5.2 Tests of Controls, Walkthroughs & Evaluating Deficiencies (ISA 265)

Key Takeaways

  • Auditors must distinguish between evaluating control Design and Implementation (D&I) and testing Operating Effectiveness (OE); D&I confirmation does not establish operating effectiveness.

  • A walkthrough test traces a single transaction from initial origination through every processing and accounting step to final financial reporting, identifying points where misstatements could occur.

  • Tests of controls employ four standard procedures—inquiry, observation, inspection, and reperformance—with inquiry alone being legally and methodologically insufficient to support control reliance.

  • ISA 265 and ISSAI 2265 establish a clear hierarchy of deficiencies, requiring significant deficiencies to be communicated in writing to Those Charged With Governance (TCWG).

  • Segregation of duties under the CARR framework (Custody, Authorization, Recording, Reconciliation) is codified in the EU Financial Regulation via the strict separation of Authorising Officers and Accounting Officers.

Last updated: October 2026

5.2 Tests of Controls, Walkthroughs & Evaluating Deficiencies (ISA 265)

Core Principle: An auditor cannot rely on internal controls to reduce substantive testing merely because a control policy exists in an administrative manual. Under International Standard on Auditing (ISA) 315 and ISA 330, the auditor must first evaluate the design and verify the implementation (D&I) of controls. Only if a control is properly designed and implemented may the auditor proceed to test its operating effectiveness (OE) throughout the period of reliance.


1. Design & Implementation (D&I) vs. Operating Effectiveness (OE)

In both commercial audits under ISAs and public sector audits under the ISSAI framework (such as ISSAI 2315 and ISSAI 2330 applied by the European Court of Auditors), testing internal controls is executed in two distinct, sequential phases:

Phase 1: Evaluating Design and Implementation (D&I)

  • Design Evaluation: The auditor evaluates whether the control, individually or in combination with other controls, is capable of effectively preventing, or detecting and correcting, material misstatements at the assertion level. A poorly designed control cannot prevent errors, regardless of how diligently staff execute it.
  • Implementation Evaluation: The auditor verifies that the control actually exists and that the entity is actively utilizing it in practice at a specific point in time.
  • Golden Rule: Evaluating D&I does not provide audit evidence regarding the operating effectiveness of the control over time (except for automated application controls where verified IT general controls ensure unchanged software operation).

Phase 2: Testing Operating Effectiveness (OE)

If the auditor plans to assess control risk as low and rely on the control to restrict the scope of substantive testing, the auditor must test operating effectiveness under ISA 330. Testing OE evaluates:

  1. How the control was applied at relevant times throughout the audit period.
  2. The consistency with which it was applied.
  3. By whom or by what means it was applied.
  4. The rate of deviation from the prescribed control procedure.
                         CONTROL TESTING METHODOLOGY
+-----------------------------------------------------------------------------+
| 1. EVALUATE CONTROL DESIGN                                                  |
|    Is the control theoretically capable of preventing or detecting error?    |
|    --> NO: Record design deficiency; do not test further; perform 100%       |
|            substantive testing.                                             |
|    --> YES: Proceed to implementation check.                                |
+-----------------------------------------------------------------------------+
                                      |
                                      v
+-----------------------------------------------------------------------------+
| 2. VERIFY IMPLEMENTATION                                                    |
|    Does the control actually exist and is it in active operational use?     |
|    (Walkthrough test of one transaction).                                    |
|    --> NO: Record implementation deficiency; do not rely on control.        |
|    --> YES: Proceed to operating effectiveness testing (if relying).        |
+-----------------------------------------------------------------------------+
                                      |
                                      v
+-----------------------------------------------------------------------------+
| 3. TEST OPERATING EFFECTIVENESS (OE)                                        |
|    Did the control operate consistently throughout the entire audit period? |
|    (Sample testing across the year: inspection, observation, reperformance).|
|    --> Deviations found: Reassess control risk to HIGH; expand substantive  |
|                          testing of details.                                |
|    --> Effective: Reduce substantive testing; rely on controls.             |
+-----------------------------------------------------------------------------+

2. Walkthrough Tests: Mechanics and Audit Objectives

A walkthrough test is an often useful audit procedure during the risk assessment and D&I evaluation phases. In a walkthrough, the auditor traces a single transaction from its initial origination at the operational level, through every manual and automated processing stage, through authorization and accounting recording, until it is finally reflected in the financial statements.

Core Objectives of a Walkthrough

  1. Confirm System Understanding: Validates the accuracy of system flowcharts and narrative descriptions documented by the auditor during interviews.
  2. Identify "What Could Go Wrong" (WCGW): Pinpoints the exact operational junctures where transactions could be lost, altered, improperly calculated, or recorded without authorization.
  3. Assess Control Design: Evaluates whether controls positioned at identified risk points are appropriately designed to mitigate risks.
  4. Verify Implementation: Confirms that controls have been put into operation and are not merely theoretical directives in organizational policies.

Execution Technique

A walkthrough requires the auditor to sit with operational personnel, observe them perform their daily routine on live computer terminals, examine the documents generated, and inspect the electronic sign-offs. Simply asking a manager how the system is supposed to work does not constitute a valid walkthrough.


3. The Four Test of Controls Procedures

When testing the operating effectiveness of controls under ISA 330 and ISSAI 2330, auditors draw upon four classic audit procedures, which vary significantly in their evidentiary persuasiveness:

ProcedureNature and ScopeEvidentiary PersuasivenessCritical Audit Limitation
InquirySeeking oral or written information from knowledgeable personnel across the entity.LowestInquiry alone is NEVER sufficient. Must always be corroborated with another procedure.
ObservationWatching personnel execute a control process or procedure in real time.ModerateLimited strictly to the point in time when the observation takes place. Staff may perform flawlessly while observed.
InspectionExamining physical or electronic records, approval signatures, reconciliations, and exception logs.HighVerifies that a sign-off or document exists, but does not definitively prove the reviewer rigorously examined the data.
ReperformanceIndependent execution by the auditor of procedures or controls originally performed by the entity.HighestDemonstrates that the control produces the exact expected result when executed independently. Most time-consuming.

Important Exam Rule: To test operating effectiveness, inquiry must always be combined with inspection, observation, or reperformance. An audit file containing only inquiries of management to support control reliance represents a severe audit failure under ISA 330.


4. Evaluating Control Deficiencies under ISA 265 / ISSAI 2265

When auditors identify weaknesses during control evaluations or substantive testing, they must evaluate their severity and report them in accordance with ISA 265 (Communicating Deficiencies in Internal Control to Those Charged with Governance and Management) and ISSAI 2265.

The Deficiency Severity Hierarchy

  1. Deficiency in Internal Control:
    • Exists when a control is designed, implemented, or operated in such a way that it cannot prevent, or detect and correct, misstatements in the financial statements on a timely basis; OR
    • A control necessary to prevent, or detect and correct, misstatements is missing entirely.
  2. Significant Deficiency:
    • A deficiency or combination of deficiencies in internal control that, in the auditor's professional judgment, is of sufficient importance to merit the attention of Those Charged With Governance (TCWG).
  3. Material Weakness:
    • A term utilized in international practice and US standards (PCAOB Auditing Standard 2201), representing a deficiency or combination of deficiencies such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented, or detected and corrected, on a timely basis. In ISA 265 terminology, material weaknesses fall within the upper severity bracket of significant deficiencies.

Indicators of Significant Deficiencies

ISA 265 identifies explicit red flags that indicate the presence of a significant deficiency:

  • Evidence of an ineffective Control Environment (e.g. management lack of integrity, absence of ethical oversight).
  • Absence of a formalized risk assessment process within an entity exposed to volatile operational environments.
  • Evidence of management override of controls or management fraud.
  • Ineffective response to identified significant risks (e.g. failure to implement controls over high-risk grant payments).
  • Correction of a material misstatement in the current period financial statements that was not initially detected by internal controls.
  • Prior period restatements resulting from failure to detect errors.

5. Mandatory Communication Requirements (ISA 265)

ISA 265 establishes rigid, legally binding communication protocols regarding internal control deficiencies:

Written Communication to Those Charged with Governance (TCWG)

  • The auditor shall communicate in writing significant deficiencies in internal control identified during the audit to Those Charged With Governance on a timely basis.
  • In EU institutions, TCWG corresponds to the Audit Progress Committee (APC), the College of Commissioners, and ultimately the European Parliament's Committee on Budgetary Control (CONT) in the context of the annual discharge procedure.

Communication to Management

  • The auditor shall communicate in writing to management at an appropriate level of responsibility:
    1. Significant deficiencies in internal control (unless it would be inappropriate to communicate directly with management, such as when management integrity is in question).
    2. Other deficiencies in internal control identified during the audit that have not been communicated to management by other parties and that, in the auditor's professional judgment, are of sufficient importance to merit management's attention (may be communicated orally or in writing).

Required Contents of Written Communication

The written communication of significant deficiencies must include:

  1. A clear description of the deficiencies and an explanation of their potential consequences.
  2. Sufficient contextual explanation to enable TCWG and management to understand that:
    • The purpose of the audit was to express an opinion on the financial statements.
    • The audit included consideration of internal control only to design appropriate audit procedures, not to express an opinion on internal control effectiveness.
    • The matters reported are limited to those deficiencies identified during the audit that the auditor concluded were of sufficient importance to report to TCWG.

6. Segregation of Duties: The CARR Framework & EU Financial Regulation

Segregation of duties (SoD) is the primary structural safeguard preventing fraud and error. Under the classic CARR framework, four incompatible organizational functions must be assigned to different individuals:

  • C - Custody of Assets: Physical or electronic access to cash, bank accounts, inventory, or digital payment tokens.
  • A - Authorization: Approving transactions, entering into legal commitments, signing purchase orders, or executing contracts.
  • R - Recording (Accounting): Preparing journal entries, posting vouchers, maintaining general ledgers, and preparing financial statements.
  • R - Reconciliation: Reconciling bank accounts, matching purchase orders to invoices, comparing inventory counts to book records, and conducting independent verification.
                                  THE CARR FRAMEWORK
               +-------------------------------------------------------+
               |                    CARR FUNCTIONS                     |
               +-------------------------------------------------------+
               |  [C] Custody: Physical/electronic control of funds   |
               |  [A] Authorization: Approving contracts & commitments |
               |  [R] Recording: Journal entries & general ledger     |
               |  [R] Reconciliation: Independent verification        |
               +-------------------------------------------------------+
                                           |
               Must be segregated across independent administrative actors
                                           |
                                           v
                        EU FINANCIAL REGULATION CODIFICATION
               +-------------------------------------------------------+
               |  AUTHORISING OFFICER (AOD)   |   ACCOUNTING OFFICER   |
               |  - Budgetary commitments     |  - Payment execution   |
               |  - Legal contracts           |  - Treasury & cash     |
               |  - Validating expenditure    |  - Keeping the books   |
               |  - Issuing recovery orders   |  - Accounting systems  |
               +-------------------------------------------------------+
                                STRICT INCOMPATIBILITY

Separation in the EU Financial Regulation

The CARR label is a teaching mnemonic, not a statutory term. The current Financial Regulation, Regulation (EU, Euratom) 2024/2509, separates authorising and accounting duties and makes them mutually incompatible. Authorising officers manage revenue and expenditure operations within delegated powers; accounting officers execute payments and collection, keep accounts, manage treasury and validate accounting systems under the Regulation.

An audit should map the actual legal delegation and workflow. Segregation reduces the opportunity for one person to initiate, approve, record and execute a transaction, but small teams may need controlled compensating review rather than an impossible ideal structure.

Loading diagram...
ISA 265 Internal Control Deficiency Classification and Communication
Test Your Knowledge

What is the critical audit distinction between evaluating control Design and Implementation (D&I) and testing Operating Effectiveness (OE)?

A

D&I testing evaluates whether controls operated without deviation across the entire year, while OE testing only checks documentation on day one

B

D&I evaluates whether the control as conceived could prevent or detect errors and is in active use, whereas OE evaluates whether the control functioned consistently throughout the period under reliance

C

D&I testing is performed exclusively through reperformance, while OE testing relies solely on inquiry of management

D

D&I testing is mandatory only in private commercial audits, whereas OE testing is required only under ISSAI public sector standards

Test Your Knowledge

What is the primary audit purpose of executing a walkthrough test during the planning phase of an audit engagement under ISA 315?

A

To accumulate sufficient substantive evidence to express a final unmodified audit opinion

B

To replace the requirement for external bank confirmations

C

To trace a single transaction from origination through financial reporting to confirm system understanding and verify control design and implementation

D

To calculate the final materiality and tolerable misstatement thresholds for the financial statements

Test Your Knowledge

Under ISA 265 and ISSAI 2265, which governance protocol is strictly mandatory when an auditor identifies one or more significant deficiencies in internal control?

A

The auditor must notify the local criminal prosecution authorities within 48 hours

B

The auditor must immediately withdraw from the audit engagement without issuing a report

C

The auditor must communicate all deficiencies orally during the final closing conference without formal written records

D

The auditor must communicate the significant deficiencies in writing to Those Charged With Governance on a timely basis

Test Your Knowledge

How is the segregation of duties principle operationalized in the EU Financial Regulation (Regulation 2024/2509) to uphold the CARR control framework?

A

By strictly separating the functions of the Authorising Officer, who commits and validates expenditure, from the Accounting Officer, who executes payments and maintains accounts

B

By allowing the Director-General to execute payments directly provided the internal auditor signs the bank order

C

By transferring custody of all EU bank accounts to private external commercial audit firms

D

By merging the roles of budget authorization and payment execution under a single project manager to maximize administrative speed

Sections you finish are checked off in the contents.