Skip to content

Audit and Assurance · Systems of internal control

Internal Control System Components for ACCA Audit and Assurance

Updated 11 October 2026 · Fact-checked

An internal control system is the set of policies and procedures management puts in place to achieve reliable reporting, effective operations, compliance and asset protection. Its components are the control environment, risk assessment, information and communication, control activities and monitoring. It can only give reasonable, not absolute, assurance.

Understand Internal Control Systems and Their Components

An internal control system is everything management and those charged with governance set up to run the business in an orderly way. It covers policies, procedures, people and systems. Its job is to reduce the risk that something goes wrong.

The usual objectives are: reliable financial reporting, effective and efficient operations, compliance with laws and regulations, and safeguarding of assets (including prevention and detection of fraud and error). The auditor cares most about the first, because weak controls over reporting raise the risk of material misstatement.

The framework you meet in ACCA AA follows the COSO-style model and ISA 315 (Revised 2019). It has five components:

  • Control environment: the tone at the top, integrity and ethics, board and audit committee oversight, management philosophy, organisational structure and HR policies.
  • Risk assessment process: how the entity identifies business risks, judges their significance and likelihood, and decides how to respond.
  • Information system and communication: how transactions are captured, processed and reported, and how roles and responsibilities are communicated.
  • Control activities: specific actions such as authorisation, segregation of duties, reconciliations, physical controls and IT controls.
  • Monitoring of controls: ongoing and separate evaluations, including internal audit and management review, so that deficiencies are found and fixed.

No system is perfect. Inherent limitations include human error and misjudgement, collusion between employees, management override, controls aimed at routine rather than unusual transactions, cost exceeding benefit, and controls becoming out of date as the business changes. Small entities have extra problems, such as limited segregation of duties, though owner-manager involvement can partly compensate.

The auditor must understand the system to assess risk. Where controls look strong, the auditor may test them and rely on them. Where they are weak, the auditor does more substantive work.

Key rules to remember

Objectives of internal control
Reliable reporting + efficient operations + legal compliance + asset safeguarding
Use these four as a checklist when a question asks what controls are for.
Components of internal control
Control environment + Risk assessment + Information and communication + Control activities + Monitoring
Learn the five in this order. Control environment is the foundation.
Level of assurance
Internal control gives reasonable assurance, not absolute assurance
Always link this to inherent limitations such as collusion and management override.
Control risk link
Strong controls → lower control risk → less substantive testing; weak controls → higher control risk → more substantive testing
Only rely on controls after tests of controls show they operate effectively.

How to solve Internal Control Systems and Their Components questions

Use this method for any question on internal control systems, whether it asks you to define, list components, assess a scenario or explain limitations.

  1. 1Read the requirement and note the verb: explain, describe, identify, evaluate or recommend. This sets the depth.
  2. 2Decide which area is tested: objectives, components, limitations, or the scenario's weaknesses.
  3. 3If components are tested, go through the five in order and match each scenario fact to a component.
  4. 4For each point, state the fact, then the effect: what could go wrong or what risk it creates.
  5. 5For scenario questions, label each issue as a deficiency or a strength, then give a practical recommendation.
  6. 6For limitations, tie each one to the scenario, for example one person controlling cash points to a lack of segregation of duties.
  7. 7Finish with the audit link: the impact on control risk and on the audit approach.
  8. 8Check you have made enough distinct points for the marks available.

Quickest way: Five-component scan

When to use it: Use it for objective test questions and for planning a written answer in under a minute.

  1. Write C, R, I, A, M on your rough paper for Control environment, Risk assessment, Information, Activities, Monitoring.
  2. Tag each fact in the scenario with one letter.
  3. For objective questions, eliminate options that mix up components, for example calling a reconciliation part of the control environment.
  4. If an option says controls give absolute assurance or remove all fraud risk, reject it.
  5. For written answers, use each tagged letter as a paragraph heading in your plan.

Common mistakes in Internal Control Systems and Their Components

  • Confusing control environment with control activities.

    Both sound like they are about how controls are applied.

    Fix: Control environment is attitude and culture (tone at the top, governance). Control activities are specific procedures such as authorisations and reconciliations.

  • Claiming internal controls prevent all fraud and error.

    Students focus on what controls are designed to do, not what they achieve.

    Fix: Say controls give reasonable assurance only, and cite limitations such as collusion, management override and human error.

  • Listing the components without applying them to the scenario.

    Students recall the textbook list under time pressure.

    Fix: Quote the scenario fact, name the component, and explain the risk or benefit.

  • Forgetting monitoring and risk assessment as components.

    Students think of controls only as physical or authorisation checks.

    Fix: Use the C, R, I, A, M scan so all five are considered.

  • Giving limitations that are really deficiencies in one company.

    Students mix up general limitations with a specific weakness.

    Fix: Limitations apply to any system, such as cost-benefit and collusion. Deficiencies are weaknesses in this entity's design or operation.

  • Ignoring the audit consequence.

    Students answer as if they were management.

    Fix: Add a sentence on how the control assessment affects risk of material misstatement and the mix of tests of controls and substantive procedures.

Worked examples

Example 1

Describe the five components of an entity's internal control system. (5 marks)

Show the solution
  1. Control environment: the attitudes, awareness and actions of those charged with governance and management, including integrity, ethics, oversight and structure. It sets the foundation for all other controls.
  2. Risk assessment process: the entity identifies business risks relevant to financial reporting, estimates their significance and likelihood, and decides how to manage them.
  3. Information system and communication: how transactions are initiated, recorded, processed and reported, and how responsibilities are communicated to staff.
  4. Control activities: policies and procedures such as authorisation, segregation of duties, reconciliations, physical controls and IT controls.
  5. Monitoring of controls: ongoing management review and separate evaluations such as internal audit, which identify deficiencies so they can be corrected.

Answer: The five components are the control environment, the risk assessment process, the information system and communication, control activities and monitoring of controls. Each is described above with one mark per component.

Example 2

A small retailer's owner-manager also opens the post, records cash receipts, banks the takings and reconciles the bank account. There is no internal audit. Identify the control weaknesses and explain what the auditor should do. (6 marks)

Show the solution
  1. Weakness 1: no segregation of duties. One person handles receipt, recording, banking and reconciliation, so misappropriation or error could go undetected. This is a control activities deficiency.
  2. Weakness 2: no independent review of the reconciliation. The person who could hide a theft also checks for it.
  3. Weakness 3: no monitoring, as there is no internal audit or other independent review.
  4. Weakness 4: the control environment depends entirely on one person's integrity, and management override is possible.
  5. Audit consequence: control risk for cash receipts is high, and risk of material misstatement (completeness of income and existence of cash) is higher.
  6. Audit response: do not rely on controls, perform more substantive procedures such as detailed testing of receipts to bank statements and analytical procedures on sales, and consider reporting the deficiencies to management.

Answer: The entity has no segregation of duties, no independent review and no monitoring, and relies on one person. The auditor should assess control risk as high, avoid reliance on controls, increase substantive testing of cash and income, and report the deficiencies to management.

Exam tips

  • In scenario questions, quote the fact first, then name the component or deficiency, then state the risk. Marks follow this chain.
  • Objective tests often swap component names. Know exactly which component each example belongs to.
  • When asked for limitations, give general ones. When asked for weaknesses, give ones specific to the scenario.
  • Always end a written answer with the effect on the audit approach: control risk and the balance of tests of controls and substantive procedures.
  • Use short, separate points with a clear heading for each, so the marker can award a mark for each one.

Internal Control Systems and Their Components in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Internal Control Systems and Their Components: frequently asked questions

What are the components of an internal control system in ACCA AA?

They are the control environment, the entity's risk assessment process, the information system and communication, control activities and monitoring of controls. The auditor needs to understand each one to assess the risk of material misstatement.

What are the limitations of internal control?

Controls give reasonable, not absolute, assurance. Limitations include human error, collusion, management override, controls aimed at routine transactions, cost exceeding benefit and controls becoming outdated. Small entities may also lack segregation of duties.

Do I need to know the COSO framework for ACCA AA?

You should know the components, as ACCA's approach is similar. Focus on the five components as ACCA presents them and apply them to scenarios, rather than memorising the detail of any one framework.

How does internal control affect the audit approach?

If controls are strong and tests of controls confirm they work, the auditor can rely on them and do less substantive testing. If controls are weak, control risk is higher and the auditor does more substantive procedures.