Skip to content

ACCA Applied Skills · Audit and Assurance

The Use and Evaluation of Systems of Internal Control by Auditors

Auditors obtain an understanding of the entity's internal controls, evaluate whether they are designed and implemented effectively, test the ones they plan to rely on, and report deficiencies to management. The results decide how much substantive testing is needed. In the exam, you must link each control to the risk it addresses.

What this chapter covers

This chapter covers how an auditor looks at the systems a client uses to prevent, detect and correct errors and fraud. You start with the components of internal control, then learn how to understand the entity's controls, the main types of control activity, how to judge deficiencies, and how tests of controls differ from substantive procedures. It also covers computerised environments and the role of internal audit and governance.

The chapter sits at the centre of the audit process. Your understanding of controls feeds risk assessment, which shapes the audit approach and the nature, timing and extent of further procedures. If controls look strong, you can test them and reduce substantive work. If they look weak, you do more substantive testing. Later chapters on audit evidence, the completion of the audit and reporting all lean on what you conclude here.

The topic appears in both objective test cases and written questions. Objective questions test definitions, control types and the logic of reliance. Written questions usually give a scenario about a client process, such as sales, purchases or payroll, and ask you to identify deficiencies, explain their consequences and recommend improvements, or to describe tests of controls.

Internal control questions turn up regularly in the Audit and Assurance paper, in OT cases and in constructed response questions, and the skill carries across the whole syllabus. A typical written question asks you to spot weaknesses in a described system, explain the risk each creates and suggest a fix. These are marks you can win by using a fixed method rather than relying on recall. The ideas also support your answers on risk assessment, audit procedures and reporting, so the effort pays off in several places.

The use and evaluation of systems of internal control by auditors: topics in the order to study them

  1. 1Internal Control Systems and ComponentsStart here to learn what internal control is, its components and its limitations, because every later topic uses these terms.
  2. 2Understanding the Entity's Internal ControlsNext, learn how the auditor obtains that understanding and why it is needed for risk assessment.
  3. 3Control Activities and Control ProceduresOnce you know the framework, study the specific controls such as authorisation, segregation of duties and reconciliations.
  4. 4Evaluating Deficiencies and Reporting to ManagementWith the controls known, you can learn to spot weaknesses, judge their significance and communicate them.
  5. 5Tests of Controls and Substantive ProceduresThis shows how the evaluation turns into audit work and how control reliance changes substantive testing.
  6. 6Internal Controls in Computerised EnvironmentsStudy this after the manual basics, as it applies the same objectives to general and application controls in IT systems.
  7. 7Internal Audit and Governance Aspects of ControlFinish with the wider oversight layer, including internal audit, so you can link controls to governance and to the external auditor's reliance on others.

How to prepare The use and evaluation of systems of internal control by auditors

Use a method-based approach. Aim to explain each control in terms of the risk it addresses, then practise applying that to unfamiliar scenarios.

  1. Read the components and limitations of internal control until you can explain them in your own words, with one example for each.
  2. Learn the control activity types and attach each to a risk. For example, link authorisation to invalid transactions and reconciliations to errors and omissions.
  3. Practise on one business cycle at a time: sales, purchases, payroll, inventory and cash. For each, list the typical controls and the typical deficiencies.
  4. For every deficiency, write three parts: the weakness, the possible consequence, and the recommendation. Use this layout in every written answer.
  5. Separate tests of controls from substantive procedures in your notes, and write out which assertion each procedure supports.
  6. Add the computerised environment: general controls versus application controls, with examples of each.
  7. Finish with timed exam-style questions. Do objective test cases quickly, then at least a few written scenarios against a time limit.

Common mistakes in The use and evaluation of systems of internal control by auditors

  • Listing a weakness without explaining the risk it creates.

    Fix: Always write weakness, consequence and recommendation. State what could go wrong, such as fraud or error.

  • Confusing tests of controls with substantive procedures.

    Fix: Ask what the test proves. If it shows that a control operated, it is a test of controls. If it checks a balance or transaction, it is substantive.

  • Giving vague recommendations such as 'improve controls'.

    Fix: Make each recommendation specific and practical, for example that a manager independently approves changes to supplier bank details.

  • Treating all controls as reliable once they exist.

    Fix: Mention operating effectiveness, limitations and the need to test before relying on any control.

  • Mixing up general IT controls and application controls.

    Fix: General controls support the whole IT environment; application controls act on specific transactions, such as input validation checks.

  • Writing generic answers that ignore the scenario facts.

    Fix: Quote the detail from the scenario in each point and tie every control or procedure to it.

Last-day revision: The use and evaluation of systems of internal control by auditors

  • Internal control is the process designed and maintained to give reasonable assurance on reliable reporting, effective operations and compliance.
  • Controls give reasonable, not absolute, assurance because of limitations such as human error, collusion and management override.
  • The auditor must understand controls relevant to the audit, whether or not they plan to rely on them.
  • Understanding controls means evaluating design and checking implementation.
  • Key control activities include authorisation, segregation of duties, reconciliations, physical controls and performance reviews.
  • A deficiency answer has three parts: weakness, consequence, recommendation.
  • Tests of controls check operating effectiveness; substantive procedures address misstatements in figures and disclosures.
  • If controls are effective, substantive work can be reduced; if not, it must be increased.
  • Significant deficiencies must be communicated to those charged with governance in writing on a timely basis.
  • General IT controls cover access, program changes and operations; application controls work within individual programs.
  • Internal audit is part of the monitoring of controls, and the external auditor can only use its work after assessing it.
  • Objective questions are all or nothing, so read each option against the exact definition.

The use and evaluation of systems of internal control by auditors in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

The use and evaluation of systems of internal control by auditors: frequently asked questions

What is the difference between tests of controls and substantive procedures?

Tests of controls check whether a control operated effectively during the period. Substantive procedures check whether the figures and disclosures are materially misstated. The result of the control tests decides how much substantive work is needed.

How should I answer a question on control deficiencies?

For each deficiency, state the weakness, explain the risk or consequence, and give a specific recommendation. Use the facts in the scenario. A table-style layout in plain lines helps the marker see each point.

Does the auditor have to understand controls even if they will not rely on them?

Yes. The auditor needs an understanding of the relevant controls to assess the risks of material misstatement. Reliance is a separate decision that requires testing operating effectiveness.

How are internal controls tested in the objective test cases?

Expect short questions on control types, which test fits which situation, and how deficiencies affect the audit approach. Marking is all or nothing, so check the precise wording of the question before choosing.