Auditing and Ethics · Risk Assessment and Internal Control
Internal Control: Components and Limitations under SA 315
Updated 5 October 2026 · Fact-checked
Internal control is the system a company's management designs and runs to give reasonable assurance on reliable reporting, effective operations and legal compliance. SA 315 lists five components: control environment, entity's risk assessment process, process to monitor the system of internal control, information system and communication, and control activities. Controls have inherent limitations.
Understand Internal Control: Components and Limitations
Internal control is the policies and procedures that those charged with governance, management and other personnel put in place. Its purpose is to give reasonable assurance that the entity achieves its objectives. It is management's responsibility, not the auditor's. The auditor only studies it to assess the risk of material misstatement.
The objectives fall in three groups: reliability of financial reporting, effectiveness and efficiency of operations (including safeguarding assets), and compliance with applicable laws and regulations. For audit purposes, the first group matters most. Controls over operations or compliance matter only where they relate to the financial statements or the audit.
SA 315 (Revised 2019) describes five components. In the order the standard gives them, they are: control environment, entity's risk assessment process, entity's process to monitor the system of internal control, information system and communication, and control activities. The control environment, the entity's risk assessment process and the process to monitor the system of internal control are mainly indirect controls. They set the tone and do not directly prevent or detect misstatements. The information system and communication component and control activities are mainly direct controls, and they relate to processing transactions and information. Control activities also include some indirect controls, such as general IT controls. The control environment covers things like management's integrity and ethical values, commitment to competence, the participation of those charged with governance, management's philosophy and operating style, organisational structure, and assignment of authority and responsibility. Control activities include authorisation, reconciliations, segregation of duties, physical controls over assets, verification and information processing controls.
Internal control can give only reasonable assurance, never absolute assurance. The reasons are inherent limitations: human judgment can be faulty, people make mistakes, two or more people can collude, management can override controls, and controls may be designed for routine transactions only and not unusual ones. Cost is also a factor, because the cost of a control should not exceed its expected benefit. Controls can also become inadequate when conditions change, and compliance with procedures may deteriorate.
Do not confuse internal control with internal audit. Internal control is the whole system. Internal audit is one function, usually part of the monitoring component, which reviews and tests that system for management.
Key rules to remember
- Five components of internal control (SA 315)
- Control environment + Entity's risk assessment process + Process to monitor the system of internal control + Information system and communication + Control activities
- Write all five by name, in the order SA 315 (Revised 2019) gives them.
- Objectives of internal control
- Reliable financial reporting + Effective and efficient operations + Compliance with laws and regulations
- Safeguarding of assets is usually discussed under operations.
- Level of assurance
- Internal control gives reasonable assurance, not absolute assurance
- Reason: inherent limitations such as human error, collusion, management override and cost-benefit.
- Responsibility
- Design, implementation and maintenance of internal control = management and those charged with governance; understanding and evaluating it for audit = auditor
- Use this line to answer questions on who is responsible.
How to solve Internal Control: Components and Limitations questions
Questions on this topic are usually theory, a scenario to classify, or a short case asking which component or limitation applies. Use this method.
- 1Read the question and mark the verb: define, list, explain, distinguish or identify.
- 2For a definition, state who sets up internal control, what it consists of and why (reasonable assurance on the three objectives).
- 3For components, name all five first, then give one or two elements of each as the marks allow.
- 4For a scenario, find the key fact (for example, a manager overriding approval limits) and match it to the component or limitation.
- 5For limitations, give each point with a short example from the scenario, so the answer is not a bare list.
- 6For a distinction, use a two-column layout of basis and point, covering at least four bases such as meaning, responsibility, objective and reporting.
- 7Close with a one-line conclusion linking the answer to the auditor's assessment of the risk of material misstatement.
Quickest way: Match the fact to the component or limitation
When to use it: Use this for MCQs and short scenario questions where you have under two minutes.
- Ask first: is it about tone, ethics, structure or governance? The answer is the control environment.
- If it is about identifying business risks and responding to them, choose the entity's risk assessment process.
- If it is about reviewing, follow-up or internal audit checking controls over time, choose the monitoring component.
- If it is about approvals, reconciliations, segregation of duties or physical safeguards, choose control activities.
- If it is about recording, processing and reporting transactions or communicating roles, choose information system and communication.
- For limitations, look for collusion, override, human error, judgment or cost, and eliminate options that claim absolute assurance.
- In written answers, use a short heading for each component or limitation, then one line of explanation. This earns step marks quickly.
Common mistakes in Internal Control: Components and Limitations
Using the component names from the earlier version of SA 315 in an answer written under SA 315 (Revised 2019).
Older notes and books use the earlier names for the same ideas.
Fix: The earlier version used names such as 'information system, including related business processes, relevant to financial reporting, and communication', 'control activities relevant to the audit' and 'monitoring of controls'. The revised SA 315 uses 'information system and communication', 'control activities' and 'process to monitor the system of internal control'. The entity's risk assessment process kept the same name in both versions. Write the revised names.
Saying internal control gives absolute assurance or prevents all fraud.
Students think a good system must be complete.
Fix: Always write reasonable assurance and add that inherent limitations stop it from being absolute.
Treating internal control and internal audit as the same.
Both words sound alike and both involve checking.
Fix: Say internal control is a system run by management; internal audit is a function that evaluates that system and is part of monitoring.
Mixing up management override and collusion.
Both defeat controls and look similar.
Fix: Override is a person with authority bypassing controls. Collusion is two or more people acting together to defeat segregation of duties.
Putting segregation of duties under control environment.
It feels like a culture or structure matter.
Fix: Segregation of duties is a control activity. Organisational structure and the assignment of authority belong to the control environment.
Giving limitations as a bare list without examples.
Students memorise headings only.
Fix: Add one line of example for each, such as a clerk misreading an instruction for human error.
Worked examples
Example 1
Explain the inherent limitations of internal control, with one example for each. (5 marks)
Show the solution
- Start with the principle: internal control gives only reasonable assurance because of inherent limitations.
- Human error: staff may misunderstand instructions or make mistakes through carelessness or fatigue. Example: a clerk enters a wrong GST rate while booking an invoice.
- Collusion: two or more people may act together to defeat controls. Example: the storekeeper and the purchase officer jointly approve fictitious deliveries.
- Management override: a person with authority may bypass controls. Example: the finance head approves a payment beyond his limit without second approval.
- Judgment and design: controls are often designed for routine transactions, so unusual transactions may escape them. Example: a one-off asset sale not covered by the approval procedure.
- Cost-benefit and change: the cost of a control should not exceed its benefit, and controls may become outdated when conditions change.
Answer: Internal control provides reasonable, not absolute, assurance. Its inherent limitations are human error, collusion, management override, faulty judgment or design for routine transactions only, and cost-benefit considerations, as illustrated above.
Example 2
In ABC Ltd, the Board has a code of conduct that is enforced strictly, and the CEO regularly stresses ethical behaviour. Separately, the internal audit team tests purchase approvals each quarter and reports gaps to the audit committee. Identify the SA 315 components these facts relate to, and state how internal control differs from internal audit. (6 marks)
Show the solution
- The code of conduct and the CEO's emphasis on ethics relate to management's integrity and ethical values, so they fall under the control environment.
- Quarterly testing of purchase approvals by internal audit, with reporting to the audit committee, is review of controls over time, so it falls under the entity's process to monitor the system of internal control.
- Meaning: internal control is the whole system of policies and procedures, whereas internal audit is a function that evaluates that system.
- Responsibility: management and those charged with governance are responsible for internal control, whereas the internal audit function reports to management or the audit committee.
- Purpose: internal control aims at the three objectives, whereas internal audit assesses the adequacy and effectiveness of controls and suggests improvements.
- Link: internal audit is part of the monitoring component, so it is one element of internal control and not a replacement for it.
Answer: The ethical code and CEO's tone relate to the control environment. The internal audit testing and reporting relate to the monitoring component. Internal control is a system run by management; internal audit is a function that evaluates that system.
Exam tips
- Write all five components by their SA 315 (Revised 2019) names. Marks are lost when names are paraphrased too loosely.
- In scenario questions, quote the key fact from the case in your answer and then name the component. This shows application.
- For limitation questions, give at least four limitations with a one-line example each, even when the question carries only 4 marks.
- In MCQs, any option saying controls give absolute assurance or eliminate fraud is almost certainly wrong.
- Practise the internal control versus internal audit distinction with four bases. It is a frequent short-answer format.
Practice questions from Risk Assessment and Internal Control
- Ritu & Associates audits Delta Logistics Ltd, a listed company. During planning, the auditor finds that the CFO has set aggressive profit ta…
- Rao & Associates is auditing Kaveri Pharma Ltd. In the planning stage, the engagement partner proposes to assess the risk of material missta…
- Sundaram Pharma Ltd has a policy that the person who prepares bank reconciliations also has authority to approve payments and sign cheques. …
- While auditing Kaveri Textiles Ltd, the auditor identifies that the company's sales invoices are raised by a billing clerk who also has the …
- While auditing Kaveri Textiles Ltd, the auditor identifies that the company's CFO has a history of overriding journal-entry controls near qu…
Internal Control: Components and Limitations in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Internal Control: Components and Limitations: frequently asked questions
What are the five components of internal control under SA 315?
They are the control environment, the entity's risk assessment process, the entity's process to monitor the system of internal control, the information system and communication, and control activities. The auditor obtains an understanding of each when assessing the risk of material misstatement.
What is the control environment and what are its elements?
It is the set of attitudes, awareness and actions of management and those charged with governance about internal control. Elements include integrity and ethical values, commitment to competence, participation of those charged with governance, management's philosophy and operating style, organisational structure, and assignment of authority and responsibility.
What is the difference between internal control and internal audit?
Internal control is the system of policies and procedures designed and run by management to meet its objectives. Internal audit is a function that evaluates and reports on that system, and it forms part of the monitoring component. Internal control is wider, and internal audit is one tool within it.
Why can internal control not give absolute assurance?
Because of inherent limitations such as human error, collusion, management override, judgment in design and cost-benefit considerations. Controls can also be outdated when conditions change. So the best they can give is reasonable assurance.