Skip to content

Compliance Management, Audit and Due Diligence · Internal Audit and Performance Audit

Internal Control and Risk-Based Internal Audit Explained

Updated 11 October 2026 · Fact-checked

Internal control is the set of policies and procedures a company uses to run reliably, protect assets and comply with law. Risk-based internal audit ranks risks first, then directs audit effort to the highest-risk areas. To answer, identify risks, rate them, test controls, report gaps and follow up.

Understand Internal Control and Risk-Based Internal Audit

Internal control is the system management sets up to achieve its objectives: reliable reporting, efficient operations, protection of assets and compliance with laws. It includes policies, approvals, segregation of duties, reconciliations and monitoring.

Internal check is narrower. It is a built-in arrangement in day-to-day routine, where one person's work is automatically checked by another, for example the cashier and the person who records cash. It mainly prevents and detects errors and fraud in accounting. Internal check is a part of internal control. Internal control is the wider system, and it also covers budgets, authorisation limits, IT controls and compliance monitoring.

Internal audit is an independent review of how well governance, risk management and internal control work. It does not replace control. It tests it and recommends improvements. SA 610 (Revised) describes the typical scope of an internal audit function as assurance and consulting activities designed to evaluate and improve governance processes, risk management and internal control. This includes evaluating controls, examining financial and operating information, reviewing the economy, efficiency and effectiveness of operations, and reviewing compliance with laws and policies.

A risk-based internal audit (RBIA) starts from risk, not from a fixed checklist. The internal auditor first understands the business and identifies what could go wrong. Each risk is rated by likelihood and impact, and the risk is compared with the controls in place. Audit time then goes mostly to high-risk areas with weak controls. Low-risk areas get lighter or less frequent cover.

The approach works because audit resources are limited. It also links the audit plan to what the board and audit committee care about. The internal auditor reports on whether risks are being managed within the company's risk appetite, and then follows up on agreed actions.

Key rules to remember

Risk rating (common approach)
Risk score = Likelihood × Impact
A common scoring method, not a statutory formula. Rate each on a set scale, such as 1 to 5, and rank risks by score.
Residual risk
Residual risk = Inherent risk − Effect of controls
Conceptual, not arithmetic in the strict sense. Inherent risk is the risk before controls. Residual risk is what remains after controls.
Internal check vs internal control
Internal check ⊂ Internal control
Internal check is one part of the wider internal control system.
Conditions to rely on internal audit work (SA 610)
Objectivity + Competence + Systematic and disciplined approach (including quality control)
The external auditor evaluates all three. If the function fails any one, the external auditor shall not use its work.

How to solve Internal Control and Risk-Based Internal Audit questions

Use this order for any question on internal control or risk-based internal audit. It keeps your answer structured: concept, analysis of facts, conclusion.

  1. 1Read the facts and identify the objective: define a term, compare, design an audit approach, or advise on reliance.
  2. 2State the relevant concept in one or two lines, such as internal control, internal check or RBIA.
  3. 3Identify the risks in the facts: what could go wrong, in which process, and with what impact.
  4. 4Rate the risks by likelihood and impact, and note which controls exist and whether they are weak.
  5. 5Link the rating to the audit response: more testing and frequency for high risks, less for low risks.
  6. 6Add practical points: working papers, report to the audit committee, management action plan and follow-up.
  7. 7Close with a clear conclusion that answers the exact question asked.

Quickest way: Risk-Control-Response in three lines

When to use it: Use when time is short and the question asks you to advise on an audit approach or on reliance on internal controls.

  1. Name the top risks from the facts and rate each high, medium or low.
  2. Match each with its control and say whether the control is strong or weak.
  3. Give the audit response: heavy testing for high risk with weak control, light review otherwise, then report and follow up.

Common mistakes in Internal Control and Risk-Based Internal Audit

  • Treating internal check and internal control as the same thing.

    Both terms appear together in notes and both deal with preventing errors.

    Fix: Say that internal check is a routine arrangement within accounting where work is cross-checked, and that it is only a part of the wider internal control system.

  • Saying internal audit is the same as internal control.

    Both look at controls, so students merge the roles.

    Fix: Internal control is operated by management. Internal audit is an independent function that evaluates it and recommends improvements.

  • Describing RBIA as auditing only high-risk areas and ignoring the rest.

    The phrase 'focus on risk' is read too strictly.

    Fix: Write that lower-risk areas still get cover, but with lesser depth or frequency.

  • Writing generic theory without using the facts given.

    Students recall notes instead of analysing the case.

    Fix: Pick out the risks and weak controls from the facts and apply them one by one before concluding.

  • Saying the external auditor can always rely on internal audit work.

    Students overlook the conditions in SA 610 (Revised).

    Fix: State that the external auditor must evaluate objectivity, competence and a systematic and disciplined approach, and shall not use the work if any one is lacking.

Worked examples

Example 1

Distinguish between internal check and internal control. Is internal check sufficient for a listed company?

Show the solution
  1. Internal control is the entire system of policies and procedures that management uses to achieve reliable reporting, efficient operations, asset protection and legal compliance.
  2. Internal check is an arrangement in the routine accounting work where one person's work is checked by another, such as separating cash receipt from cash recording.
  3. Internal check is therefore one part of internal control. Internal control also includes authorisation limits, budgets, IT controls, compliance monitoring and management review.
  4. Internal check is aimed mainly at errors and fraud in accounting. Internal control has broader objectives.
  5. A listed company has complex operations, regulatory duties and many risks. Cross-checking within accounting does not cover operational risk, compliance risk or IT risk.

Answer: Internal check is a part of internal control and covers routine cross-checking in accounting. Internal control is wider. Internal check alone is not sufficient for a listed company, which needs a full internal control system plus independent evaluation through internal audit.

Example 2

Sharma Textiles Ltd has two risks: (a) frequent cash payments to many vendors with weak approval controls, and (b) an annual stationery purchase of small value with proper approval. The internal auditor must prepare a plan. Explain the risk-based approach.

Show the solution
  1. Identify the risks: payments to vendors carry fraud and error risk. Stationery purchase carries little financial exposure.
  2. Rate them: payments are high likelihood and high impact because controls are weak. Stationery is low likelihood and low impact.
  3. Allocate effort: the payments area gets detailed testing, a sample of transactions, and more frequent review in the audit plan.
  4. Stationery gets a light review, perhaps a periodic check on whether approvals are followed.
  5. Report the payment control gaps to the audit committee with recommendations, such as approval limits and segregation of duties, and follow up on implementation.

Answer: Under the risk-based approach, most audit time goes to vendor payments, which are high risk with weak controls. Stationery purchases get minimal cover. Findings go to the audit committee and are followed up until fixed.

Exam tips

  • Always give a definition first and then apply it to the facts. Pure theory scores less in case-based questions.
  • For a 'distinguish' question, write at least three points of difference and state the relationship, that internal check is part of internal control.
  • When reliance on internal audit is asked, list objectivity, competence and a systematic and disciplined approach, and state that the work cannot be used if any one fails.
  • Mention that for significant risks, an external auditor's use of internal audit work is limited to procedures involving limited judgment, as SA 610 (Revised) explains.
  • Close every answer with a clear one-line conclusion and a practical point such as audit committee reporting and follow-up.

Practice questions from Internal Audit and Performance Audit

Internal Control and Risk-Based Internal Audit in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Internal Control and Risk-Based Internal Audit: frequently asked questions

What is the difference between internal check and internal control?

Internal check is a routine arrangement in accounting where one person's work is verified by another. Internal control is the whole system of policies and procedures covering reporting, operations, assets and compliance. Internal check is a part of internal control.

What is a risk-based internal audit approach?

It is an approach where the internal auditor identifies and rates risks first, then plans audit work around the highest risks. Areas with high risk and weak controls get the most effort. Lower-risk areas get lighter cover.

How are internal control and internal audit related?

Management designs and operates internal control. Internal audit independently evaluates how well it works and recommends improvements. Internal audit is itself part of the overall control and governance structure of a company.

Can an external auditor use the internal auditor's work?

Yes, but only after evaluating the function. Under SA 610 (Revised), the auditor looks at objectivity, competence and whether a systematic and disciplined approach, including quality control, is applied. If any one is missing, the work shall not be used.