Skip to content

ACCA Applied Knowledge · Business and Technology

Internal controls: formula sheet

Full chapter guide

Key formulas

Purposes of internal control
Safeguard assets + reliable records + compliance + efficiency + prevent/detect fraud and error
Use this as a checklist when a question asks why a control system is needed.
Components of a control system
Control environment + risk assessment + control activities + information and communication + monitoring
These five components follow the widely used COSO-style framework. Name them in this order.
Cost-benefit rule
Cost of a control should not exceed the benefit it gives
This is a limitation and a design principle. It explains why not every risk is controlled.
Level of assurance
Internal control = reasonable assurance, not absolute assurance
Use this wording whenever limitations are tested.
Preventive control
Acts BEFORE the event: stops the error or fraud
Examples: segregation of duties, authorisation limits, passwords, locked stores.
Detective control
Acts AFTER the event: finds the error or fraud
Examples: reconciliations, stock counts, exception reports, internal audit review.
Corrective control
Acts AFTER detection: fixes the problem and restores normal operation
Examples: data backup restoration, correcting entries, disciplinary action, retraining.
Financial vs non-financial
Financial = money and records; Non-financial = everything else
A control can be both financial and preventive, for example payment authorisation.
Incompatible duties to separate
Authorisation, Recording, Custody (and often Reconciliation)
Aim for different people to perform each. If one person does two or more, point out the risk.
Control answer pattern
Weakness → Risk → Control → How it helps
Use this four-part pattern for every scenario point to earn full marks.
Authorisation rule
Amount ≤ limit: approver at that level; Amount > limit: next level up
Limits should match seniority and be set in writing.
Reconciliation rule
Balance per records ± reconciling items = balance per external source
Done regularly and reviewed by someone independent of the person who keeps the records.
Control types
Preventive = before; Detective = after; Corrective = fix
Segregation, authorisation and physical controls are mainly preventive.
General controls
General controls = controls over the whole IT environment
Includes access, backup and recovery, physical security, network security, and change and development controls.
Application controls
Application controls = controls inside one program (input, processing, output)
Includes validation checks, batch totals, run-to-run totals and exception reports.
Common validation checks
Range, format, presence, check digit, limit, reasonableness
Each tests data at entry. They show the data is reasonable, not that it is correct.
Control types
Preventive, detective, corrective
Passwords prevent, exception reports detect, restoring from backup corrects.
Internal audit purpose
Internal audit = independent review of risk management, control and governance to help management
Serves management and the board. It is not primarily for shareholders.
External audit purpose
External audit = independent opinion on whether the financial statements are fairly presented
Serves shareholders. Appointed by shareholders, usually a legal requirement for larger companies.
Value for money (the three Es)
Economy + Efficiency + Effectiveness
Internal audit often tests these. Economy is low cost of inputs, efficiency is output per input, effectiveness is achieving objectives.
Independence reporting line
Internal audit → audit committee (or board)
Not to the managers whose work is being audited.
Fraud versus error
Fraud = intentional deception; Error = unintentional mistake
Intent is the deciding test. Always state it when asked for the difference.
Fraud triangle
Fraud risk = Pressure + Opportunity + Rationalisation
All three are normally present. This is a model, not a calculation. Removing one element reduces risk.
Two main types of fraud
Misappropriation of assets; Fraudulent financial reporting
Theft of assets versus deliberate misstatement of the accounts.
Control approach
Prevent first, then detect
Preventive controls stop fraud; detective controls find it after it occurs.
Responsibility
Management and governance prevent and detect; auditors assess risk of material misstatement
Auditors do not guarantee that fraud will be found.
Monitoring levels
Management (ongoing) → Internal audit (periodic, independent) → Audit committee (review) → Board (responsible)
Use this chain to say who does what in a scenario question.
Content of a deficiency report
Weakness + Risk/consequence + Recommendation + Management response
Four parts. Missing the consequence or the recommendation loses marks.
Cost-benefit test for a control
Implement only if benefit of reduced risk > cost of the control
Use it when asked whether a recommended control is sensible.

Quick revision

  • An internal control system is the set of policies and procedures that helps safeguard assets, keep records reliable, ensure compliance and support efficient operations.
  • Controls give reasonable assurance, not absolute assurance. Collusion, human error and management override can defeat them.
  • Preventive controls stop problems happening, detective controls find problems that have happened, corrective controls fix them.
  • Segregation of duties separates authorising, recording and custody of assets so one person cannot control a whole transaction.
  • Authorisation means transactions are approved by someone with the right level of authority before they proceed.
  • Physical controls include locks, safes, restricted access and stock checks to protect assets.
  • General IT controls cover the whole IT environment, such as access, backups and change management. Application controls work within a specific program, such as input checks.
  • Passwords, access rights and firewalls are common preventive IT controls.
  • Internal audit is an appraisal function that reviews controls and risk management, and reports to management or the audit committee.
  • Internal audit is part of the organisation and its scope is set by management. External audit gives an opinion on the financial statements for shareholders.
  • Fraud is deliberate deception for gain. Error is unintentional.
  • Controls should be monitored and reviewed regularly, and weaknesses reported to those responsible for governance.

Common mistakes

  • Saying internal control guarantees that fraud will not happen. Fix: Always use 'reasonable assurance'. Controls reduce risk; they cannot remove it.
  • Confusing the control environment with control activities. Fix: The environment is the attitude and culture set by management. Activities are specific procedures like approvals and reconciliations.
  • Calling a reconciliation preventive. Fix: A reconciliation happens after transactions are recorded and reveals differences, so it is detective.
  • Confusing detective and corrective controls. Fix: Detective only discovers the problem. Corrective takes action to repair it or prevent recurrence.
  • Saying segregation of duties means different people do different jobs in general. Fix: Define it as separating authorisation, recording and custody for the same transaction so fraud needs collusion.
  • Recommending segregation in a very small business without caveats. Fix: Suggest alternatives such as owner review, rotation of duties and independent checking of reconciliations.
  • Calling a validation check a general control. Fix: Validation works on data in one program, so it is an application control.
  • Saying passwords alone make a system secure. Fix: Passwords can be shared or guessed. Add regular changes, user rights by role and multi-factor authentication.
  • Saying internal audit gives an opinion on the financial statements to shareholders. Fix: Link the true and fair opinion only to external audit. Internal audit reports to management and the audit committee.
  • Treating internal audit as legally required for all companies. Fix: Remember internal audit is generally a management decision, though governance codes encourage it.

Exam tips

  • Look out for absolute words such as 'guarantee', 'prevent all' or 'eliminate'. These options are almost always wrong for this topic.
  • In multiple response questions, count the required answers first, then pick only the options that fit the exact wording.
  • Learn the five components by name so you can match a scenario to the right one quickly.
  • In Section B multi-task questions, link your answer to the scenario. Name the actual control and the risk it addresses.
  • Do not spend more than about a minute on a one-mark question. Flag it and return if unsure.
  • Classify by timing and purpose, not by how the control sounds.
  • In multiple response questions, check every option separately and select exactly the stated number.
  • Learn two or three examples of each type, as questions often give a scenario and ask you to label it.