Audit and Assurance · Corporate governance
Internal Control and Risk Management Responsibilities in ACCA Audit and Assurance
Updated 11 October 2026 · Fact-checked
The board is responsible for setting risk appetite, maintaining sound risk management and internal control systems, and reporting on them. Management runs the systems day to day. An internal audit function monitors them where the entity needs it. You solve exam questions by identifying the party, the duty and the reporting route.
Understand Internal Control and Risk Management Responsibilities
Corporate governance is the system by which a company is directed and controlled. Internal control is one part of it. It is the set of policies and procedures that management puts in place to achieve objectives, such as reliable reporting, effective operations and compliance with laws.
So the two terms are not the same. Governance is about who directs and oversees the entity: the board, its committees and its accountability to shareholders. Internal control is the machinery that operates inside the entity. Governance sets the tone and oversight. Internal control is one of the tools used.
Risk management comes first. The board decides which risks the entity will accept (its risk appetite), identifies the significant risks, and decides how to respond: avoid, reduce, share or accept. Internal controls are mainly the way risks are reduced. The board must review how well this works. Many governance codes expect the review to cover all material controls: financial, operational and compliance.
The board delegates. Executive management designs and operates the controls. The audit committee, made up of independent non-executive directors, oversees financial reporting, internal control, risk management and the internal audit function. It also deals with the external auditor.
Internal audit is an evaluation of the entity's activities, risk management and controls, carried out within the entity or by an outsourced provider. It is usually not required by law, so the board decides whether to have one. Governance codes typically expect listed companies without one to review annually whether it is needed. Governance reporting is then made to shareholders. Typically the annual report describes the board's review of risk and control, and confirms going concern. The external auditor reads this and considers whether it is consistent with what they know.
Key rules to remember
- Board responsibility
- Board = sets risk appetite + maintains and reviews risk management and internal control + reports on it
- The board cannot hand over its accountability, even though it delegates the operation of controls to management.
- Management responsibility
- Management = designs, implements and operates the controls
- Controls are management's job. The auditor does not take over this role.
- Audit committee role
- Audit committee = oversees reporting, controls, risk, internal audit and external auditor
- Best practice is independent non-executive directors, including relevant financial experience.
- Risk responses
- Avoid | Reduce | Share | Accept
- Internal controls mainly support the reduce response.
- Internal audit need factors
- Scale, complexity, number of employees, cost-benefit, risk, regulation and the previous record of fraud or error
- Use these as a checklist when asked if an entity needs internal audit.
- Limitation of control
- Controls give reasonable, not absolute, assurance
- Limits include collusion, management override, human error and cost.
How to solve Internal Control and Risk Management Responsibilities questions
Use this method for any scenario or written question on control, risk and governance responsibility.
- 1Read the requirement and note who is asked about: board, management, audit committee, internal audit or external auditor.
- 2Identify the entity facts: size, listed or not, complexity, existing controls and any weaknesses or incidents.
- 3State the relevant responsibility in one clear sentence, such as the board maintaining the system and management operating it.
- 4Link the responsibility to the facts in the scenario. Say what is missing or what has gone wrong.
- 5Give the recommendation: for example set up an audit committee, create an internal audit function or improve reporting.
- 6Mention the reporting route: to whom, how often and in what form, such as the annual report or a report to the audit committee.
- 7Finish with the auditor's view if asked: the auditor considers and reports, but does not take over the board's duties.
Quickest way: Who, what, report
When to use it: Use this for Section A and B objective questions and for short written parts when time is tight.
- Who: pick the party. Board owns it, management operates it, audit committee oversees it, internal audit monitors it.
- What: match the duty. Risk appetite and review is the board. Design and operation is management. Independent evaluation is internal audit.
- Report: decide where the output goes. Shareholders get the annual report. The audit committee gets internal audit reports.
- Eliminate options that put the external auditor in charge of the controls or say controls give absolute assurance.
Common mistakes in Internal Control and Risk Management Responsibilities
Treating internal control and corporate governance as the same thing.
Both deal with oversight and both appear in the same chapter.
Fix: Say that governance is the direction and oversight of the entity, and internal control is the set of procedures inside it that the governance system relies on.
Saying the external auditor is responsible for the internal control system.
Students mix up assessing controls with owning them.
Fix: State that the board and management are responsible. The auditor only obtains an understanding and may test controls for the audit.
Stating that internal audit is compulsory for all companies.
Students assume that good practice is a legal rule.
Fix: Say that it is normally a board decision based on need, and that codes expect listed companies without one to review the need regularly.
Claiming that effective controls guarantee no fraud or error.
The word effective sounds absolute.
Fix: Always say reasonable assurance and name the limits: collusion, override, error and cost.
Giving a list of factors for internal audit without applying them.
Students memorise the list and ignore the scenario.
Fix: Take each factor and link it to a fact in the scenario, then reach a conclusion about whether the entity needs the function.
Saying the audit committee runs the controls.
Oversight is confused with operation.
Fix: The committee reviews and challenges. Management operates the controls.
Worked examples
Example 1
Zeta Co is a listed company with 3,500 employees and operations in six countries. It has no internal audit function. The finance director says the external audit is enough. Discuss whether Zeta Co needs internal audit. (6 marks)
Show the solution
- Point 1: scale and complexity. 3,500 employees and six countries mean many locations and transactions, so management cannot supervise everything directly.
- Point 2: risk. A multinational faces currency, regulatory and fraud risks that need ongoing monitoring.
- Point 3: listed status. Governance codes expect the board to review the need for internal audit and explain it if there is none.
- Point 4: external audit differs. It gives an opinion on the financial statements once a year to shareholders. It does not monitor controls for management through the year.
- Point 5: cost-benefit. Zeta can probably afford the function, so cost is not a strong argument against.
- Conclusion: the finance director's view is weak.
Answer: Zeta Co should establish an internal audit function, or outsource it, reporting to the audit committee. External audit has a different purpose and does not replace it.
Example 2
The board of Kora Ltd says it has no responsibility for internal control because the finance manager designed the systems. Explain the board's responsibilities and how it should report. (5 marks)
Show the solution
- The board is ultimately responsible for maintaining sound risk management and internal control. Delegating operation to the finance manager does not remove accountability.
- The board should set risk appetite and identify the significant risks to the objectives.
- The board should review at least annually the effectiveness of the controls, covering financial, operational and compliance controls.
- The board can use the audit committee and internal audit to carry out the review, but it must consider their findings.
- Reporting: the annual report should state that the review took place, describe the process, and disclose any significant failings, and confirm going concern.
Answer: The board remains responsible for risk management and internal control. The finance manager only operates the systems. The board reports on its review to shareholders in the annual report.
Exam tips
- Always name the exact party. Writing the company is responsible scores less than the board, management or the audit committee.
- In internal audit need questions, apply each factor to the scenario and finish with a clear conclusion.
- Use the phrase reasonable assurance whenever you discuss what controls can achieve.
- In objective questions, watch for options that give the external auditor the board's duties. They are usually wrong.
- Keep written answers in short, separate points with one idea each, so the marker can see the marks.
Internal Control and Risk Management Responsibilities in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Internal Control and Risk Management Responsibilities: frequently asked questions
What is the difference between internal control and corporate governance?
Corporate governance is the overall system of directing and overseeing the entity, including the board and its committees. Internal control is the set of procedures that management operates to manage risk and achieve objectives. Governance relies on internal control as one of its tools.
Who is responsible for internal control and risk management?
The board is responsible for maintaining sound systems and reviewing them. Management designs and operates the controls. The audit committee oversees the process and the internal audit function.
Does every company need an internal audit function?
No. It is usually not a legal requirement. The board should decide based on factors such as size, complexity, risk and cost. Governance codes expect listed companies without one to review the need regularly.
How does the board report on internal controls and going concern?
Typically the annual report includes a statement that the board has reviewed the effectiveness of risk management and internal control, and the directors state whether the entity is a going concern. The external auditor considers these statements in relation to the audit.