Internal Controls Evaluation
Controls
Internal Controls Evaluation
Syllabus tag: KASNEB CPA | Advanced Level | CA36 Advanced Auditing and Assurance
1. The COSO 2013 framework
COSO defines internal control as a process providing reasonable assurance regarding objectives in operations, reporting, and compliance. Five components: control environment (tone at the top — management attitude, ethical values, governance); risk assessment (identifying and analysing relevant risks); control activities (authorisation, reconciliation, segregation of duties); information and communication (capturing and communicating relevant information); monitoring activities (ongoing and periodic evaluations of control quality).
2. Types of controls
Preventive controls stop errors before they occur: authorisation, segregation of duties, physical access controls, input validation. Detective controls identify errors after they occur: reconciliations, supervisory review, exception reports, internal audit. Corrective controls remedy problems once detected: error correction, insurance, backups.
Automated vs manual controls: automated IT application controls are generally more reliable — they operate consistently and leave an audit trail. However they depend on IT general controls (GITCs) being effective.
3. Segregation of duties
No single person should have custody of assets, authorisation of transactions, and recording of transactions simultaneously. Separating these functions means fraud requires collusion, making concealment significantly harder.
4. IT general controls (GITCs)
Govern the IT environment: access controls (user authentication, privilege management), change management (testing and approval of system changes), operations controls (backup, recovery, job scheduling), and system acquisition/development controls. Weak GITCs undermine reliance on all application controls.
5. Evaluating controls
Walk-through test: trace one or two transactions from initiation to recording to confirm understanding and identify where controls apply. Tests of controls: obtain evidence controls operated effectively throughout the period — inquiry, observation, inspection, re-performance. Sample sizes depend on control frequency and intended reliance.
6. Reporting control deficiencies — ISA 265
Significant deficiencies in internal control must be communicated to those charged with governance and management. A material weakness is a significant deficiency (or combination) resulting in a reasonable possibility of material misstatement not being prevented or detected.
7. Impact on substantive testing
Effective controls (confirmed by testing) → detection risk set higher → less extensive substantive testing needed. Weak controls → detection risk set lower → more extensive substantive procedures required (larger samples, more year-end testing, more locations).
