ACCA Applied Knowledge · Business and Technology
Internal Controls for ACCA Business and Technology
Internal controls are the policies and procedures an organisation uses to safeguard assets, keep records reliable, follow rules and run efficiently. To solve BT questions, identify the risk first, then match it to the control type (preventive, detective or corrective) and the specific activity, such as segregation of duties or authorisation.
What this chapter covers
This chapter covers how an organisation protects itself from error, waste and fraud. You start with the purpose of an internal control system. Then you learn the types of control, the main control activities, IT controls, the internal audit function, fraud, and finally how controls are monitored and reported on.
The chapter links to several other parts of the Business and Technology paper. Governance and risk management explain why controls exist and who is responsible for them. Accounting systems and information technology show where controls are applied in practice. Ethics ties in because fraud and pressure to bend rules are ethical issues too.
Questions are usually short and practical. You may get a scenario with a weakness and be asked which control fixes it. Or you may be asked to classify a control. Knowing the definitions precisely is enough to score well, as long as you can apply them to a short scenario.
Internal controls appear in the objective test in Section A, and the topic can also be the base for a four-mark multi-task question in Section B on governance, risk and control. The questions are mostly about recognition and application, so the marks are reliable once you know the vocabulary. The same ideas also return later in the ACCA qualification, in audit and governance papers, so the effort pays off twice. Because the exam is two hours with all questions compulsory, quick and accurate answers here free up time for harder questions elsewhere.
Internal controls: topics in the order to study them
- 1Internal Control Systems and Their PurposeStart here because every later topic is a part of the system, and you need its purpose and limits first.
- 2Types of Control: Preventive, Detective and CorrectiveThis classification is the language used in questions, so learn it before looking at specific controls.
- 3Control Activities: Segregation of Duties, Authorisation and Physical ControlsThese are the core examples you will classify and apply, so they come right after the types.
- 4Information Systems and IT ControlsIT controls build on the same ideas, split into general and application controls, so study them once the basic activities are clear.
- 5Internal Audit FunctionInternal audit tests and reports on controls, so it makes sense once you know what the controls are.
- 6Fraud, Fraud Prevention and DetectionFraud shows why controls fail and which controls prevent or detect it, which pulls earlier topics together.
- 7Monitoring and Review of Controls and ReportingFinish with how controls are reviewed and reported on, which closes the loop on the whole system.
How to prepare Internal controls
Treat this chapter as a vocabulary and matching exercise. Your aim is to read a short scenario and name the weakness and the fix quickly.
- Read the chapter once in the study order, writing a one-line definition for each key term in your own words.
- Build a table in your notes of control examples, with the type (preventive, detective or corrective) beside each. Keep it on your phone for quick review.
- For each control activity, write the risk it addresses. For example, segregation of duties reduces the chance that one person can commit and hide an error or fraud.
- Practise short scenarios: spot the weakness, name the missing control, and say what it would prevent or detect.
- Practise all three question types: multiple choice, multiple response where you must pick the stated number, and number entry if it appears. For multiple response, test each option separately.
- Compare internal audit with external audit, and general IT controls with application controls, until you can state the difference in one sentence.
- Finish with timed sets of objective questions and review every wrong answer to find which term you confused.
Common mistakes in Internal controls
Mixing up preventive and detective controls.
Fix: Ask whether the control works before or after the event. If it acts after, it is detective or corrective.
Saying controls can eliminate fraud and error completely.
Fix: Remember that controls give reasonable assurance only. Collusion and management override can get around them.
Confusing segregation of duties with authorisation.
Fix: Segregation splits tasks between people. Authorisation is approval by someone with the right authority.
Mixing up general IT controls and application controls.
Fix: General controls cover the whole IT environment. Application controls sit inside one program, such as validation of input.
Treating internal audit as the same as external audit.
Fix: Remember who it serves. Internal audit serves management on controls and risk. External audit gives an opinion on the financial statements.
Ticking too many options in multiple response questions.
Fix: Select exactly the stated number. Judge each option on its own against the scenario and cross out the weakest ones.
Last-day revision: Internal controls
- An internal control system is the set of policies and procedures that helps safeguard assets, keep records reliable, ensure compliance and support efficient operations.
- Controls give reasonable assurance, not absolute assurance. Collusion, human error and management override can defeat them.
- Preventive controls stop problems happening, detective controls find problems that have happened, corrective controls fix them.
- Segregation of duties separates authorising, recording and custody of assets so one person cannot control a whole transaction.
- Authorisation means transactions are approved by someone with the right level of authority before they proceed.
- Physical controls include locks, safes, restricted access and stock checks to protect assets.
- General IT controls cover the whole IT environment, such as access, backups and change management. Application controls work within a specific program, such as input checks.
- Passwords, access rights and firewalls are common preventive IT controls.
- Internal audit is an appraisal function that reviews controls and risk management, and reports to management or the audit committee.
- Internal audit is part of the organisation and its scope is set by management. External audit gives an opinion on the financial statements for shareholders.
- Fraud is deliberate deception for gain. Error is unintentional.
- Controls should be monitored and reviewed regularly, and weaknesses reported to those responsible for governance.
Internal controls practice questions
- A warehouse holds high-value electronic components. Management wants to reduce the risk of theft while still allowing staff to do their jobs…
- A company discovers that a software virus corrupted its sales ledger. It restores the data from the previous night's backup and re-enters th…
- A company's finance director states that the company has a strong control environment. Which of the following most directly forms part of th…
- A retailer's internal auditors test a sample of purchase invoices each quarter to check that they were approved by an authorised manager bef…
- Which of the following best describes the primary purpose of an internal control system in an organisation?
- In a small retailer, the same employee receives customer cash, records the sales in the ledger and prepares the bank paying-in slips. Which …
- A payroll clerk with sole control of the employee master file adds a fictitious employee and directs the salary to their own bank account. W…
- A warehouse manager at Kestrel Ltd is responsible for authorising purchases of stock, receiving the goods and also maintaining the inventory…
Internal controls in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Internal controls: frequently asked questions
What is the difference between preventive, detective and corrective controls?
Preventive controls stop an error or fraud happening, such as password access. Detective controls find one that has happened, such as a bank reconciliation. Corrective controls fix the damage and stop it recurring, such as restoring data from a backup.
How do I answer internal control scenario questions quickly?
Find the weakness or risk in the scenario first. Then name the control that addresses it and say whether it is preventive, detective or corrective. Check that your answer fits the exact wording of the question.
Is internal control tested in the ACCA BT exam?
Yes. It is part of the Business and Technology syllabus and can be tested through Section A objective questions or Section B multi-task questions. It links to governance, risk and accounting systems.
Do I need to learn lots of detail on fraud?
You need the definition, why fraud happens, and the main prevention and detection measures. Focus on matching a given situation to the right control rather than memorising long lists.