Internal Control

The processes designed to provide reasonable assurance about reliable reporting, effective operations, and compliance.

AUD items hinge on one rule: obtaining an understanding of internal control is required on every audit, but testing operating effectiveness is optional. When a fact pattern asks what the auditor “must” do, the answer is almost always evaluate the design and determine whether controls are implemented (via inquiry, observation, inspection, and often a walkthrough), not test them. Auditors test controls only when they plan to rely on them, or when substantive procedures alone cannot reduce risk to an acceptably low level (e.g., highly automated, paperless processing). The classic trap: confusing design and implementation (always assessed) with operating effectiveness (tested only on reliance).

Don’t blur internal control with control risk — internal control is the system; control risk is the risk that a material misstatement won’t be prevented, or detected and corrected timely by that system. Controls map to management assertions and the COSO components. COSO mnemonic — CRIME: Control environment, Risk assessment, Information & communication, Monitoring, Existing (control) activities. The control environment is the foundation (“tone at the top”); a weak one taints every other component.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Auditing and Attestation (AUD)