3.1 Internal Control Objectives & COSO / ISA 315 Components

Key Takeaways

  • Internal control is a process designed, implemented, and maintained by those charged with governance, management, and other personnel to provide reasonable assurance regarding the achievement of objectives in financial reporting reliability, operational effectiveness, and regulatory compliance.
  • Under ISA 315 (Revised) and the COSO Internal Control Framework, internal control comprises five components: Control Environment, Risk Assessment Process, Information System & Communication, Control Activities, and Monitoring of Controls.
  • The control environment provides the overarching tone at the top, acting as the foundation for all internal control components; an inadequate control environment creates high risk across all account balances and transaction cycles.
  • Internal controls can only provide reasonable assurance—never absolute assurance—due to inherent limitations such as human error, management override, collusion among employees, and cost-benefit constraints.
  • In Bangladesh, directors of companies incorporated under the Companies Act 1994 hold statutory responsibilities under Section 181 to keep proper books of account and ensure internal accounting controls safeguard corporate assets.
Last updated: August 2026

3.1 Internal Control Objectives & COSO / ISA 315 Components

Internal control forms the backbone of operational discipline and financial integrity in modern business entities. For ICAB Certificate Level candidates, mastering internal control concepts is essential not only for passing audit examinations but also for conducting statutory audits under International Standards on Auditing (ISAs) as applicable in Bangladesh.

Definition and Objectives of Internal Control

According to ISA 315 (Revised), Identifying and Assessing the Risks of Material Misstatement, internal control is defined as the process designed, implemented, and maintained by those charged with governance (TCWG), management, and other personnel to provide reasonable assurance regarding the achievement of an entity's objectives.

These objectives fall into three primary categories:

  1. Reliability of Financial Reporting: Ensuring that financial statements are prepared in accordance with applicable financial reporting frameworks (e.g., International Financial Reporting Standards / IFRS as adopted by ICAB and the Financial Reporting Council of Bangladesh).
  2. Efficiency and Effectiveness of Operations: Ensuring that business operations run smoothly, assets are safeguarded against unauthorized acquisition or disposition, and organizational resources are utilized efficiently.
  3. Compliance with Applicable Laws and Regulations: Ensuring adherence to statutory legislation such as the Bangladesh Companies Act 1994, the Income Tax Act 2023, the Value Added Tax and Supplementary Duty Act 2012, and Bangladesh Bank directives for financial institutions.
CategoryPrimary FocusRelevant StakeholdersAudit Scope Relevance
Financial ReportingAccuracy, completeness, and timeliness of accounting recordsShareholders, ICAB Auditors, RegulatorsCore focus of external audit
OperationsResource utilization, asset safeguarding, operational targetsManagement, Operational Heads, Internal AuditSecondary (evaluated if impacting financial statements)
ComplianceLegal adherence, tax returns, statutory filingsFRC, NBR, RJSC, Bangladesh BankDirect impact on provisions, contingencies, and legal risk

The Five Components of Internal Control (COSO & ISA 315)

Both ISA 315 and the widely recognized Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework structure internal control into five interrelated components. Auditors must evaluate each component to understand how the entity prevents or detects material misstatements.

1. Control Environment

The control environment sets the overall tone of the organization, influencing the control consciousness of its people. It is the foundation for all other components. Key elements include:

  • Tone at the Top: Integrity and ethical values demonstrated by the Board of Directors and senior management.
  • Governance Oversight: Active independence and competence of the Audit Committee and Those Charged With Governance (TCWG).
  • Organizational Structure: Clear lines of authority, responsibility, and reporting channels.
  • Human Resource Policies: Standards for recruiting, training, evaluating, and promoting staff.

Exam Key Point: A weak control environment undermines even the most sophisticated control activities. If senior management bypasses controls, control risk is assessed as high across the entire audit.

2. The Entity's Risk Assessment Process

Management must identify, analyze, and manage business risks relevant to the preparation of true and fair financial statements. The risk assessment process involves:

  • Identifying business risks (e.g., rapid expansion, new product lines, regulatory shifts, IT system migrations).
  • Estimating the significance of identified risks.
  • Assessing the likelihood of risk occurrence.
  • Deciding upon actions to address and mitigate those risks.

If management fails to identify a material risk that the auditor subsequently detects, the auditor evaluates why management's risk assessment process missed the risk and whether a significant deficiency in internal control exists.

3. Information System and Communication

The information system consists of procedures, software, hardware, and records established to initiate, record, process, and report entity transactions. Relevant aspects include:

  • Classes of transactions in the entity's operations that are significant to financial statements.
  • Procedures within both automated and manual systems by which transactions are initiated, recorded, processed, corrected, and transferred to the general ledger.
  • Related accounting records and supporting documentation (e.g., invoices, delivery challans, voucher systems).
  • How the system captures events and conditions other than transactions (e.g., depreciation, asset impairment).
  • Financial reporting processes used to prepare financial statements, including significant accounting estimates and disclosures.

Communication involves providing a clear understanding of individual roles and responsibilities regarding internal control over financial reporting.

4. Control Activities

Control activities are the policies and procedures that help ensure management directives are carried out. They operate at all levels of an entity and include:

  • Authorization and Approvals: Transactions must be executed within management's general or specific authority.
  • Performance Reviews: Management compares actual results against budgets, forecasts, and prior-period performance.
  • Information Processing Controls: Verifications, checks, and reconciliation controls (e.g., batch input totals, system validation controls).
  • Physical Controls: Physical security of assets, cash, inventory, and system access rights.
  • Segregation of Duties (SoD): Dividing responsibilities between transaction authorization, asset custody, recording, and reconciliation.

5. Monitoring of Controls

Monitoring is an ongoing process to assess the design and operation of controls over time and take necessary corrective actions. It encompasses:

  • Ongoing Monitoring: Management's daily operational reviews, supervisory checks, and customer complaint evaluations.
  • Separate Evaluations: Periodic evaluations conducted by the internal audit department or third-party consultants.
  • Internal Audit Function: Evaluating control design and operating effectiveness, reporting directly to the Audit Committee.

Inherent Limitations of Internal Control

Even an exceptionally well-designed internal control system cannot guarantee error-free financial reporting. Internal control provides reasonable assurance, not absolute assurance, due to inherent limitations:

  1. Human Judgment and Error: Decision-making can be faulty, or staff may commit mistakes due to fatigue, carelessness, or lack of training.
  2. Collusion: Two or more individuals working together can deliberately bypass segregation of duties controls (e.g., a purchasing manager colluding with a storekeeper).
  3. Management Override: Management can intentionally override established controls to inflate earnings or misstate financial position.
  4. Cost-Benefit Constraints: The cost of implementing a control should not exceed the expected benefits derived from risk reduction.
  5. Unusual Transactions: Controls are typically designed for routine transactions; non-routine or complex transactions may bypass standard control pathways.

ICAB & Bangladesh Statutory Framework Context

In Bangladesh, statutory provisions mandate corporate governance and internal control mechanisms:

  • Section 181 of the Companies Act 1994: Requires every company to keep proper books of account at its registered office detailing all sums of money received and expended, sales and purchases, and assets and liabilities.
  • Corporate Governance Code (CGC) of the Bangladesh Securities and Exchange Commission (BSEC): Mandates that listed companies maintain an Audit Committee comprising independent directors to review internal control systems and oversee internal audit findings.
  • Banking Companies Act 1991 (Amended 2023): Mandates stringent internal control and compliance (ICC) guidelines issued by Bangladesh Bank for commercial banks.

Summary of ISA 315 Audit Responsibilities

Audit PhaseAuditor's Required Action under ISA 315
Obtaining UnderstandingPerform risk assessment procedures (inquiries, analytical procedures, inspection, observation) to understand all 5 control components.
Evaluating DesignAssess whether controls individually or in combination are capable of effectively preventing or detecting and correcting material misstatements.
Evaluating ImplementationPerform walkthrough tests to confirm that controls have been implemented as designed.
Testing Operating EffectivenessTest operating effectiveness of controls ONLY if planning to rely on controls to reduce substantive procedures, or if substantive procedures alone are insufficient.
Loading diagram...
ISA 315 & COSO Internal Control Components Hierarchy
Test Your Knowledge

Which component of internal control under ISA 315 sets the overall tone of an organization and serves as the foundation for all other components?

A
B
C
D
Test Your Knowledge

Under ISA 315, an auditor evaluates internal controls to obtain reasonable assurance. Why can internal controls NEVER provide absolute assurance?

A
B
C
D
Test Your Knowledge

Under Section 181 of the Bangladesh Companies Act 1994, who carries the primary legal responsibility for establishing and maintaining proper accounting books and internal control records?

A
B
C
D