ACCA Applied Knowledge · Business and Technology
Internal controls: formula sheet
Key formulas
- Purposes of internal control
- Safeguard assets + reliable records + compliance + efficiency + prevent/detect fraud and error
- Use this as a checklist when a question asks why a control system is needed.
- Components of a control system
- Control environment + risk assessment + control activities + information and communication + monitoring
- These five components follow the widely used COSO-style framework. Name them in this order.
- Cost-benefit rule
- Cost of a control should not exceed the benefit it gives
- This is a limitation and a design principle. It explains why not every risk is controlled.
- Level of assurance
- Internal control = reasonable assurance, not absolute assurance
- Use this wording whenever limitations are tested.
- Preventive control
- Acts BEFORE the event: stops the error or fraud
- Examples: segregation of duties, authorisation limits, passwords, locked stores.
- Detective control
- Acts AFTER the event: finds the error or fraud
- Examples: reconciliations, stock counts, exception reports, internal audit review.
- Corrective control
- Acts AFTER detection: fixes the problem and restores normal operation
- Examples: data backup restoration, correcting entries, disciplinary action, retraining.
- Financial vs non-financial
- Financial = money and records; Non-financial = everything else
- A control can be both financial and preventive, for example payment authorisation.
- Incompatible duties to separate
- Authorisation, Recording, Custody (and often Reconciliation)
- Aim for different people to perform each. If one person does two or more, point out the risk.
- Control answer pattern
- Weakness → Risk → Control → How it helps
- Use this four-part pattern for every scenario point to earn full marks.
- Authorisation rule
- Amount ≤ limit: approver at that level; Amount > limit: next level up
- Limits should match seniority and be set in writing.
- Reconciliation rule
- Balance per records ± reconciling items = balance per external source
- Done regularly and reviewed by someone independent of the person who keeps the records.
- Control types
- Preventive = before; Detective = after; Corrective = fix
- Segregation, authorisation and physical controls are mainly preventive.
- General controls
- General controls = controls over the whole IT environment
- Includes access, backup and recovery, physical security, network security, and change and development controls.
- Application controls
- Application controls = controls inside one program (input, processing, output)
- Includes validation checks, batch totals, run-to-run totals and exception reports.
- Common validation checks
- Range, format, presence, check digit, limit, reasonableness
- Each tests data at entry. They show the data is reasonable, not that it is correct.
- Control types
- Preventive, detective, corrective
- Passwords prevent, exception reports detect, restoring from backup corrects.
- Internal audit purpose
- Internal audit = independent review of risk management, control and governance to help management
- Serves management and the board. It is not primarily for shareholders.
- External audit purpose
- External audit = independent opinion on whether the financial statements are fairly presented
- Serves shareholders. Appointed by shareholders, usually a legal requirement for larger companies.
- Value for money (the three Es)
- Economy + Efficiency + Effectiveness
- Internal audit often tests these. Economy is low cost of inputs, efficiency is output per input, effectiveness is achieving objectives.
- Independence reporting line
- Internal audit → audit committee (or board)
- Not to the managers whose work is being audited.
- Fraud versus error
- Fraud = intentional deception; Error = unintentional mistake
- Intent is the deciding test. Always state it when asked for the difference.
- Fraud triangle
- Fraud risk = Pressure + Opportunity + Rationalisation
- All three are normally present. This is a model, not a calculation. Removing one element reduces risk.
- Two main types of fraud
- Misappropriation of assets; Fraudulent financial reporting
- Theft of assets versus deliberate misstatement of the accounts.
- Control approach
- Prevent first, then detect
- Preventive controls stop fraud; detective controls find it after it occurs.
- Responsibility
- Management and governance prevent and detect; auditors assess risk of material misstatement
- Auditors do not guarantee that fraud will be found.
- Monitoring levels
- Management (ongoing) → Internal audit (periodic, independent) → Audit committee (review) → Board (responsible)
- Use this chain to say who does what in a scenario question.
- Content of a deficiency report
- Weakness + Risk/consequence + Recommendation + Management response
- Four parts. Missing the consequence or the recommendation loses marks.
- Cost-benefit test for a control
- Implement only if benefit of reduced risk > cost of the control
- Use it when asked whether a recommended control is sensible.
Quick revision
- An internal control system is the set of policies and procedures that helps safeguard assets, keep records reliable, ensure compliance and support efficient operations.
- Controls give reasonable assurance, not absolute assurance. Collusion, human error and management override can defeat them.
- Preventive controls stop problems happening, detective controls find problems that have happened, corrective controls fix them.
- Segregation of duties separates authorising, recording and custody of assets so one person cannot control a whole transaction.
- Authorisation means transactions are approved by someone with the right level of authority before they proceed.
- Physical controls include locks, safes, restricted access and stock checks to protect assets.
- General IT controls cover the whole IT environment, such as access, backups and change management. Application controls work within a specific program, such as input checks.
- Passwords, access rights and firewalls are common preventive IT controls.
- Internal audit is an appraisal function that reviews controls and risk management, and reports to management or the audit committee.
- Internal audit is part of the organisation and its scope is set by management. External audit gives an opinion on the financial statements for shareholders.
- Fraud is deliberate deception for gain. Error is unintentional.
- Controls should be monitored and reviewed regularly, and weaknesses reported to those responsible for governance.
Common mistakes
- Saying internal control guarantees that fraud will not happen. Fix: Always use 'reasonable assurance'. Controls reduce risk; they cannot remove it.
- Confusing the control environment with control activities. Fix: The environment is the attitude and culture set by management. Activities are specific procedures like approvals and reconciliations.
- Calling a reconciliation preventive. Fix: A reconciliation happens after transactions are recorded and reveals differences, so it is detective.
- Confusing detective and corrective controls. Fix: Detective only discovers the problem. Corrective takes action to repair it or prevent recurrence.
- Saying segregation of duties means different people do different jobs in general. Fix: Define it as separating authorisation, recording and custody for the same transaction so fraud needs collusion.
- Recommending segregation in a very small business without caveats. Fix: Suggest alternatives such as owner review, rotation of duties and independent checking of reconciliations.
- Calling a validation check a general control. Fix: Validation works on data in one program, so it is an application control.
- Saying passwords alone make a system secure. Fix: Passwords can be shared or guessed. Add regular changes, user rights by role and multi-factor authentication.
- Saying internal audit gives an opinion on the financial statements to shareholders. Fix: Link the true and fair opinion only to external audit. Internal audit reports to management and the audit committee.
- Treating internal audit as legally required for all companies. Fix: Remember internal audit is generally a management decision, though governance codes encourage it.
Exam tips
- Look out for absolute words such as 'guarantee', 'prevent all' or 'eliminate'. These options are almost always wrong for this topic.
- In multiple response questions, count the required answers first, then pick only the options that fit the exact wording.
- Learn the five components by name so you can match a scenario to the right one quickly.
- In Section B multi-task questions, link your answer to the scenario. Name the actual control and the risk it addresses.
- Do not spend more than about a minute on a one-mark question. Flag it and return if unsure.
- Classify by timing and purpose, not by how the control sounds.
- In multiple response questions, check every option separately and select exactly the stated number.
- Learn two or three examples of each type, as questions often give a scenario and ask you to label it.