tip

ISA 402 (service organisations): Type 2 reports are more useful than Type 1 (they cover operating effectiveness over a PERIOD, not just design at a POINT). If no report is available: the auditor may perform direct testing at the service organisation or rely on complementary user entity controls. Don't forget to check whether user entity complementary controls are in place.

Written Practice

Internal Controls (Advanced): Applied Requirement

Prepare a focused written answer with clear workings and justified recommendations.

22 mins · 12 marks

A client has asked for a concise exam-style written response for a client or senior manager on internal controls (advanced). Use the key rules, calculations, risks, and professional judgement from this topic to structure your answer.

Answer Prompts

  • Identify the issue and explain why it matters in the scenario.
  • Apply the relevant technical rule, calculation, or framework.
  • State the commercial, ethical, tax, reporting, or assurance implication.
  • Conclude with a clear recommendation or exam-ready judgement.

Marking Focus

  • Application to facts rather than textbook recall
  • Clear structure and answer-first communication
  • Balanced judgement where there is uncertainty
  • Commercially sensible conclusion

Key Definitions

IT general controls (ITGCs)

Controls over the IT environment that support all applications: access security, program change controls, program development, and computer operations. If ITGCs are weak, application controls cannot be relied upon.

IT application controls

Controls embedded within specific applications that process transactions. Three types: input controls (data entry), processing controls (correct processing), output controls (complete and accurate output).

Automated control

Programmed into software — operates consistently without human intervention. Small samples sufficient for testing (if ITGCs effective). Risk: unauthorised program changes.

Manual control

Performed by a person — requires human judgement and action. Less consistent than automated. Larger sample sizes required for testing. Risk: human error, fatigue, override, collusion.

Entity-level controls

Controls operating across the whole organisation: governance, tone at the top, risk management, management monitoring, internal audit, HR policies. Influence the overall control environment.

Test of controls

An audit procedure to evaluate whether a control operated effectively throughout the period. Nature: inquiry + observation/inspection/reperformance. Timing: test for entire period of reliance. Extent: depends on control frequency and whether automated or manual.

Internal audit function (ISA 610)

An entity's internal assurance function. The external auditor may use their work (evaluate objectivity, competence, discipline) or obtain direct assistance (if not prohibited). The external auditor retains sole responsibility for the opinion.

Auditor's expert (ISA 620)

A person/organisation with specialised knowledge used by the auditor (e.g., valuer, actuary). The auditor evaluates competence, objectivity, and the adequacy of the expert's work. The auditor retains responsibility.

Management's expert

An expert engaged by the entity to help prepare the FS (e.g., actuary for pensions). The auditor evaluates their work as part of auditing management's assertions under ISA 500, not ISA 620.

Service organisation (ISA 402)

A third party that provides services to the entity that are relevant to financial reporting (e.g., outsourced payroll, IT hosting). The auditor must understand the services and obtain evidence on controls.

Type 1 / Type 2 report

Reports from the service organisation's auditor. Type 1: design and implementation at a point in time. Type 2: design, implementation, AND operating effectiveness over a period. Type 2 is more useful.

Complementary user entity controls

Controls the user entity implements to complement the service organisation's controls (e.g., output reconciliations). The auditor must verify these are in place and effective.

Key Formulas

Worked Examples

Key Takeaways

  • ITGCs: four categories — access security, program change controls, program development, computer operations. They underpin ALL application controls. If ITGCs are weak, automated application controls cannot be relied upon.
  • Application controls: input (validation, authorisation), processing (run-to-run totals, exception reports), output (reconciliation, distribution security). Embedded in specific applications to prevent/detect transaction-level misstatements.
  • Automated controls: consistent, small samples sufficient (1-2 if ITGCs effective). Manual controls: inconsistent, larger samples needed (20-40 for daily controls). Automated controls risk: unauthorised program changes. Manual risk: human error, override, collusion.
  • Entity-level controls: governance, tone at the top, risk management, monitoring, internal audit, HR. Strong entity-level controls reduce risk across all areas. Some are precise enough to test directly; others are indirect (influence the environment).
  • Testing controls (ISA 330): nature (inquiry alone is insufficient — combine with observation/inspection/reperformance), timing (test for entire period of reliance; current period for significant risks), extent (sample size depends on frequency, risk, automated vs manual).
  • ISA 610 (internal audit): use work or obtain direct assistance. Evaluate: objectivity, competence, systematic approach. External auditor retains sole responsibility. Significant judgement areas must be done by the external auditor. Direct assistance prohibited for UK PIE audits.
  • ISA 620 (expert): evaluate competence, capabilities, objectivity. Agree scope and terms. Evaluate adequacy of work. Auditor retains responsibility — expert not mentioned in unmodified report.
  • ISA 402 (service organisations): understand services and their effect on controls. Obtain evidence via: Type 2 report (design + operating effectiveness over a period — most useful), Type 1 (design only at a point), direct testing, or alternative procedures. Check complementary user entity controls.

Practice Questions

Question 1 of 8

IT general controls (ITGCs) include all of the following EXCEPT:

Question 2 of 8

If ITGCs are found to be weak, the most likely consequence for the audit is:

Question 3 of 8

When testing an automated control, if ITGCs are effective, the typical sample size is:

Question 4 of 8

Under ISA 610, the external auditor may use the work of internal audit if:

Question 5 of 8

An auditor's expert under ISA 620 differs from a management's expert because:

Question 6 of 8

A Type 2 report from a service organisation's auditor provides assurance on:

Question 7 of 8

For a significant risk, the auditor testing controls must:

Question 8 of 8

Complementary user entity controls are:

Source and Version

Syllabus: ICAEW ACA Professional Level 2026 · Reviewed: 2026-05-04

ICAEW ACA syllabusLocal syllabus coverage review