Business and Technology · Internal controls
Monitoring and Reviewing Internal Controls for ACCA BT
Updated 11 October 2026 · Fact-checked
Monitoring internal controls means checking regularly that controls exist, work as designed and still fit the business. Management monitors day to day, internal audit tests independently, and the audit committee reviews and reports to the board. Deficiencies are reported up the chain, ranked by seriousness, and fixed with agreed actions.
Understand Monitoring and Review of Controls and Reporting
A control that was good last year may fail this year. Staff leave, systems change, and people find ways around rules. Monitoring is the process of checking that controls keep working. Without it, a control system slowly decays.
Monitoring happens at several levels. Management carries out ongoing monitoring: supervisors review exception reports, check reconciliations and watch for unusual results. Internal audit gives separate, periodic checks. It tests controls, reports findings and follows up on fixes. External audit looks at controls only to the extent needed to plan the audit of the financial statements. It is not a full control review.
Those charged with governance have the final oversight role. The board is responsible for the system of internal control. Many governance codes expect the board to review its effectiveness at least annually and to report on this to shareholders. The audit committee, made up mainly of independent non-executive directors, usually does the detailed work for the board. It reviews the internal control system, oversees internal audit, and talks to the external auditor.
When a weakness (a control deficiency) is found, it must be reported to someone with the authority to act. The report should say what the weakness is, what could go wrong, how serious it is, and what to do. Management then agrees an action plan with owners and dates. Internal audit follows up to confirm the fix works.
Improvements should be sensible, not just more controls. Compare the cost of a control with the risk it reduces. Sometimes the right answer is to accept a small risk. The aim is a system that is proportionate, current and actually used.
Key formulas to remember
- Monitoring levels
- Management (ongoing) → Internal audit (periodic, independent) → Audit committee (review) → Board (responsible)
- Use this chain to say who does what in a scenario question.
- Content of a deficiency report
- Weakness + Risk/consequence + Recommendation + Management response
- Four parts. Missing the consequence or the recommendation loses marks.
- Cost-benefit test for a control
- Implement only if benefit of reduced risk > cost of the control
- Use it when asked whether a recommended control is sensible.
How to solve Monitoring and Review of Controls and Reporting questions
Use this method for any question on monitoring, reporting or improving controls.
- 1Read the scenario and identify who is involved: management, internal audit, audit committee, board or external auditor.
- 2Identify the weakness or the monitoring gap. Name it precisely, such as no independent review of bank reconciliations.
- 3State the risk it creates, such as undetected fraud, error or misstatement.
- 4Decide who should be told. Operational issues go to line management; serious or repeated ones go to the audit committee or board.
- 5Recommend a specific, practical improvement that links directly to the weakness.
- 6Consider cost and practicality, and say who should follow up and when.
- 7For objective test items, match your answer to the exact role or wording asked and eliminate options that give a role to the wrong party.
Quickest way: Weakness, risk, fix, owner
When to use it: Use this for multiple choice and short multi-task questions when time is tight.
- Spot the key word: monitor, report, review or improve.
- Match the role: day-to-day is management, independent testing is internal audit, oversight is the audit committee, responsibility is the board.
- For a weakness, write one line each: what is wrong, what could happen, what to change.
- Check the fix addresses the cause, not a symptom.
- Pick the option that is specific and proportionate.
Common mistakes in Monitoring and Review of Controls and Reporting
Saying internal audit is responsible for the internal control system.
Students see internal audit testing controls and assume it owns them.
Fix: The board and management are responsible. Internal audit evaluates and reports, and stays independent.
Treating the external auditor as the main monitor of controls.
Both audit roles get blended together.
Fix: External audit reviews controls only to plan its audit work and may report significant deficiencies. It does not provide a full assurance on controls.
Listing a weakness without the risk it creates.
Students rush to the recommendation.
Fix: Always link the weakness to a consequence, such as fraud or misstatement, before recommending.
Recommending vague fixes like 'improve controls' or 'hire more staff'.
It feels safe and quick to write.
Fix: Name the control, such as independent monthly review of reconciliations by a supervisor.
Ignoring cost when recommending improvements.
Students think more controls are always better.
Fix: Add a brief cost-benefit point. A control costing more than the risk it removes may not be worthwhile.
Forgetting follow-up after reporting a deficiency.
The report feels like the end of the process.
Fix: State that management agrees an action plan and internal audit checks that it was done.
Worked examples
Example 1
An internal auditor finds that the same employee raises purchase orders, receives goods and approves supplier payments in a retail company. Explain the risk, who should receive the report and one recommendation.
Show the solution
- Weakness: no segregation of duties over the purchasing cycle.
- Risk: the employee could create fake orders or suppliers and pay themselves, and errors would go undetected.
- Reporting: the finding goes to line management and the finance director. Because fraud risk is significant, the audit committee should also be informed.
- Recommendation: split the duties so that different people raise orders, receive goods and authorise payment. Add independent approval above a set limit.
- Follow-up: management sets a date, and internal audit retests later.
Answer: The lack of segregation of duties creates a risk of fraud and error. Report to management and the audit committee, and separate ordering, receiving and payment approval, with internal audit follow-up.
Example 2
Which party is primarily responsible for reviewing the effectiveness of a listed company's internal control system and reporting on it to shareholders? A) External auditor B) Board of directors C) Internal audit department D) Company secretary
Show the solution
- Responsibility for the control system sits with the board, even if work is delegated.
- The external auditor gives an opinion on the financial statements, not on the control system as a whole, so A is wrong.
- Internal audit supports the review but reports to the audit committee and does not own the system, so C is wrong.
- The company secretary handles administration and compliance advice, so D is wrong.
Answer: B) Board of directors
Exam tips
- Learn who does what: management monitors, internal audit tests independently, the audit committee oversees, the board is responsible.
- In scenario questions, always write weakness, risk and recommendation in that order.
- Make recommendations specific and tied to the facts given. Generic answers score poorly.
- In multiple response questions, select exactly the number asked. Check each option against the role described.
- Mention cost versus benefit when asked to evaluate a proposed improvement.
Practice questions from Internal controls
- At the end of each month, a finance team compares the payroll bank payments with the approved payroll listing and investigates any differenc…
- An exception report produced by Hale Co's inventory system lists only items where the physical count differs from system records by more tha…
- Which of the following is an example of a detective control rather than a preventive control?
- Who has primary responsibility for the prevention and detection of fraud in a company?
- The internal audit department of Kestrel Co reports directly to the finance director, who also decides its budget and promotion of its staff…
Monitoring and Review of Controls and Reporting in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Monitoring and Review of Controls and Reporting: frequently asked questions
Who monitors internal controls in a company?
Management does ongoing monitoring as part of daily work. Internal audit provides independent periodic testing. The audit committee oversees this on behalf of the board, which is ultimately responsible.
What does an audit committee do for internal control?
It reviews the effectiveness of the internal control system, oversees the internal audit function and receives reports on deficiencies. It also communicates with the external auditor and reports its conclusions to the board.
How should a control weakness be reported?
Report it to someone with authority to act. Include the weakness, the risk it creates, its seriousness and a practical recommendation. Management then responds with an action plan.
How do I recommend control improvements in the exam?
Link each recommendation to the specific weakness in the scenario. Make it practical, say who should do it, and note that the cost should not exceed the benefit.