Cost and Management Audit · Internal Control and Internal Audit
Internal Control Systems and Techniques for CMA Final
Updated 11 October 2026 · Fact-checked
Internal control is the set of policies and procedures that ensure management's directives are carried out. Controls are preventive, detective or corrective. Key techniques are authorisation, segregation of duties, performance reviews, information processing and physical controls. To answer a question, identify the risk in the cycle, then name the control, its type and its purpose.
Understand Internal Control Systems and Techniques
Internal control is how a business makes sure its rules are followed, its records are reliable and its assets are safe. SA 315 describes control activities as the policies and procedures that help ensure that management directives are carried out. They work in IT systems and in manual systems, at many organisational levels.
Controls can be grouped by when they act. A preventive control stops an error or fraud before it happens, for example approval of a purchase order before it is sent to the supplier. A detective control finds a problem after it has happened, for example a bank reconciliation or a review of an exception report. A corrective control fixes the problem and stops it recurring, for example correcting a wrongly posted entry and fixing the cause. A directive control, such as a policy manual, guides people to act correctly. Directive is a common extra category in textbooks, so check how your study material groups them.
SA 315 lists the main kinds of control activity: authorisation, performance reviews, information processing, physical controls and segregation of duties. Segregation of duties means giving different people the jobs of authorising transactions, recording them and keeping custody of assets. Its aim is to reduce the chance that one person can both commit and conceal an error or fraud.
Also know the difference between internal control and internal check. Internal control is the whole system: all policies and procedures, financial and non-financial. Internal check is one part of it. It is the arrangement of duties so that the work of one person is automatically checked by another, without a separate act of checking. Internal check is built into the routine; internal control is the broader framework that also includes budgets, authorisation limits, physical safeguards, IT controls and monitoring.
In practice you apply these ideas to business cycles: purchases, sales and payroll. For each cycle, ask what could go wrong, which control prevents or detects it, and who performs it.
Key rules to remember
- Control activities listed in SA 315
- Authorisation + Performance reviews + Information processing + Physical controls + Segregation of duties
- Use these five as headings when you are asked for control techniques.
- Segregation of duties
- Authorise ≠ Record ≠ Keep custody of assets
- Different people should hold these three responsibilities, so no one can both commit and conceal errors or fraud.
- Control types by timing
- Preventive (before) | Detective (after) | Corrective (fix and prevent recurrence)
- Always say when the control acts and give one example from the case.
- Information processing controls
- Application controls + General IT controls
- Application controls work on individual applications (edit checks, sequence checks, exception follow-up). General IT controls cover many applications (program change, access to programs and data).
- Physical controls
- Physical security + Authorised access to programs and data + Periodic counts compared with records
- For example, cash, security and inventory counts compared with the accounting records.
- Audit committee role, Companies Act 2013, Section 177(4)(vii)
- Terms of reference include evaluation of internal financial controls and risk management systems
- Applies to every listed public company and other prescribed classes. Minimum three directors, independent directors in majority (Section 177(2)).
How to solve Internal Control Systems and Techniques questions
Use this method for any question on internal control systems, whether it is theory or a case on purchases, sales or payroll.
- 1Read the question and identify the cycle or area: purchases, sales, payroll, stores, cash or IT.
- 2List the main risks in that cycle: unauthorised transactions, incomplete recording, wrong amounts, theft, fictitious entries.
- 3Match each risk to a control technique: authorisation, segregation of duties, performance review, information processing or physical control.
- 4Classify each control as preventive, detective or corrective, and say who performs it.
- 5Check segregation: confirm that authorising, recording and custody are with different people. Flag any case where one person does two or more of these.
- 6Note IT effects if the case uses software: application controls such as edit checks and sequence checks, and general IT controls such as access restriction.
- 7Link to monitoring: management review, internal audit or audit committee follow-up, so the control keeps working over time.
- 8Close with a clear conclusion or recommendation: the weakness found, its risk, and the control you would add.
Quickest way: Risk, control, type, who
When to use it: Use for short MCQs and for 14-mark case answers when time is tight.
- Write the risk in one line.
- Write the control that answers it.
- Tag it P, D or C (preventive, detective, corrective).
- Name the person or role, making sure it is not the same person who records or holds the asset.
- Repeat for each stage of the cycle in a short table-like list, then add one recommendation.
Common mistakes in Internal Control Systems and Techniques
Treating internal check and internal control as the same thing.
Both words appear together in study material and sound alike.
Fix: Say internal control is the whole system of policies and procedures. Internal check is one part, where work is divided so one person's work is checked by another.
Calling a bank reconciliation a preventive control.
Students focus on the word control and ignore timing.
Fix: A reconciliation finds differences after transactions are recorded, so it is detective. Approval before payment is preventive.
Naming segregation of duties without saying which duties are separated.
The phrase is memorised, not understood.
Fix: State the three: authorising, recording and custody of assets. Then show which person holds each in the case.
Ignoring IT in the case and giving only manual controls.
Older textbooks stress manual checks.
Fix: Add application controls (edit checks, numerical sequence checks, exception reports) and general IT controls (access and program change controls). IT also brings risk, such as unauthorised access that breaks segregation of duties.
Listing controls without a conclusion.
Students treat the answer as recall.
Fix: End with the weakness, its effect on reliability of records or safety of assets, and a recommended control.
Applying the same controls to every entity regardless of size.
Students forget that formality varies.
Fix: In a small entity, concepts are similar but less formal. Owner-manager authority over credit and big purchases can reduce the need for detailed controls.
Worked examples
Example 1
In Kaveri Engineering Ltd, one clerk raises purchase orders, receives goods at the gate, and posts the supplier invoices in the books. Identify the weaknesses and suggest controls, stating the type of each.
Show the solution
- Risk: the clerk can order goods that are not needed, accept short supply and record the invoice, with no one to notice. This breaks segregation of duties, since ordering, custody and recording sit with one person.
- Control 1 (preventive): purchase orders raised by the purchase department only after a requisition is approved by the authorised head. This is authorisation.
- Control 2 (preventive): goods received by the stores department, which prepares a goods received note against the order.
- Control 3 (detective): the accounts department matches the purchase order, goods received note and supplier invoice before posting. Differences are investigated.
- Control 4 (corrective): mismatches are resolved with the supplier, and wrong entries are corrected, with the cause removed.
- Control 5 (detective): periodic stock counts compared with records, and numerical sequence checks on orders and notes, with exceptions followed up.
Answer: The weakness is that one person authorises, holds custody and records. Separate these duties among purchase, stores and accounts. Add approval before ordering (preventive), a three-way match (detective), correction of mismatches (corrective) and periodic counts.
Example 2
Classify each as preventive, detective or corrective: (a) password access limited to payroll staff; (b) review of a payroll exception report showing a duplicate employee; (c) deleting the duplicate record, recovering the excess pay and restricting master-file changes.
Show the solution
- (a) Restricting access stops unauthorised changes before they occur. It is a preventive control, and a general IT control over access to programs and data.
- (b) Reviewing an exception report finds an error after it has occurred. It is a detective control. It is a manual follow-up of an exception report, an application control example.
- (c) Removing the duplicate, recovering the money and tightening master-file changes fixes the error and reduces recurrence. It is a corrective control.
- Also check segregation: the person who approves new joiners should not process payroll or disburse salaries.
Answer: (a) Preventive; (b) Detective; (c) Corrective.
Exam tips
- In MCQs, decide the timing first: before the event is preventive, after the event is detective, fixing and stopping recurrence is corrective.
- For case questions, structure the answer by cycle stage and give risk, control and type for each point.
- Always name who does what in segregation answers. Marks go to the application to the case.
- Quote the SA 315 five control activities as headings for any question on techniques, and the Section 177(4)(vii) role of the audit committee where governance is asked.
- Close every case answer with a recommendation, because examiners look for decision-oriented conclusions.
Practice questions from Internal Control and Internal Audit
- Under SA 315 as quoted, in considering audit evidence about the control environment, the auditor may also consider which of the following re…
- Which statement about the vigil mechanism under Section 177 of the Companies Act, 2013 is correct?
- Consider these statements on the vigil mechanism under Section 177 of the Companies Act, 2013. (i) The mechanism must provide adequate safeg…
- Under Section 177 of the Companies Act, 2013, which of the following is a right of the statutory auditors and key managerial personnel in re…
- In obtaining audit evidence about the control environment, SA 315 states that the auditor may also consider which of the following regarding…
Internal Control Systems and Techniques in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Internal Control Systems and Techniques: frequently asked questions
What are the types of internal controls?
By timing, controls are preventive, detective and corrective. Many textbooks add directive controls. By technique, SA 315 lists authorisation, performance reviews, information processing, physical controls and segregation of duties.
What is the difference between internal check and internal control?
Internal control is the whole system of policies and procedures that ensures directives are carried out and records are reliable. Internal check is a part of it. Duties are arranged so that one person's work is checked by another as a routine.
What is segregation of duties with an example?
It means different people authorise transactions, record them and keep custody of assets. For example, the purchase department orders, the stores department receives goods and the accounts department records the invoice.
Does the audit committee have a role in internal controls?
Yes. Under Section 177(4)(vii) of the Companies Act, 2013, its terms of reference include evaluation of internal financial controls and risk management systems. It may also call for the auditors' comments on internal control systems.