9.1 Control Concepts & Types
Key Takeaways
- Internal controls are processes designed to provide reasonable assurance that objectives related to operations, reporting, and compliance will be achieved.
- Controls are commonly classified as preventive, detective, or corrective based on when they act relative to an undesired event.
- Internal auditors recommend controls that mitigate identified risks proportionately—balancing residual risk, cost, and operational practicality.
- Financial controls protect the integrity of monetary transactions and reporting; nonfinancial controls protect operations, compliance, safety, quality, and other non-monetary objectives.
- Segregation of duties separates incompatible functions (authorization, custody, recording, and reconciliation) so one person cannot both perpetrate and conceal an error or fraud.
9.1 Control Concepts & Types
Quick Answer: Internal controls are the policies, procedures, and activities management designs and operates to provide reasonable assurance that objectives for operations, reporting, and compliance are met. For Syllabus C7, classify controls as preventive, detective, or corrective; recommend controls that mitigate risk; contrast financial vs. nonfinancial examples; and apply segregation of duties basics.
Syllabus C7 sits inside Domain III — Governance, Risk Management, and Control (~30% of the exam). After you can name risks and evaluate responses (C4–C6), you must translate residual-risk gaps into control recommendations that actually reduce likelihood or impact—without claiming perfect assurance.
Purpose of Internal Controls
Internal control is a process, effected by an entity’s board, management, and other personnel, designed to provide reasonable assurance—not absolute assurance—regarding achievement of objectives in three categories commonly used with the COSO Internal Control — Integrated Framework (2013):
- Operations — effectiveness and efficiency of operations, including safeguarding of assets.
- Reporting — reliability, timeliness, and transparency of internal and external financial and nonfinancial reporting.
- Compliance — adherence to laws, regulations, and binding policies the entity has adopted.
Why “reasonable” assurance? Controls have cost, human judgment fails, collusion can defeat segregation, and management can override. Internal auditors who promise zero residual risk misunderstand both control theory and board expectations.
Controls exist to mitigate risk relative to objectives. A control without a linked risk and objective is busywork. A risk without a proportionate control (or documented acceptance) is unmanaged exposure. On the IAP, stems often ask whether a proposed control addresses the right objective category, whether it is the right type of control, or whether management’s control mix leaves residual risk within appetite.
What Controls Are—and Are Not
| Controls are… | Controls are not… |
|---|---|
| Processes embedded in how work gets done | A binder of policies that nobody follows |
| Owned by management (first line), with second-line support | Owned by internal audit as the primary control operator |
| Designed for reasonable assurance | Guarantees against all error, fraud, or loss |
| Proportionate to risk and cost | Automatically “more controls = better” |
Internal audit evaluates and recommends controls; it does not replace management’s responsibility to design and operate them.
Preventive, Detective, and Corrective Controls
The most tested classification for C7 is timing relative to the undesired event:
| Control type | When it acts | Core purpose | Typical characteristics |
|---|---|---|---|
| Preventive | Before the event | Stop errors, fraud, or noncompliance from occurring | Authorization, access restrictions, segregation of duties, edit checks, training, physical barriers |
| Detective | After the event (or during processing) | Identify that something went wrong so response can begin | Reconciliations, exception reports, audits, inventory counts, CCTV review, variance analysis |
| Corrective | After detection | Fix the condition, recover loss, and restore the process | Error correction workflows, backup restoration, disciplinary action, process redesign after an incident, insurance claims processing |
Exam tip: Many strong control systems combine all three. Preventive controls reduce frequency; detective controls provide visibility; corrective controls limit impact and prevent recurrence. If a stem shows only detective controls with no prevention, residual risk of occurrence may remain high even if issues are eventually found.
How to Classify Ambiguous Controls
Some activities span types depending on design:
- A system edit check that blocks an out-of-range journal entry is preventive.
- A nightly exception report that lists out-of-range postings already accepted is detective.
- A workflow that reverses the bad posting and re-trains the clerk is corrective (and may include a preventive redesign).
When classifying on the exam, ask: Does this stop the event, find the event, or fix the event? Choose the primary purpose described in the stem.
Financial vs Nonfinancial Control Examples
IAP items expect you to recognize that internal control is not only about the general ledger. Financial and nonfinancial controls often work together against the same risk.
Financial Control Examples
| Objective focus | Preventive | Detective | Corrective |
|---|---|---|---|
| Accurate disbursements | Dual approval of wires above threshold; vendor master change approvals | Bank reconciliation; payment exception report | Reverse unauthorized payment; recover funds; tighten approval matrix |
| Reliable financial reporting | Period-close checklist with required sign-offs; system access limited by role | Flux analysis; account reconciliations; management review of draft statements | Restate or correct misstatements; update close procedures |
| Asset safeguarding (cash/inventory value) | Locked cash drawers; inventory issue authorization | Surprise cash counts; cycle counts | Adjust records; investigate shortages; change custody assignments |
Nonfinancial Control Examples
| Objective focus | Preventive | Detective | Corrective |
|---|---|---|---|
| Operations / quality | Standard operating procedures; machine calibration before production | Quality sampling; customer complaint dashboards | Rework batches; root-cause redesign of the process |
| Compliance / privacy | Mandatory privacy training before system access; consent capture | Access-log monitoring; regulatory filing completeness checks | Breach notification; remediation plan; policy update |
| Safety / ESG | Permit-to-work; PPE requirements; emissions-limit interlocks | Incident reporting; emissions monitoring alerts | Incident investigation; equipment repair; revised safety controls |
| IT / cybersecurity (often mixed) | Multi-factor authentication; least-privilege access | Intrusion detection; failed-login alerts | Incident response; patching; credential reset |
IAP scenario: A hospital’s risk of wrong-site surgery is primarily operational / patient-safety (nonfinancial), though lawsuits create financial and reputational impact. A preoperative “time-out” checklist is a preventive nonfinancial control; morbidity-and-mortality review that spots pattern failures is detective; protocol redesign after a near-miss is corrective.
Do not assume “financial = important” and “nonfinancial = soft.” Boards oversee both. Internal auditors recommend controls where risk threatens critical objectives—monetary or not.
Recommending Controls to Mitigate Risks
Syllabus C7 expects you to recommend controls, not only define them. Use a disciplined sequence:
- Name the objective and risk — What could go wrong, and relative to which objective?
- Assess inherent risk — How exposed is the activity before responses?
- Identify root cause — Is the gap about authorization, competence, data integrity, custody, monitoring, or incentives?
- Select control type mix — Prefer prevention for high-frequency/high-impact risks; ensure detection where prevention can fail; plan correction/recovery.
- Check proportionality — Cost, friction, and residual risk vs. appetite.
- Assign ownership and evidence — Who operates the control, and what evidence proves it ran?
Recommendation Quality Tests
A weak recommendation: “Management should improve controls.”
A strong recommendation: “Require dual electronic approval for vendor bank-detail changes, with a weekly detective report of all master-file changes reviewed by someone without change rights, to mitigate unauthorized diversion of payments.”
When evaluating answer choices:
- Prefer controls that address the cause in the stem (for example, custody + recording combined → segregation).
- Prefer specific, operable controls over slogans (“tone at the top” alone rarely fixes a wire-fraud gap).
- Prefer layered responses for high residual risk (preventive + detective).
- Reject recommendations that transfer ownership to internal audit as the ongoing control performer.
Cost, Efficiency, and Over-Control
Controls can be effective yet inefficient (duplicate approvals that add days of delay with little risk reduction) or efficient yet ineffective (a rubber-stamp approval). C7 focuses on concepts and types; C8 deepens design vs. operating effectiveness and efficiency. For now, remember: recommendations should mitigate risk proportionately, not maximize bureaucracy.
Segregation of Duties (SoD) Basics
Segregation of duties is a foundational preventive control. It separates incompatible responsibilities so that one individual cannot both commit and conceal an error or irregularity. Classic incompatible duties include:
| Function | Meaning | Why it must be separated |
|---|---|---|
| Authorization | Approving transactions or changes | Alone with custody → can approve diversion of assets |
| Custody | Physical or electronic control of assets | Alone with recording → can steal and alter books |
| Recording | Entering transactions in systems/ledgers | Alone with authorization → can create fictitious activity |
| Reconciliation / review | Independent comparison of records to reality | If done by the same person who records/custodies, detection fails |
Practical example: The person who maintains the vendor master file should not also initiate and approve payments to those vendors. The person who receives customer remittances should not also post receivables and reconcile the bank account without independent review.
Compensating Controls When SoD Is Imperfect
Small organizations often cannot fully segregate. Compensating controls may include:
- Increased management review of transactions and exception reports.
- Periodic independent reconciliations by an owner or external bookkeeper.
- System audit logs reviewed by someone without transaction rights.
- Job rotation or mandatory vacation (detective/corrective support).
Compensating controls do not make imperfect SoD “ideal,” but they can bring residual risk within appetite when full segregation is impractical. Exam stems may ask which compensating control best mitigates a known SoD weakness.
SoD Failures Auditors Commonly Find
- Shared system IDs that destroy accountability.
- Supervisors who both enter and approve their own transactions.
- IT administrators with business-transaction rights and no logging/review.
- Temporary “emergency” access that becomes permanent.
When recommending fixes, restore incompatible-duty separation first; add detective monitoring where residual access risk remains.
Putting C7 Together for Exam Scenarios
Walk every control stem with this checklist:
- What is the objective (operations, reporting, compliance)?
- Is the risk financial, nonfinancial, or both?
- Is the needed control primarily preventive, detective, or corrective?
- Would segregation of duties (or a compensating detective control) address the root cause?
- Does the recommendation provide reasonable assurance proportionate to risk—not absolute certainty?
/practice/iia-iapPractice questions with detailed explanationsA company wants to reduce the risk that unauthorized employees change vendor bank account details and divert payments. Which control is primarily preventive?
A manufacturing plant implements a mandatory lockout/tagout procedure before machine maintenance, daily safety walkthrough checklists that record hazards found, and a formal incident investigation process that redesigns procedures after near-misses. How should these three controls be classified?
In a small nonprofit, the same employee records cash receipts, deposits cash, and prepares the bank reconciliation with no independent review. Which recommendation best mitigates the segregation-of-duties risk?