Audit and Assurance · Tests of controls
Evaluating Control Test Results and the Impact on the Audit Approach
Updated 11 October 2026 · Fact-checked
After testing controls, you decide whether they worked. If they did, you rely on them and can reduce substantive work. If they failed, control risk is high, so you extend substantive procedures and report the deficiencies to management or those charged with governance in writing.
Understand Evaluating Results and Impact on the Audit Approach
A test of controls checks whether a control operated effectively throughout the period. You do it because you planned to rely on that control. Reliance lets you do less substantive testing.
The link is the audit risk model: audit risk = risk of material misstatement × detection risk. Risk of material misstatement is made up of inherent risk and control risk. Control risk is the risk that the client's controls fail to prevent or detect a misstatement. Detection risk is the risk that your own procedures fail to find a misstatement. You do not control control risk. You control detection risk through the nature, timing and extent of substantive procedures.
The two move in opposite directions. If controls are effective, control risk is lower. You can accept higher detection risk, so you do less substantive work. If controls fail, control risk is higher. You must lower detection risk, so you do more extensive, more reliable substantive work, closer to the year end, and often with larger samples.
When a control test finds an exception, do not just count it. Find out why it happened. Was it a one-off error or a systematic failure? Could it affect the whole population? Then judge whether the control can still be relied on. If not, you plan substantive procedures on the assumption that controls are weak.
You must also communicate. Under ISA 265, you report significant deficiencies in internal control in writing, on a timely basis, to those charged with governance. Whether a deficiency is significant is a matter of your professional judgement: it is significant if it is of sufficient importance to merit their attention. Other deficiencies are communicated to management, orally or in writing, where they merit management's attention and management has not already been told. A deficiency is not the same as a misstatement. It is a weakness in the system that could allow one.
Key rules to remember
- Audit risk model
- Audit risk = Risk of material misstatement (inherent risk × control risk) × Detection risk
- Inherent risk × control risk together make the risk of material misstatement. Acceptable audit risk is set first. Detection risk is then the balancing figure that you set through substantive procedures.
- Control risk and detection risk
- Lower control risk → higher acceptable detection risk → less substantive work. Higher control risk → lower acceptable detection risk → more substantive work.
- The inverse link is the exam answer. You set detection risk through substantive procedures.
- Deficiency reporting rule
- Significant deficiencies → in writing to those charged with governance; other deficiencies → to management (orally or in writing) if they merit management's attention and management is not already aware.
- Based on ISA 265. Whether a deficiency is significant is a matter of judgement. Report on a timely basis. Include description, potential effects and recommendations.
- Management letter point structure
- Deficiency + Possible consequence + Recommendation
- Use this three-part structure for every point in a written answer.
How to solve Evaluating Results and Impact on the Audit Approach questions
Use this method for any question on the results of tests of controls.
- 1Identify what the control was meant to prevent or detect, and which assertion or balance it protects.
- 2Decide whether each result shows a deficiency. Ask if it is isolated or systematic, and whether it affected the whole period.
- 3Conclude on reliance. If the control is effective, you may rely on it. If not, you cannot.
- 4State the effect on control risk, then on detection risk. Use the inverse link in words.
- 5Change the substantive procedures: nature (more reliable evidence), timing (at or after year end) and extent (larger samples).
- 6Say what the deficiency could lead to. Tie it to a specific misstatement or fraud risk, not a general worry.
- 7Give a recommendation for management that fixes the cause of the deficiency.
- 8Say who is told and how. Significant deficiencies go in writing to those charged with governance. Other deficiencies that merit attention go to management, orally or in writing, if management does not already know. Significance is a judgement, so explain why.
Quickest way: Result, risk, response, report
When to use it: Use it for Section A and B questions and for short written parts in Section C when time is tight.
- Result: did the control work? Yes or no.
- Risk: if yes, control risk is lower. If no, control risk is higher.
- Response: lower control risk means less substantive work. Higher means more.
- Report: write the deficiency, its effect and a fix for management.
- For multiple choice, look for the option that keeps control and detection risk moving in opposite directions.
Common mistakes in Evaluating Results and Impact on the Audit Approach
Saying that effective controls mean no substantive procedures are needed.
Students over-read the idea of reliance.
Fix: Say substantive work is reduced, not removed. Material balances and significant risks always need some substantive testing.
Confusing control risk with detection risk.
Both sound like risks of missing errors.
Fix: Control risk belongs to the client's system. Detection risk belongs to the auditor's procedures. Only detection risk is set by the auditor.
Listing deficiencies without consequences or recommendations.
Students stop at identifying the problem.
Fix: Write each point as deficiency, possible effect, recommendation. Marks are given for all three.
Treating a deficiency as proof of misstatement.
A failed control feels like an error.
Fix: A deficiency raises the risk of misstatement. You respond with more substantive work to find out if there is one.
Reporting every deficiency to the board in writing.
Students ignore the significant versus other distinction.
Fix: Significant deficiencies go in writing to those charged with governance. Other deficiencies go to management.
Suggesting substantive work only at the interim date after failed controls.
Students forget that timing is a lever.
Fix: When controls are weak, move testing nearer to or after the year end and use larger samples.
Worked examples
Example 1
You test the control that each sales invoice is matched to a goods despatched note before posting. In a sample of 40 invoices, 6 had no matching note. Explain the effect on your audit approach and what you would report.
Show the solution
- The control is meant to ensure that sales recorded are for goods actually despatched. It relates to occurrence of revenue and to cut-off.
- 6 exceptions out of 40 is a high rate. It suggests the control is not operating consistently, not a one-off slip.
- Conclusion: you cannot rely on the control. Control risk for revenue is assessed as high.
- Detection risk must be lowered. You do more substantive work on revenue and receivables.
- Nature: use more reliable evidence. Vouch a sample of recorded sales invoices back to despatch records, because going from the invoice to the despatch note tests occurrence (overstatement). Also select despatch notes and trace them forward to sales invoices, because going from the despatch note to the invoice tests completeness and cut-off (goods sent but not invoiced). Also obtain customer confirmations of receivables.
- Timing: perform procedures at or after the year end rather than relying on interim work, including cut-off tests on despatches and invoices either side of the year end.
- Extent: increase sample sizes for revenue and receivables testing.
- Report: the deficiency is that invoices are posted without a despatch note. The possible effect is overstated revenue and receivables. The recommendation is to block posting unless a matched despatch note is on file, with a supervisor reviewing exceptions. This deficiency is likely to be significant because the exception rate is high (6 out of 40) and revenue is a material, high-risk area where the potential misstatement is large. This is a matter of judgement. Report it in writing to those charged with governance.
Answer: Do not rely on the control, treat control risk as high, and extend substantive testing of revenue and receivables. Key procedures include vouching sales invoices to despatch records (occurrence), tracing despatch notes to invoices (completeness and cut-off), cut-off testing and confirming receivables. This is not an exhaustive list. Report the significant deficiency in writing to those charged with governance, with its effect and a recommendation.
Example 2
Your tests show the purchase ordering controls operated effectively all year. Explain how this affects detection risk and the substantive procedures on trade payables.
Show the solution
- Effective controls mean control risk for purchases and payables is assessed as lower.
- With lower control risk, the risk of material misstatement falls. For the same audit risk, you can accept a higher detection risk.
- Higher acceptable detection risk means substantive procedures can be reduced.
- Nature: you can use less persuasive evidence, such as analytical procedures alongside tests of details.
- Timing: more testing can be done at an interim date.
- Extent: you can use smaller samples.
- Caution: payables have a completeness risk that controls over ordering may not address. So you still perform some tests, such as the search for unrecorded liabilities.
Answer: Control risk is lower, so acceptable detection risk is higher. Substantive procedures on payables can be reduced in nature, timing and extent, but not removed.
Exam tips
- Always state the inverse link between control risk and detection risk in words. Examiners reward it directly.
- In written answers, name nature, timing and extent when you explain changes to substantive procedures.
- Use a three-part structure for every management letter point: deficiency, effect, recommendation.
- In objective questions, check who owns the risk. Auditor-controlled means detection risk.
- Link recommendations to the cause of the deficiency in the scenario, not to generic advice.
Evaluating Results and Impact on the Audit Approach: frequently asked questions
What is the difference between control risk and detection risk?
Control risk is the risk that the client's controls fail to prevent or detect a material misstatement. Detection risk is the risk that your audit procedures fail to find one. You assess control risk and you set detection risk through your substantive work.
How do test of controls results affect substantive testing?
Effective controls lower control risk, so you can reduce substantive testing. Ineffective controls raise control risk, so you extend it. You adjust the nature, timing and extent of the procedures.
Who do I report control deficiencies to?
Report significant deficiencies in writing to those charged with governance on a timely basis. Report other deficiencies that merit attention to management. Each point should give the deficiency, its possible effect and a recommendation.
Can I rely on controls if I found a few exceptions?
It depends on why the exceptions happened and how many there were. An isolated, explained exception may not stop reliance. A systematic or frequent failure does. State your judgement and give the reason.