11.3 Policies, Checklists, Risk-and-Control Questionnaires, and Self-Assessments

Key Takeaways

  • B1b is determining suitable documents for obtaining information: policies, checklists, risk-and-control questionnaires (RCQs), and self-assessment surveys.
  • Policies describe expected design and often serve as evaluation criteria; in the survey you compare them to the live process rather than filing them as proof of operation.
  • Checklists help the auditor cover survey steps (or show how management closes a period); a ticked management checklist is still a claim until independently tested.
  • An RCQ is an auditor-directed set of questions about risks and controls; a management self-assessment is management's own rating of how well those controls work. Both are representations.
  • A completed questionnaire is not sufficient evidence that controls are effective. Independent methods — interviews, observations, walk-throughs, data analysis, and later tests — still have to be performed.
Last updated: August 2026

Documents that inform the survey without finishing the engagement

Quick Answer: B1b asks you to determine suitable documents for obtaining information: policies, checklists, risk-and-control questionnaires, and self-assessment surveys. In the preliminary survey they tell you what should happen, what management says happens, and which corners of the process you must not skip. They cannot replace independent evidence. Filing a completed questionnaire as proof that controls are effective is the classic B1b trap.

B1a was methods you do (talk, watch, walk, scan). B1b is documents you obtain or create so those methods are aimed. The 2025 verb is again determine suitable — pick the document that fits the objective, not a binder of everything the department can print. Chapter 3 already treated written policies as a candidate for evaluation criteria. Here the same policy is a source of information about alleged design. Chapter 12 will decide whether a signed policy, a ticked checklist, or a "yes" on a questionnaire is relevant, sufficient, and reliable as evidence. This section stops at: what is each document for in the survey, and what must still happen after it is in the file.

Policies

A policy (and its procedures, desk aids, and system configuration standards) states the expected design: three-way match before payment, dual approval above $5,000, no shared bank-portal IDs. Survey uses:

  • Learn the alleged process before you interview, so you can hear gaps.
  • Identify criteria you may later use to evaluate conditions (Standard 13.4 / Chapter 3).
  • Spot conflicts (corporate policy vs shared-service desk aid vs what the ERP actually enforces).

Policies do not prove the related controls operated throughout the period. They do not prove the live role design matches the org chart. A beautiful match policy plus a walk-through that posts unmatched invoices is a design story, not comfort. Read the policy, then go to 11.1 and 11.2.

Stale policies are still information. "Last updated 2019" plus an ERP go-live in 2024 is a survey finding-in-waiting: criteria may be obsolete, or the live process may be undocumented. Either way you do not treat the PDF as the process.

Checklists

Checklists come in two flavors, and the exam expects you to know which one you are holding.

Auditor checklists keep the survey complete: subprocesses to walk, people to interview, IPE steps before a scan, Topical Requirement criteria to consider when applicable. They are a project-management and coverage tool (Chapter 6's discipline applied to B1). A blank line on your own checklist is a prompt, not evidence about the auditee.

Management process checklists (month-end close, new-vendor setup, user-access joiners) are documents about the activity. In the survey, obtain the close checklist to see what management claims happens every period. Later, testing whether those ticks are contemporaneous, complete, and performed by the right person is operating-effectiveness work — and IPE work if the checklist is generated from a report. A fully ticked March close packet in the survey file is a claim. It becomes evidence only after you test it.

Do not confuse 2019 language that emphasized developing checklists as a standalone proficient task with the 2025 task, which is determining suitable documents, including checklists. You may still build an auditor checklist. Building one is not a substitute for using the right management documents, and a completed checklist is not a substitute for a walk-through.

Risk-and-control questionnaires versus self-assessments

A risk-and-control questionnaire (RCQ) is an auditor-directed set of questions: what risks exist in this process, what controls address them, who performs them, how often, what evidence is retained, what happens when the control fails. You send it to process owners, plant controllers, or third-party administrators when you need comparable coverage across many locations without flying to each one in week one. Answers populate a first-pass risk-and-control matrix and tell you which walk-throughs are non-negotiable.

An RCQ is inquiry on paper. It has the same limits as a leading interview, plus the extra risk that someone copies last year's answers. Write open items ("describe the override path") rather than only yes/no ("is match always performed?"). Follow every material "yes, duties are segregated" with a live role inspect or RACI, not with a file stamp.

A self-assessment survey (control self-assessment, CSA, or management's control rating) asks management to evaluate design and/or operating effectiveness, often on a scale (effective / needs improvement / ineffective). It is management's grade, not the auditor's. Survey uses: see where management already admits a gap (those gaps still need independent corroboration — an admitted gap can be understated); see where management is confident (those are the places inquiry is most likely to be rosy); gather culture and awareness signals that Chapter 8 taught you to notice.

Risk-and-control questionnaireManagement self-assessment survey
Who drives itInternal audit's questionsManagement's rating of its own controls
Typical contentWhat risks and controls exist, who, when, what evidenceHow well those controls are designed or operating
Survey valueBuilds the alleged risk-control map; comparable across sitesHighlights known gaps and overconfidence
What it isDocumented inquiry / representationDocumented management evaluation / representation
What it is notIndependent evidence of effective controlsIndependent evidence of effective controls

They can be combined in one packet (questions plus a rating column). Combined paper is still paper. The trap does not get smaller because the form is longer.

Blank, "N/A," and refused RCQs are information. Blank often means undocumented. "N/A" on a control you walked yesterday means the owner does not recognize the live process. Refusal is tone, capacity, or both — you switch to interviews and observation; you do not skip the activity because the questionnaire never came back.

Cannot replace independent evidence

Assurance conclusions rest on information the auditor obtained or corroborated through methods in 11.1–11.2 and later tests, judged under Chapter 12. Management representations — interviews, RCQs, CSA scores, signed policies, ticked close checklists — can direct that work. They cannot be that work when the objective is to evaluate controls.

Suitable survey sequence:

  1. Read policies and last period's close checklist (alleged design and claimed operation).
  2. Issue an RCQ to the five plant controllers; issue a short CSA rating if the function uses CSA.
  3. Walk through one item at a high-volume plant and one at a plant that rated itself "fully effective."
  4. Scan duplicates and weekend postings (11.2) against the live file, not against the questionnaire's yes/no column.
  5. Refine the work program. Keep the questionnaires in the file as sources that were followed up, not as the effectiveness conclusion.

If the CSA says all 12 key controls are effective and the walk-through shows one user ID completing both match and override, you believe the live path for planning purposes. You do not average the CSA and the walk-through into "partially effective" and stop.

Loading diagram...
B1b documents inform the survey; independent methods still follow
Illustrative split: CSA ratings versus independent follow-up still required

Worked example: five-plant AP survey

Corporate AP policy requires three-way match and dual approval above $5,000. You send an RCQ to five plant controllers and a one-page CSA. Four RCQs come back with "match always performed." Plant 3 does not return the form. All four respondents rate controls effective. The month-end checklist at Plant 1 is fully ticked for twelve months.

Suitable next documents-and-methods mix: walk Plant 1 (the confident, complete-checklist plant) and Plant 3 (the silent plant); inspect live ERP roles against the policy's dual-approval rule; scan duplicates across all five company codes after IPE. If Plant 1's ticked checklists were all signed the week internal audit announced the engagement, that timing is a reliability issue for Chapter 12 — and a survey reason not to treat the packet as period evidence.

Unsuitable next step: file the four RCQs, the CSA scores, the policy, and the ticked checklists, conclude AP controls are effective at four plants, and schedule no tests at Plant 3 "because they did not participate."

Exam traps

  • Filing a completed RCQ or CSA as sufficient evidence of effective controls.
  • Treating a written policy as proof of operating effectiveness.
  • Treating a management close checklist as tested because every box is ticked.
  • Equating RCQ with CSA (questions about what exists versus management's grade) or calling either independent.
  • Using only yes/no RCQ items that lead the owner the same way a leading interview does.
  • Skipping a location that did not return the questionnaire.
  • Drifting into Chapter 12's relevance / sufficiency / reliability criteria as if they were the B1b task, or into Part 3 final-report attributes because a CSA score looks like an audit rating.

B1b is complete when the file shows which documents you used, what they claimed, and which independent procedures those claims triggered. The questionnaire is a map. It is not the territory.

Test Your Knowledge

A process owner returns a completed risk-and-control questionnaire stating all 12 key controls are effective. What should the auditor do?

A
B
C
D
Test Your Knowledge

What is the best distinction between a risk-and-control questionnaire and a management self-assessment survey?

A
B
C
D
Test Your Knowledge

In a preliminary survey, what is the primary use of written policies?

A
B
C
D