Audit and Assurance · Systems of internal control
Control Activities and Types of Control in ACCA Audit and Assurance
Updated 11 October 2026 · Fact-checked
Control activities are the policies and procedures that reduce risk to an acceptable level. Preventive controls stop errors before they occur. Detective controls find errors after they occur. Common types are authorisation, segregation of duties, physical and reconciliation controls. In exams, name the control, then link it to a specific risk.
Understand Control Activities and Types of Control
An entity faces risks: errors, theft, fraud and breaches of rules. Control activities are the actions management puts in place to deal with those risks. They are one component of internal control, alongside the control environment, the risk assessment process, the information system and monitoring of controls.
Controls can be grouped by when they work. A preventive control stops a problem happening. A password stops unauthorised access. A detective control finds a problem that has already happened. A bank reconciliation finds a missing receipt. Good systems use both. Prevention is better, but nothing is perfect, so detection is the safety net.
Controls can also be grouped by how they work. A manual control relies on a person, such as a manager reviewing and signing a payment list. An automated control is performed by the system, such as a credit limit block that refuses an order. Automated controls are consistent and fast, but they depend on correct programming and on IT general controls. Manual controls are flexible and use judgement, but they can be skipped, rushed or done wrongly.
The main control activities you must know are:
- Authorisation: transactions are approved by someone with the right authority before they proceed.
- Segregation of duties: no one person handles authorisation, custody of the asset and recording of the transaction. This makes fraud need collusion.
- Physical controls: locks, safes, restricted access, security guards, and inventory counts to protect assets.
- Reconciliations: comparing two sources, such as the ledger and a supplier statement, and investigating differences.
Others include performance reviews, information processing checks (such as sequence checks and control totals) and documentation. The auditor needs to understand these controls to assess the risk of material misstatement and decide whether to test them.
Key rules to remember
- Preventive vs detective
- Preventive = stops error before it happens; Detective = finds error after it has happened
- Always say which one applies and why. Reconciliations and reviews of exception reports are usually detective.
- Segregation of duties
- Separate: authorisation, custody of assets, recording, and reconciliation/review
- Where segregation is not possible, such as in a small entity, suggest compensating management review or oversight.
- Control answer structure
- Control + what it does + risk it addresses
- Marks are awarded for the link to the risk, not for naming the control alone.
- Manual vs automated
- Automated = consistent but depends on IT general controls; Manual = flexible but prone to human error and override
- Use this when asked to compare the two.
How to solve Control Activities and Types of Control questions
Use this method for any question that asks you to identify, describe, evaluate or recommend controls.
- 1Read the requirement and note the verb: identify, explain, recommend, or test. It sets the depth you need.
- 2Underline the process in the scenario, such as purchases, payroll or cash receipts, and the weakness or risk shown.
- 3Work through the process stage by stage: initiation, authorisation, custody, recording and review. Look for a gap at each stage.
- 4Match each gap to a control type: authorisation, segregation, physical, reconciliation, or an automated check.
- 5Write each point as control, then what it does, then the risk it covers. For deficiencies write: deficiency, consequence, recommendation.
- 6Say whether the control is preventive or detective if the question asks for types.
- 7If asked about audit impact, add how the auditor would test the control or why it affects the audit approach.
- 8Check you used facts from the scenario and did not give a generic list.
Quickest way: Risk-to-control matching
When to use it: Use this in Section A and OT case questions, or when time is short in a written question.
- Ask what could go wrong in the stated process.
- If the control happens before the transaction completes, choose preventive. If it checks afterwards, choose detective.
- If one person does two incompatible jobs, such as ordering and receiving goods, the answer is segregation of duties.
- If two records are compared and differences investigated, the answer is reconciliation.
- If access to assets or systems is restricted, the answer is physical or access control.
- Eliminate options that describe a different purpose, then choose the one that fits the exact risk.
Common mistakes in Control Activities and Types of Control
Listing control names with no link to risk
Students memorise lists and write them out.
Fix: For every control write what it does and the risk it reduces. Use the scenario facts.
Calling every review a preventive control
Students assume any control is there to stop errors.
Fix: If it happens after the transaction, such as a reconciliation or exception report review, it is detective.
Treating segregation of duties as just having two people
Students miss that the duties must be incompatible.
Fix: Separate authorising, holding assets and recording. Two people doing the same type of task is not segregation.
Assuming automated controls need no further checking
Students think computers do not make errors.
Fix: Say automated controls rely on effective IT general controls such as change management and access controls.
Confusing controls with audit procedures
Both use words like checking and review.
Fix: Controls are management's actions. Tests of controls are the auditor's work on them. Keep the two separate in your answer.
Recommending segregation in a tiny business that cannot afford it
Students apply textbook answers without reading the context.
Fix: Offer practical alternatives: owner review, regular reconciliations by the owner and independent checking of key transactions.
Worked examples
Example 1
A retailer's purchasing clerk raises purchase orders, receives goods into the warehouse, and also enters supplier invoices into the ledger. Identify the control weakness and recommend two controls.
Show the solution
- The weakness is a lack of segregation of duties. One person controls ordering, custody of goods and recording.
- The risk is that the clerk could order goods for personal use, receive them and hide the cost, or record fictitious invoices, and no one would notice.
- Recommendation 1: separate roles. One person raises orders, a different person receives goods and a third records invoices. This is a preventive control because it makes fraud need collusion.
- Recommendation 2: a supervisor approves orders above a set limit and the accounts team matches orders, goods received notes and invoices before payment. The approval is preventive and the matching can also detect errors.
- Add a monthly supplier statement reconciliation by someone independent. This is a detective control that finds unrecorded or false liabilities.
Answer: The weakness is no segregation of duties over ordering, custody and recording. Recommend separating the three roles, supervisor authorisation of orders with three-way matching before payment, and an independent supplier statement reconciliation.
Example 2
A company's sales system automatically blocks orders that would take a customer over their credit limit. Each month the finance manager reviews a report of orders overridden by sales staff. Classify each control and explain the audit relevance.
Show the solution
- The credit limit block is an automated control because the system applies it without human input.
- It is preventive because it stops the order before the sale is completed. The risk addressed is sales to customers who may not pay, which affects the valuation of receivables.
- The review of overridden orders is a manual control because the finance manager performs it.
- It is detective because it checks after the overrides have already happened. It addresses the risk that staff abuse their ability to override the block.
- Audit relevance: the auditor can test the automated control cheaply by testing it once if IT general controls are effective. The auditor tests the manual review by inspecting evidence that it was done and that exceptions were followed up.
- If both work, the auditor may reduce substantive testing on the valuation of receivables.
Answer: The credit limit block is automated and preventive. The monthly override review is manual and detective. The auditor tests both, relies on IT general controls for the automated one, and may reduce receivables substantive work if both operate effectively.
Exam tips
- In OT questions, match the exact wording of the risk to the control. Wrong options often describe a real control that addresses a different risk.
- In Section C, structure each point as control, purpose and risk. This earns the explanation marks.
- Always use scenario facts such as the job titles, the system and the size of the business. Generic answers score poorly.
- When asked for deficiencies, give the deficiency, the possible consequence and a practical recommendation.
- Keep the roles clear. Management designs and operates controls. The auditor understands and tests them.
Control Activities and Types of Control in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Control Activities and Types of Control: frequently asked questions
What is the difference between preventive and detective controls?
A preventive control stops an error or fraud from happening, such as requiring approval before payment. A detective control finds it after it has happened, such as a bank reconciliation. A sound system uses both.
What are examples of segregation of duties?
The person who authorises payments should not prepare the payment run or sign the cheques alone. The person who handles cash should not record it in the ledger. The person who orders goods should not receive them or approve the supplier invoice.
Are automated controls always better than manual controls?
No. Automated controls are consistent and fast, but they rely on correct programming and effective IT general controls. Manual controls allow judgement but are open to human error and override.
How does the auditor use control activities?
The auditor gains an understanding of the controls to assess the risk of material misstatement. If the controls seem effective, the auditor may test them and reduce substantive procedures. If they are weak, more substantive work is needed.