Skip to content

Audit and Assurance · Understanding the entity and its environment and the applicable financial reporting framework

Components of Internal Control under ISA 315

Updated 11 October 2026 · Fact-checked

ISA 315 (Revised 2019) describes internal control as five components: the control environment, the entity's risk assessment process, the process to monitor the system of internal control, the information system and communication, and control activities. The auditor understands each one, then evaluates design and implementation to assess risks of material misstatement.

Understand Understanding the Internal Control System

Internal control is the system management and those charged with governance put in place to give reasonable assurance that the entity meets its objectives: reliable reporting, effective and efficient operations, and compliance with laws. The auditor needs to understand it because it affects the risk of material misstatement.

ISA 315 groups internal control into five components. Think of them as layers. The first three are indirect, entity-wide components. The last two are more specific to processes and transactions.

  • Control environment: the tone at the top. It covers integrity and ethical values, management's philosophy and operating style, commitment to competence, governance oversight such as an audit committee, organisational structure, and HR policies. It is the foundation. Weak here undermines everything else.
  • Entity's risk assessment process: how management identifies business risks relevant to reporting, assesses their significance, and decides how to respond.
  • Process to monitor the system of internal control: ongoing and separate evaluations, such as supervision, management review and internal audit, to check controls still work and fix deficiencies.
  • Information system and communication: the systems and records that capture, process and report transactions, plus how roles and responsibilities are communicated.
  • Control activities: the specific policies and procedures, such as authorisation, reconciliations, segregation of duties, physical controls and IT application controls.

The difference between the control environment and control activities is a favourite exam point. The control environment is about attitude, culture and governance across the whole entity. Control activities are the actual procedures that prevent or detect errors in specific transactions or balances.

The auditor does two things. First, understand the controls relevant to the audit, which means evaluating whether they are designed effectively and whether they have been implemented. Second, decide whether to test operating effectiveness (tests of controls) or rely only on substantive procedures. Inquiry alone is not enough to conclude on implementation, so combine it with observation or inspection.

Internal control has inherent limitations. It gives reasonable, not absolute, assurance. Limits include human error, collusion, management override, controls aimed at routine rather than unusual transactions, and cost versus benefit. Small entities often lack segregation of duties, so owner-manager involvement matters more.

Key rules to remember

Five components of internal control (ISA 315)
Control environment + Risk assessment process + Monitoring + Information system and communication + Control activities
Learn them as a list. Control environment, risk assessment and monitoring are entity-level. Information system and control activities are process-level.
Understanding controls
Understand = Evaluate design + Determine implementation
Design asks whether the control could prevent or detect a misstatement. Implementation asks whether it exists and is in use. Operating effectiveness is a separate test of controls.
Control objective link
Risk → Control → Test
For each risk, name the control that addresses it, then the test that shows it works.
Limitations of internal control
Human error, collusion, management override, cost versus benefit, focus on routine transactions
Controls give reasonable assurance, never absolute.

How to solve Understanding the Internal Control System questions

Use this method for any question on internal control components, whether it asks you to describe, evaluate or recommend.

  1. 1Read the requirement and identify the verb: describe a component, evaluate the system, or identify weaknesses.
  2. 2Match each fact in the scenario to one of the five components. Label it in the margin.
  3. 3Separate entity-level facts (culture, governance, monitoring) from process-level facts (specific procedures).
  4. 4For each weakness, state the deficiency, the risk or misstatement it creates, and the affected assertion or balance.
  5. 5Give a specific recommendation that fixes the weakness, linking it to the control that is missing.
  6. 6State the audit consequence: higher risk of material misstatement, less reliance on controls, more substantive procedures.
  7. 7Check that you have used the scenario facts and not just listed textbook points.

Quickest way: Component sorting plus deficiency-risk-fix

When to use it: Use it for Section C or OT case questions with a scenario that describes how a client operates and asks about weaknesses or components.

  1. Underline each fact in the scenario and write one letter beside it: E (environment), R (risk assessment), M (monitoring), I (information system), C (control activities).
  2. For OT questions, ask whether the fact concerns attitude and governance (environment) or a specific procedure (activity).
  3. For written answers, use three short parts per point: deficiency, risk, recommendation.
  4. Finish with one sentence on the effect on audit approach.

Common mistakes in Understanding the Internal Control System

  • Confusing the control environment with control activities.

    Both seem to be about controls, and students treat any control as a control activity.

    Fix: Ask whether it is a general culture or governance matter (environment) or a specific procedure on transactions (activity). Tone at the top, audit committee and competence belong to the environment.

  • Listing the old components or inventing extra ones, such as segregation of duties as its own component.

    Students memorise lists from older material or other sources.

    Fix: Learn the five ISA 315 components. Segregation of duties, authorisation and reconciliations are examples of control activities.

  • Describing weaknesses without saying the risk they create.

    Students stop once the problem is spotted.

    Fix: Always add what could go wrong, for example fictitious payroll or unrecorded sales, and the effect on the financial statements.

  • Saying controls eliminate fraud and error.

    Students forget that assurance from controls is reasonable only.

    Fix: Mention inherent limitations: collusion, management override, human error and cost versus benefit.

  • Confusing understanding controls with testing them.

    Both involve looking at controls.

    Fix: Understanding means evaluating design and implementation. Tests of controls assess operating effectiveness and are done only if the auditor plans to rely on controls or substantive procedures alone cannot give enough evidence.

  • Giving generic recommendations unrelated to the scenario.

    Students recall a standard list rather than reading the facts.

    Fix: Tie each recommendation to the exact deficiency, for example require independent approval for the specific payment type described.

Worked examples

Example 1

Section C style: A client is a family-owned wholesaler. The managing director, who owns 80% of the shares, approves all journals and overrides credit limits for favoured customers. There is no audit committee and no internal audit function. Sales invoices are raised by the same clerk who records cash receipts. Identify the weaknesses by ISA 315 component and explain the effect on the audit.

Show the solution
  1. Control environment: the dominant owner who overrides controls shows weak tone at the top and a risk of management override. There is no audit committee, so governance oversight is absent.
  2. Monitoring: there is no internal audit function and no other evidence of review, so deficiencies may go undetected.
  3. Control activities: the same clerk raises invoices and records receipts, which is a lack of segregation of duties and creates a risk of teeming and lading or misappropriated cash. Credit limit overrides weaken authorisation controls and increase the risk of irrecoverable receivables.
  4. Effect on audit: the auditor assesses a higher risk of material misstatement, especially for revenue and receivables, and is unlikely to rely on controls.
  5. Response: perform more extensive substantive procedures, such as receivables confirmations and testing of journals, and keep professional scepticism high.

Answer: Weak control environment (override, no audit committee), no monitoring, and poor control activities (no segregation of duties, overridden credit limits). The auditor treats the risk as high, avoids reliance on controls and expands substantive procedures.

Example 2

OT style: An auditor notes that a client's board regularly reviews a risk register, and management updates it when new business risks arise. Which ISA 315 component does this describe? A. Control environment B. Entity's risk assessment process C. Control activities D. Information system

Show the solution
  1. The facts describe management identifying and responding to business risks.
  2. That matches the entity's risk assessment process.
  3. The control environment concerns culture and governance, not the risk process itself.
  4. Control activities are specific procedures on transactions, and the information system captures and reports transactions.

Answer: B. Entity's risk assessment process

Exam tips

  • In scenario questions, tag every fact with its component before writing. It stops you mixing environment and activities.
  • Always give three parts for each weakness: deficiency, risk and recommendation. Marks are usually awarded for each part.
  • Mention that controls give reasonable assurance only when asked about limitations. Use specific limits, not just the word limitations.
  • Link your answer to audit approach: weak controls mean more substantive work, and strong controls allow tests of controls and possible reliance.
  • In OT questions, read all four options, since several may sound like controls. Choose the one that matches the exact component definition.

Understanding the Internal Control System in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Understanding the Internal Control System: frequently asked questions

What are the five components of internal control under ISA 315?

They are the control environment, the entity's risk assessment process, the process to monitor the system of internal control, the information system and communication, and control activities. Learn them together, because exam questions often ask you to classify a fact into one of them.

What is the difference between the control environment and control activities?

The control environment is the entity-wide culture, governance and attitude to control. Control activities are specific procedures, such as authorisation, reconciliations and segregation of duties, that operate on transactions and balances. A weak environment can undermine good activities.

How does an auditor evaluate internal controls?

The auditor understands the relevant controls, evaluates whether they are suitably designed, and determines whether they have been implemented. This uses inquiry, observation, inspection and walk-through tests. Tests of controls then check operating effectiveness if reliance is planned.

What are the limitations of internal control?

Controls give reasonable, not absolute, assurance. Limits include human error, collusion, management override, focus on routine transactions and the need to weigh cost against benefit. Small entities may also lack segregation of duties.