9.1 Control Concepts & Types

Key Takeaways

  • Internal controls are processes designed to provide reasonable assurance that objectives related to operations, reporting, and compliance will be achieved.
  • Controls are commonly classified as preventive, detective, or corrective based on when they act relative to an undesired event.
  • Internal auditors recommend controls that mitigate identified risks proportionately—balancing residual risk, cost, and operational practicality.
  • Financial controls protect the integrity of monetary transactions and reporting; nonfinancial controls protect operations, compliance, safety, quality, and other non-monetary objectives.
  • Segregation of duties separates incompatible functions (authorization, custody, recording, and reconciliation) so one person cannot both perpetrate and conceal an error or fraud.
Last updated: July 2026

9.1 Control Concepts & Types

Quick Answer: Internal controls are the policies, procedures, and activities management designs and operates to provide reasonable assurance that objectives for operations, reporting, and compliance are met. For Syllabus C7, classify controls as preventive, detective, or corrective; recommend controls that mitigate risk; contrast financial vs. nonfinancial examples; and apply segregation of duties basics.

Syllabus C7 sits inside Domain III — Governance, Risk Management, and Control (~30% of the exam). After you can name risks and evaluate responses (C4–C6), you must translate residual-risk gaps into control recommendations that actually reduce likelihood or impact—without claiming perfect assurance.

Purpose of Internal Controls

Internal control is a process, effected by an entity’s board, management, and other personnel, designed to provide reasonable assurance—not absolute assurance—regarding achievement of objectives in three categories commonly used with the COSO Internal Control — Integrated Framework (2013):

  1. Operations — effectiveness and efficiency of operations, including safeguarding of assets.
  2. Reporting — reliability, timeliness, and transparency of internal and external financial and nonfinancial reporting.
  3. Compliance — adherence to laws, regulations, and binding policies the entity has adopted.

Why “reasonable” assurance? Controls have cost, human judgment fails, collusion can defeat segregation, and management can override. Internal auditors who promise zero residual risk misunderstand both control theory and board expectations.

Controls exist to mitigate risk relative to objectives. A control without a linked risk and objective is busywork. A risk without a proportionate control (or documented acceptance) is unmanaged exposure. On the IAP, stems often ask whether a proposed control addresses the right objective category, whether it is the right type of control, or whether management’s control mix leaves residual risk within appetite.

What Controls Are—and Are Not

Controls are…Controls are not…
Processes embedded in how work gets doneA binder of policies that nobody follows
Owned by management (first line), with second-line supportOwned by internal audit as the primary control operator
Designed for reasonable assuranceGuarantees against all error, fraud, or loss
Proportionate to risk and costAutomatically “more controls = better”

Internal audit evaluates and recommends controls; it does not replace management’s responsibility to design and operate them.

Preventive, Detective, and Corrective Controls

The most tested classification for C7 is timing relative to the undesired event:

Control typeWhen it actsCore purposeTypical characteristics
PreventiveBefore the eventStop errors, fraud, or noncompliance from occurringAuthorization, access restrictions, segregation of duties, edit checks, training, physical barriers
DetectiveAfter the event (or during processing)Identify that something went wrong so response can beginReconciliations, exception reports, audits, inventory counts, CCTV review, variance analysis
CorrectiveAfter detectionFix the condition, recover loss, and restore the processError correction workflows, backup restoration, disciplinary action, process redesign after an incident, insurance claims processing

Exam tip: Many strong control systems combine all three. Preventive controls reduce frequency; detective controls provide visibility; corrective controls limit impact and prevent recurrence. If a stem shows only detective controls with no prevention, residual risk of occurrence may remain high even if issues are eventually found.

How to Classify Ambiguous Controls

Some activities span types depending on design:

  • A system edit check that blocks an out-of-range journal entry is preventive.
  • A nightly exception report that lists out-of-range postings already accepted is detective.
  • A workflow that reverses the bad posting and re-trains the clerk is corrective (and may include a preventive redesign).

When classifying on the exam, ask: Does this stop the event, find the event, or fix the event? Choose the primary purpose described in the stem.

Financial vs Nonfinancial Control Examples

IAP items expect you to recognize that internal control is not only about the general ledger. Financial and nonfinancial controls often work together against the same risk.

Financial Control Examples

Objective focusPreventiveDetectiveCorrective
Accurate disbursementsDual approval of wires above threshold; vendor master change approvalsBank reconciliation; payment exception reportReverse unauthorized payment; recover funds; tighten approval matrix
Reliable financial reportingPeriod-close checklist with required sign-offs; system access limited by roleFlux analysis; account reconciliations; management review of draft statementsRestate or correct misstatements; update close procedures
Asset safeguarding (cash/inventory value)Locked cash drawers; inventory issue authorizationSurprise cash counts; cycle countsAdjust records; investigate shortages; change custody assignments

Nonfinancial Control Examples

Objective focusPreventiveDetectiveCorrective
Operations / qualityStandard operating procedures; machine calibration before productionQuality sampling; customer complaint dashboardsRework batches; root-cause redesign of the process
Compliance / privacyMandatory privacy training before system access; consent captureAccess-log monitoring; regulatory filing completeness checksBreach notification; remediation plan; policy update
Safety / ESGPermit-to-work; PPE requirements; emissions-limit interlocksIncident reporting; emissions monitoring alertsIncident investigation; equipment repair; revised safety controls
IT / cybersecurity (often mixed)Multi-factor authentication; least-privilege accessIntrusion detection; failed-login alertsIncident response; patching; credential reset

IAP scenario: A hospital’s risk of wrong-site surgery is primarily operational / patient-safety (nonfinancial), though lawsuits create financial and reputational impact. A preoperative “time-out” checklist is a preventive nonfinancial control; morbidity-and-mortality review that spots pattern failures is detective; protocol redesign after a near-miss is corrective.

Do not assume “financial = important” and “nonfinancial = soft.” Boards oversee both. Internal auditors recommend controls where risk threatens critical objectives—monetary or not.

Recommending Controls to Mitigate Risks

Syllabus C7 expects you to recommend controls, not only define them. Use a disciplined sequence:

  1. Name the objective and risk — What could go wrong, and relative to which objective?
  2. Assess inherent risk — How exposed is the activity before responses?
  3. Identify root cause — Is the gap about authorization, competence, data integrity, custody, monitoring, or incentives?
  4. Select control type mix — Prefer prevention for high-frequency/high-impact risks; ensure detection where prevention can fail; plan correction/recovery.
  5. Check proportionality — Cost, friction, and residual risk vs. appetite.
  6. Assign ownership and evidence — Who operates the control, and what evidence proves it ran?

Recommendation Quality Tests

A weak recommendation: “Management should improve controls.”
A strong recommendation: “Require dual electronic approval for vendor bank-detail changes, with a weekly detective report of all master-file changes reviewed by someone without change rights, to mitigate unauthorized diversion of payments.”

When evaluating answer choices:

  • Prefer controls that address the cause in the stem (for example, custody + recording combined → segregation).
  • Prefer specific, operable controls over slogans (“tone at the top” alone rarely fixes a wire-fraud gap).
  • Prefer layered responses for high residual risk (preventive + detective).
  • Reject recommendations that transfer ownership to internal audit as the ongoing control performer.

Cost, Efficiency, and Over-Control

Controls can be effective yet inefficient (duplicate approvals that add days of delay with little risk reduction) or efficient yet ineffective (a rubber-stamp approval). C7 focuses on concepts and types; C8 deepens design vs. operating effectiveness and efficiency. For now, remember: recommendations should mitigate risk proportionately, not maximize bureaucracy.

Segregation of Duties (SoD) Basics

Segregation of duties is a foundational preventive control. It separates incompatible responsibilities so that one individual cannot both commit and conceal an error or irregularity. Classic incompatible duties include:

FunctionMeaningWhy it must be separated
AuthorizationApproving transactions or changesAlone with custody → can approve diversion of assets
CustodyPhysical or electronic control of assetsAlone with recording → can steal and alter books
RecordingEntering transactions in systems/ledgersAlone with authorization → can create fictitious activity
Reconciliation / reviewIndependent comparison of records to realityIf done by the same person who records/custodies, detection fails

Practical example: The person who maintains the vendor master file should not also initiate and approve payments to those vendors. The person who receives customer remittances should not also post receivables and reconcile the bank account without independent review.

Compensating Controls When SoD Is Imperfect

Small organizations often cannot fully segregate. Compensating controls may include:

  • Increased management review of transactions and exception reports.
  • Periodic independent reconciliations by an owner or external bookkeeper.
  • System audit logs reviewed by someone without transaction rights.
  • Job rotation or mandatory vacation (detective/corrective support).

Compensating controls do not make imperfect SoD “ideal,” but they can bring residual risk within appetite when full segregation is impractical. Exam stems may ask which compensating control best mitigates a known SoD weakness.

SoD Failures Auditors Commonly Find

  • Shared system IDs that destroy accountability.
  • Supervisors who both enter and approve their own transactions.
  • IT administrators with business-transaction rights and no logging/review.
  • Temporary “emergency” access that becomes permanent.

When recommending fixes, restore incompatible-duty separation first; add detective monitoring where residual access risk remains.

Putting C7 Together for Exam Scenarios

Walk every control stem with this checklist:

  1. What is the objective (operations, reporting, compliance)?
  2. Is the risk financial, nonfinancial, or both?
  3. Is the needed control primarily preventive, detective, or corrective?
  4. Would segregation of duties (or a compensating detective control) address the root cause?
  5. Does the recommendation provide reasonable assurance proportionate to risk—not absolute certainty?
/practice/iia-iapPractice questions with detailed explanations
Test Your Knowledge

A company wants to reduce the risk that unauthorized employees change vendor bank account details and divert payments. Which control is primarily preventive?

A
B
C
D
Test Your Knowledge

A manufacturing plant implements a mandatory lockout/tagout procedure before machine maintenance, daily safety walkthrough checklists that record hazards found, and a formal incident investigation process that redesigns procedures after near-misses. How should these three controls be classified?

A
B
C
D
Test Your Knowledge

In a small nonprofit, the same employee records cash receipts, deposits cash, and prepares the bank reconciliation with no independent review. Which recommendation best mitigates the segregation-of-duties risk?

A
B
C
D