Audit controls and the control audit: testing whether a control is designed properly and whether it actually ran

When people say they are going to audit controls they usually mean they are going to read the control descriptions and agree that they sound sensible. That is half a test, and it is the half that almost never fails. A control audit has two questions in it, and they need different evidence. Design: if this control worked exactly as written, would it prevent or detect the thing it exists to prevent or detect. Operation: did it actually run, every time it should have, over the whole period, and can you show me. A control that is well designed and did not run is a worse outcome than one that is badly designed, because everyone believed it was working.

Testing design: what would have to be true for this to work

Read the control and ask what it depends on. A monthly reconciliation depends on somebody having the two records to reconcile and the authority to act on a difference. An approval control depends on the approver being able to refuse and on the transaction being blocked until they do. A detective control depends on someone reading the output. Write the dependency down, then check it exists. Most design failures are a missing dependency rather than a wrong idea, and they are cheap to find because you never have to look at a single record to find them.

Testing operation: the period, the population and the sample

Operation is tested by sampling, and the sample is only meaningful if you know the population it came from. Ask for the complete list of occasions the control should have run, then sample from that list. If the control was supposed to run monthly, the population is twelve, and testing twelve is not a sample at all, it is a census, which is why frequency-based controls are the easiest to audit and the most embarrassing to fail. High-frequency controls need a real sample drawn across the period, including the busy weeks when controls get skipped.

Compensating controls and the honest version of the phrase

When a control is missing, someone will offer a compensating control. Sometimes that is legitimate: a different control that addresses the same risk to a similar standard, operated by someone else, with its own evidence. Usually it is a description of someone being careful. The test is whether the compensating control produces an artefact when it operates. If nobody can show you anything it produced, it is not a control, it is an intention, and it should be recorded as a gap so that the decision to accept the risk is made deliberately.

Writing the finding so it can be closed

A control finding that says the control is ineffective cannot be closed, because nobody knows what would make it effective. A finding that names the control, the period tested, the population, the sample size, how many exceptions were found and what the exception looked like can be closed, argued with, or accepted. It also survives the handover to whoever runs the next audit, which matters more than it sounds: repeat findings are usually not repeat failures, they are the same failure described differently by two auditors who never compared notes.

Questions people ask about audit controls

What is the difference between design and operating effectiveness?

Design asks whether the control would work if it ran as written. Operation asks whether it ran. A control can pass one and fail the other, and the audit result is different in each case, so the two are tested and reported separately.

How large should a control sample be?

It depends on the population and how often the control runs. Annual and quarterly controls are usually tested in full. For daily or transaction-level controls, pick a sample spread across the period rather than a block, and state the size and method in the working paper so the test can be repeated.

Is a control audit the same as an internal audit?

A control audit is one thing an internal audit does. An internal audit of a process will usually test the controls in it, but it also covers whether the process meets the requirement at all, which is a broader question than whether its controls operate.

What if the control changed halfway through the period?

Test both versions against their own periods and say so in the finding. Treating a changed control as one control produces a result that is true of neither, and it hides the risk window around the change, which is usually where the exceptions are.

Sources

Related answers

Start Capanix ProKeep the findings, not the binder