5.5 Evaluating Design & Implementation of Controls

Key Takeaways

  • Under AU-C Section 315 (SAS 145), every audit requires an understanding of the components of internal control and, for identified controls, an evaluation of design and implementation.
  • Evaluating design determines whether a control is capable of preventing or detecting material misstatements; evaluating implementation determines whether the control exists and is actively in use. Implementation does not equal operating effectiveness.
  • Inquiry alone is never sufficient to evaluate control design and implementation; the auditor must corroborate inquiries with observation, inspection of documents, and transaction walkthroughs.
  • Testing the operating effectiveness of controls is required when the auditor plans to rely on controls to assess control risk below maximum, or when substantive procedures alone cannot provide sufficient appropriate audit evidence (highly automated environments), as required by AU-C 330.
  • Under AU-C Section 265, Significant Deficiencies and Material Weaknesses must be communicated in writing to Those Charged With Governance (TCWG) and management; auditors are strictly prohibited from issuing a written report stating that no significant deficiencies were identified.
Last updated: September 2026

5.5 Evaluating Design & Implementation of Controls

Core Auditing Principle: Under GAAS (AU-C Section 315 / SAS 145), the auditor must obtain an understanding of the system of internal control in every engagement and, for identified controls, evaluate design and determine whether controls have been implemented. Understanding internal control is mandatory even if the auditor intends to assess control risk at maximum and perform an entirely substantive audit. Candidates must master the distinction between design, implementation, and operating effectiveness, walkthrough mechanics, documentation tools, and deficiency reporting under AU-C Section 265.


1. The Mandatory Responsibility to Understand Internal Control

Every financial statement audit performed under GAAS requires the auditor to understand the components of the entity's system of internal control. Within the control activities component, SAS 145 focuses the work on identified controls:

  • Identified controls (SAS 145): The auditor identifies (1) controls that address significant risks, (2) controls over journal entries, including nonstandard entries, (3) controls whose operating effectiveness the auditor plans to test, including controls over risks for which substantive procedures alone cannot provide sufficient evidence, and (4) other controls the auditor judges appropriate. For these controls, the auditor also identifies the IT applications and risks arising from IT that affect them, and the related general IT controls.
  • Controls outside that focus: Controls that relate only to operational efficiency (for example, factory break schedules) usually are not identified controls.

Exam Rule: The auditor cannot skip obtaining an understanding of internal control on the grounds that the client is small, or because the auditor plans to perform 100% substantive testing. Obtaining an understanding is an unconditional requirement.


2. The Critical Triad: Design vs. Implementation vs. Operating Effectiveness

A central source of confusion on the CPA exam is the boundary separating design evaluation, implementation determination, and tests of operating effectiveness:

+-------------------------------------------------------------------------+
|                   THE INTERNAL CONTROL EVALUATION TRIAD                 |
|                                                                         |
|   [ 1. CONTROL DESIGN ]       --> Is the control capable of preventing   |
|   (Risk Assessment / Plan)        or detecting material misstatement?   |
|               |                                                         |
|               v                                                         |
|   [ 2. IMPLEMENTATION ]       --> Does the control exist and is the     |
|   (Risk Assessment / Plan)        entity actually using it right now?   |
|               |                                                         |
|               v                                                         |
|   [ 3. OPERATING EFFECTIVENESS] -> Did the control operate consistently  |
|   (Further Audit Procedures)      throughout the ENTIRE audit period?   |
+-------------------------------------------------------------------------+

1. Evaluating Control Design

Evaluating the design of a control involves determining whether the control, individually or in combination with other controls, is capable of effectively preventing, or detecting and correcting, material misstatements in financial statement assertions.

  • If a control is poorly designed (e.g., a credit check control where the sales clerk performs their own credit approval without established dollar limits), it cannot mitigate risk regardless of how faithfully it is executed.

2. Determining Control Implementation

Determining implementation involves establishing that the control exists and that the entity is actively using it.

  • An entity may possess a beautifully written internal control manual outlining daily inventory reconciliations. However, if the warehouse staff has not performed a reconciliation all year, the control is designed but not implemented.

3. Testing Operating Effectiveness

Testing operating effectiveness involves gathering audit evidence regarding how the control was applied during the period under audit, the consistency with which it was applied, and by whom or by what means it was applied.

  • Crucial Boundary: Evaluating design and implementation occurs during the planning / risk assessment phase across all audits. Testing operating effectiveness occurs during the further audit procedures phase and is performed only when the auditor plans to rely on controls or is mandated to do so.

Exam Trap: Confirming that a control is implemented does not mean the control is operating effectively! Implementation verifies that the control was in place at a point in time (e.g., during a single walkthrough). Operating effectiveness proves that the control functioned reliably over the entire 12-month fiscal period.


3. Procedures to Evaluate Design and Implementation: The Power of Walkthroughs

Why Inquiry Alone Is Never Sufficient

Under AU-C Section 315, inquiry of entity personnel alone is NEVER sufficient to evaluate the design or determine the implementation of internal controls. An employee can easily tell an auditor that they review invoices every morning, but verbal statements provide zero corroborative proof.

To evaluate design and implementation, the auditor must combine inquiry with:

  1. Observation: Watching client personnel apply the control in real time (e.g., watching a supervisor count physical cash drawers or match packing slips).
  2. Inspection of Documentation: Examining internal audit reports, exception logs, signed reconciliation forms, or system configuration parameter screens.
  3. Walkthroughs: Tracing a transaction from origination to financial reporting.

Walkthrough Procedures and Execution

A walkthrough is widely considered the most effective procedure to confirm the auditor's understanding of internal control:

  • The auditor selects a single transaction and traces it step-by-step through the entire information system, from its initial origination (e.g., receipt of a customer sales order), through authorization, processing, and recording in subsidiary ledgers, to its ultimate posting in the general ledger and inclusion in the financial statements.
  • During a walkthrough, the auditor inquires of personnel involved at each processing step, observes operations, and inspects the specific electronic or paper artifacts created along the way.
  • Walkthrough Objectives: Confirm the accuracy of flowcharts/narratives, evaluate control design, verify implementation, and identify specific points in the process where material misstatements could occur.

4. Documenting the Understanding of Internal Control

The auditor must document the understanding obtained of the entity's internal control components. The four primary documentation methods are:

+-------------------------------------------------------------------------+
|                    CONTROL DOCUMENTATION TECHNIQUES                     |
|                                                                         |
|   1. FLOWCHARTS               2. INTERNAL CONTROL QUESTIONNAIRES (ICQs) |
|   (Visual process mapping)    (Comprehensive Yes/No checklists)         |
|                                                                         |
|   3. NARRATIVES / MEMORANDA   4. DECISION TABLES / LOGIC TREES          |
|   (Written prose walkthrough) (Matrix of conditions and actions)        |
+-------------------------------------------------------------------------+
MethodCore CharacteristicsAdvantages / StrengthsDisadvantages / Limitations
1. FlowchartsGraphic/symbolic representation of systems, document flows, processing steps, and departmental boundaries.Excellent visual depiction of document flows and segregation of duties; makes it easy to spot control gaps or bottlenecks.Time-consuming to draft and update; requires specialized charting skills.
2. Internal Control Questionnaires (ICQs)Standardized lists of pre-printed questions covering specific control objectives (typically answered "Yes", "No", or "N/A").Comprehensive coverage; difficult for an auditor to overlook a critical control step; "No" answers instantly highlight deficiencies.Can encourage a mechanical checklist mentality ("Yes-itis"); inflexible for unusual client processes.
3. Narratives / MemorandaWritten step-by-step description of an accounting system, transaction flow, and related controls.Highly flexible and detailed; ideal for simple, straightforward systems with few processing steps.Cumbersome and difficult to read for complex ERP environments; easy to miss subtle segregation of duties gaps.
4. Decision TablesTabular matrix mapping complex business conditions to specific control actions or authorization levels.Clearly demonstrates multi-variable logic (e.g., credit approval tiers based on order size and credit score).Limited in scope; does not illustrate physical document flow.

5. Determining the Further Audit Strategy: When Are Tests of Controls Mandatory?

After evaluating control design and implementation, the auditor makes a strategic decision regarding control risk:

+-------------------------------------------------------------------------+
|                   CONTROL RISK ASSESSMENT DECISION TREE                 |
|                                                                         |
|   Evaluate Control Design & Implementation                              |
|                      |                                                  |
|       +--------------+--------------+                                   |
|       v                             v                                   |
|   [Controls Deficient /        [Controls Well-Designed & Implemented]   |
|    Inefficient to Test]                     |                           |
|       |                                     v                           |
|       v                       Do you plan to rely on controls           |
|   Assess Control Risk (CR)    to reduce Substantive Testing?            |
|   at MAXIMUM                                |                           |
|       |                             +-------+-------+                   |
|       v                             v (Yes)         v (No)              |
|   Perform 100%                 [TEST CONTROLS]   Assess CR at MAXIMUM   |
|   SUBSTANTIVE                  Are they operating   Perform 100%        |
|   PROCEDURES                   effectively?        SUBSTANTIVE          |
|                                     |                                   |
|                              +------+------+                            |
|                              v (Yes)       v (No)                       |
|                         Assess CR     Assess CR at MAXIMUM              |
|                         LOW/MEDIUM    Expand Substantive                |
|                         Reduce Sub.   Testing                           |
|                         Testing                                         |
+-------------------------------------------------------------------------+

The Substantive Approach (No Reliance)

The auditor assesses Control Risk at maximum and performs exclusively substantive testing when:

  1. Controls are poorly designed or not implemented, OR
  2. It would be inefficient to test controls (the audit effort required to test operating effectiveness exceeds the substantive testing time saved).

The Reliance Approach (Assessing Control Risk Below Maximum)

The auditor tests the operating effectiveness of controls when the auditor plans to rely on controls to justify a reduced assessment of control risk (below maximum), thereby reducing the nature, timing, or extent of substantive testing.

When Are Tests of Controls MANDATORY Under GAAS?

There are two situations where tests of controls are strictly mandatory:

  1. When Planning to Rely on Controls: If the auditor intends to assess control risk below maximum, testing controls is mandatory. An auditor cannot assess control risk low based solely on an understanding of design and implementation!
  2. Highly Automated IT Environments: When substantive procedures alone cannot provide sufficient appropriate audit evidence. In highly automated electronic commerce environments (e.g., electronic data interchange, algorithmic order processing) where transactions are initiated, authorized, processed, and recorded entirely electronically without generating a physical paper trail, it is impossible to verify balances through substantive testing alone. Under AU-C Section 330, the auditor must perform tests of controls over the relevant automated systems.

6. Deficiency Classification & Governance Reporting (AU-C Section 265)

During the audit, the auditor often identifies deficiencies in internal control. Under AU-C Section 265 (Communicating Internal Control Related Matters Identified in an Audit), deficiencies are categorized into a three-tier hierarchy based on likelihood and magnitude:

+-------------------------------------------------------------------------+
|                    INTERNAL CONTROL DEFICIENCY HIERARCHY                |
|                                                                         |
|   [ 1. CONTROL DEFICIENCY ]     --> Normal course operation cannot      |
|                                     prevent or detect misstatements     |
|              |                                                          |
|              v                                                          |
|   [ 2. SIGNIFICANT DEFICIENCY ] --> Less severe than material weakness, |
|                                     yet merits attention by TCWG        |
|              |                                                          |
|              v                                                          |
|   [ 3. MATERIAL WEAKNESS ]      --> REASONABLE POSSIBILITY of a         |
|                                     MATERIAL MISSTATEMENT               |
+-------------------------------------------------------------------------+

Detailed Definitions & Evaluation Framework

ClassificationAuthoritative Definition (AU-C 265)Severity ThresholdGovernance Reporting Requirement
1. Control DeficiencyThe design or operation of a control does not allow management or employees, in the normal course of performing their assigned functions, to prevent, or detect and correct, misstatements on a timely basis.Inconsequential; does not rise to the level of a significant deficiency.Written or oral communication to management; governance reporting not required.
2. Significant DeficiencyA deficiency, or a combination of deficiencies, in internal control that is less severe than a material weakness yet important enough to merit attention by those charged with governance (TCWG).Significant, but does not present a reasonable possibility of a material misstatement.Mandatory written communication to TCWG and management.
3. Material WeaknessA deficiency, or a combination of deficiencies, in internal control such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented, or detected and corrected, on a timely basis.Severe; reasonable possibility of material misstatement.Mandatory written communication to TCWG and management.

The Two Evaluation Dimensions

  1. Likelihood: Is there a reasonable possibility that the entity's controls will fail? (Under US auditing standards, "reasonable possibility" encompasses reasonably possible and probable events).
  2. Magnitude: What is the potential dollar misstatement that could occur? Notice that classification depends on the potential magnitude, not whether an actual misstatement has already slipped through!

Written Communication Rules Under AU-C Section 265

  • Mandatory Written Communication: Both Significant Deficiencies and Material Weaknesses must be communicated in writing to Those Charged With Governance (TCWG) and management.
  • Timing of Communication: By the report release date, or no later than 60 days following the report release date.
  • Required Elements of the Written Communication:
    1. Definitions of the terms significant deficiency and material weakness.
    2. A description of the identified deficiencies and an explanation of their potential effects.
    3. A clear statement that the audit purpose was to express an opinion on the financial statements and not to express an opinion on the effectiveness of internal control.
    4. A statement that the auditor's consideration of internal control was not designed to identify all deficiencies that might be material weaknesses or significant deficiencies.
    5. A restricted-use paragraph indicating that the communication is intended solely for the information and use of management, TCWG, and specified regulatory authorities.

Strict Exam Prohibition: The auditor may issue a written communication stating that no material weaknesses were identified during the audit. However, the auditor is strictly PROHIBITED from issuing a written communication stating that "no significant deficiencies were identified." Because the auditor does not design procedures to search for all significant deficiencies, giving negative assurance on significant deficiencies is misleading.

Test Your Knowledge

An auditor is performing procedures to evaluate the design and implementation of internal controls over customer billing. Which of the following procedures, on its own, is insufficient to evaluate whether controls have been implemented?

A
B
C
D
Test Your Knowledge

Under AU-C Section 330, under which of the following circumstances is the auditor required to perform tests of the operating effectiveness of internal controls?

A
B
C
D
Test Your Knowledge

An auditor identifies an internal control deficiency where bank reconciliations are prepared two months late and are not reviewed by management. The maximum potential misstatement that could result is less than overall financial statement materiality but exceeds the threshold that merits the attention of those charged with governance. How should the auditor classify this deficiency and what communication is required under AU-C Section 265?

A
B
C
D
Test Your Knowledge

In preparing a written communication to Those Charged With Governance regarding internal control matters identified during an audit under AU-C Section 265, which of the following statements is prohibited from being included in the communication?

A
B
C
D