Skip to content

Internal and Forensic Audit · Internal Controls

Internal Control Evaluation and Reporting for CS Professional

Updated 11 October 2026 · Fact-checked

Internal control evaluation means documenting a control system (narrative, flowchart, questionnaire), confirming it with walkthroughs, testing whether controls operate, judging design and operating gaps, and reporting deficiencies to management and those charged with governance, ranked by severity with recommendations.

Understand Internal Control Evaluation and Reporting

An internal auditor cannot say a control is good just because a policy exists. You must first understand what the system really is, then judge whether it is well designed, and then check whether it actually works in daily practice.

The first step is documentation. You record the system in one of three ways. A narrative is a written description of the process. A flowchart is a diagram showing documents, departments and decision points. An internal control questionnaire (ICQ) is a list of questions on each control area, usually answered Yes, No or Not applicable. A "No" answer points to a weakness. Most audits use a mix of these.

The second step is the walkthrough. You pick one transaction and trace it from start to end, for example a purchase from requisition to payment. You ask the people who do the work, see the documents and confirm that the recorded process matches reality. A walkthrough tests your understanding. It is not a full test of controls.

The third step is testing. Tests of design ask whether a control, if it works, would prevent or detect the risk. Tests of operating effectiveness ask whether it worked consistently through the period. You use inquiry, observation, inspection, re-performance and sampling. The results decide how much substantive work you still need.

The last step is reporting. A control deficiency exists when a control is missing, badly designed or not operating as intended. You assess its severity by the size of the possible misstatement or loss and how likely it is. You then report it with cause, effect, risk rating and recommendation. Serious items go to the audit committee. Management then gives its action plan, and you follow up.

Key rules to remember

Evaluation sequence
Document → Walkthrough → Test design → Test operation → Assess deficiency → Report → Follow up
Use this order in any answer. Do not test controls you have not first understood.
Deficiency assessment
Severity = Likelihood of failure × Magnitude of possible impact
A qualitative judgement, not a numeric calculation. Higher severity means escalation to senior levels.
Questionnaire reading rule
"Yes" = control present; "No" = possible weakness
Design the ICQ so that a No answer always signals a weakness. Each No must still be followed up.
Section 144 limit
Statutory auditor cannot provide internal audit services to the company
Section 144(b) bars an auditor appointed under the Act from rendering internal audit, directly or indirectly, including to its holding or subsidiary company.
Section 138 appointee
Internal auditor = chartered accountant, cost accountant or other professional decided by the Board
Section 138 applies to prescribed classes of companies. The manner and intervals of audit and reporting to the Board are set by rules.

How to solve Internal Control Evaluation and Reporting questions

Use this method for any question on evaluating or reporting internal controls. It shows the examiner provision, analysis and conclusion.

  1. 1Identify the process or area in the question (purchases, payroll, cash) and the control objective at risk.
  2. 2Choose the documentation method and justify it: narrative for simple systems, flowchart for complex flows and segregation of duties, ICQ for broad coverage.
  3. 3Describe the walkthrough: which transaction you trace, whom you ask and which documents you inspect.
  4. 4Classify each control as preventive, detective or corrective and test its design, then its operation by inspection, re-performance or sampling.
  5. 5Link each fact in the case to a gap: missing segregation, no authorisation, no reconciliation, override by management.
  6. 6Rate severity using likelihood and impact, and state whether it is a deficiency needing escalation.
  7. 7Draft the report point: observation, cause, risk, recommendation, management response and timeline.
  8. 8Conclude on the overall reliability of the control and the effect on the audit plan.

Quickest way: Five-line control evaluation answer

When to use it: Use when time is short and the question asks you to evaluate or report on a control in a case.

  1. Line 1: name the documentation tool chosen and why.
  2. Line 2: state the walkthrough done and what it confirmed.
  3. Line 3: list the gaps found from the facts, each tied to a control objective.
  4. Line 4: rate each gap as high, medium or low with a one-phrase reason.
  5. Line 5: give recommendations and say who gets the report and when you will follow up.

Common mistakes in Internal Control Evaluation and Reporting

  • Treating a walkthrough as a complete test of controls.

    Both involve looking at transactions, so they seem the same.

    Fix: Say a walkthrough confirms understanding using one transaction. Operating effectiveness needs a sample over the period.

  • Testing operation without checking design.

    Students jump to sampling because it feels like real audit work.

    Fix: First ask if the control would address the risk if it worked. A badly designed control cannot be fixed by testing.

  • Listing weaknesses without a recommendation or risk rating.

    Students stop at observation.

    Fix: Write observation, cause, risk, recommendation and management response for every point.

  • Saying the statutory auditor can also do the internal audit.

    Both roles review controls, so they get mixed up.

    Fix: Quote Section 144(b): internal audit is a prohibited service for the statutory auditor.

  • Treating every "No" in a questionnaire as a serious failure.

    Students read answers mechanically.

    Fix: Check whether a compensating control exists, then judge severity by likelihood and impact.

  • Reporting only to the process owner.

    Students forget the governance chain.

    Fix: Send significant deficiencies to senior management and the audit committee, and plan follow-up.

Worked examples

Example 1

Sharma Textiles Ltd has a decentralised purchase process across three plants. The internal auditor wants to document it. Compare the flowchart and the questionnaire and advise which to use.

Show the solution
  1. The process spans plants, departments and documents (requisition, order, goods receipt note, invoice, payment). A flowchart shows this flow and the points where one person does several tasks.
  2. A flowchart makes missing segregation of duties visible, for example the same person raising orders and receiving goods.
  3. A questionnaire covers many control points quickly and gives a standard checklist across all three plants, so results can be compared. Its limit is that Yes or No answers hide how the process really flows.
  4. Best advice: use the flowchart for the main purchase cycle and the ICQ for coverage across plants, then confirm both with a walkthrough of one purchase at each plant.

Answer: Use a flowchart for the purchase cycle to show flow and segregation, an ICQ for consistent coverage across plants, and confirm with a walkthrough of one transaction per plant.

Example 2

During a payroll review at Kaveri Pharma Ltd, you find that the HR executive who updates employee bank details also processes monthly salary, and no one reviews the change log. Evaluate and draft the reporting point.

Show the solution
  1. Control objective: salary is paid only to genuine employees at correct amounts.
  2. Design gap: no segregation between master data changes and payroll processing, and no detective control (change log review).
  3. Risk: a fictitious employee or altered bank account could receive pay without detection. Likelihood is moderate and impact can be high, so rate it high.
  4. Test operation: re-perform by extracting bank detail changes for the period and trace each to an approved request. Any change without approval confirms the failure in practice.
  5. Report: Observation, one person controls bank detail changes and salary processing and the change log is not reviewed. Cause, no defined roles in payroll. Risk, payment to wrong or fictitious accounts. Recommendation, separate the roles and have the finance head review the log monthly. Escalate to the audit committee given the rating. Follow up after the agreed date.

Answer: High-rated design deficiency: no segregation and no log review. Test changes against approvals, report with cause, risk and recommendation to management and the audit committee, and follow up.

Exam tips

  • Write answers in the order document, walkthrough, test, assess, report. It matches how examiners mark case-based questions.
  • Always attach a recommendation and risk rating to each deficiency you name. Bare lists lose marks.
  • Use the case facts. Name the person, department or document that creates the gap.
  • When Section 144 or 138 is relevant, state the rule in plain words and apply it to the facts.
  • Know the pros and cons of narrative, flowchart and questionnaire, since comparison questions are common.

Practice questions from Internal Controls

Internal Control Evaluation and Reporting in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Internal Control Evaluation and Reporting: frequently asked questions

What is the difference between a flowchart and an internal control questionnaire?

A flowchart is a diagram of how documents and activities move through a process. A questionnaire is a list of questions on controls answered Yes, No or Not applicable. The flowchart shows flow and segregation. The questionnaire gives broad, standard coverage.

What is a walkthrough test in internal audit?

You trace one transaction from start to finish through the actual process. You ask staff and inspect documents. It confirms you have understood the system correctly. It does not prove controls operate throughout the period.

What is the difference between test of design and test of operating effectiveness?

A test of design checks whether a control would prevent or detect the risk if it worked. A test of operating effectiveness checks whether it actually worked consistently during the period, usually by sampling.

Who should receive reports on control deficiencies?

Report to the process owner and management, and escalate significant deficiencies to senior management and the audit committee. Include observation, cause, risk and recommendation, then follow up on management's action.

Can the statutory auditor perform internal audit of the same company?

No. Section 144 lists internal audit as a service the statutory auditor cannot provide, directly or indirectly, to the company or its holding or subsidiary company.