Skip to content

Internal and Forensic Audit · Internal Controls

Types and Techniques of Internal Controls Explained

Updated 11 October 2026 · Fact-checked

Internal controls are classified by purpose (preventive, detective, corrective, directive), by nature (manual or automated) and by level (entity-level or process-level). Answer any question by defining the type, giving a business example, stating its strength and weakness, and linking it to risk and the audit approach.

Understand Types and Techniques of Internal Controls

An internal control is any policy or procedure that gives reasonable assurance that the entity meets its objectives: reliable records, safe assets, efficient operations and compliance. Controls are not all alike. You classify them in three ways: by purpose, by nature and by level.

By purpose, there are four types. A preventive control stops an error or fraud before it happens, such as authorisation limits or a password. A detective control finds an error after it has happened, such as a bank reconciliation. A corrective control fixes the problem found and stops it recurring, such as reversing a wrong entry or patching a system. A directive control guides people to act correctly, such as a code of conduct, policy manuals and written instructions.

By nature, a control is manual (done by a person, such as a supervisor's review) or automated (built into software, such as an edit check on input data). SA 315 notes that manual controls may be more easily bypassed, ignored or overridden and are more prone to simple errors, so their consistent application cannot be assumed. It also notes that manual elements suit judgment areas: large, unusual or non-recurring transactions, hard-to-predict errors, changing circumstances, and monitoring automated controls. Automated controls suit high-volume, recurring transactions. Most entities use a mix, depending on how complex their use of IT is.

By level, entity-level controls operate across the whole organisation. Examples are the tone at the top, the code of conduct, the board and audit committee oversight, the risk management framework and the vigil mechanism. Process-level controls (also called transaction-level or activity-level controls) operate inside one process such as purchase-to-pay or payroll. Examples are three-way matching, approval of payments and segregation of duties. Strong entity-level controls support process-level controls but do not replace them.

Common control techniques include authorisation and approval, segregation of duties, physical safeguards, reconciliations, independent checks, numerical sequence checks, edit and validation checks, access controls and management review. The same technique can be preventive or detective depending on when it operates.

Key rules to remember

Preventive control
Acts BEFORE the event; stops the error or fraud
Examples: authorisation limits, segregation of duties, passwords. Lower cost of error, but can be bypassed or overridden.
Detective control
Acts AFTER the event; finds the error or fraud
Examples: reconciliations, exception reports, physical stock count, review of variances. It does not stop the error, it reveals it.
Corrective control
Acts AFTER detection; fixes the error and prevents recurrence
Examples: correcting entries, recovering from backup, system patches, disciplinary action.
Directive control
Guides behaviour towards the desired outcome
Examples: policies, manuals, code of conduct, training, written instructions.
Manual vs automated (SA 315, A59-A65)
Manual: judgment, unusual items. Automated: high volume, recurring items
Manual controls can be more easily bypassed or overridden and are more error-prone. IT helps apply predefined rules consistently and reduces the risk that controls are circumvented.
Entity-level vs process-level
Entity-level: whole organisation. Process-level: one process or transaction cycle
Entity-level controls set the control environment. Process-level controls address specific risks of misstatement in a process.

How to solve Types and Techniques of Internal Controls questions

Use this method for any question that asks you to explain, classify, compare or apply types of controls.

  1. 1Read the question and mark the classification asked for: purpose, nature, level, or technique.
  2. 2Define each type in one line, in plain words.
  3. 3Give a practical example from a named process such as purchases, payroll, sales or IT access.
  4. 4State when the control operates: before the event, after the event, after detection, or as guidance.
  5. 5Add the strength and the limitation, such as override risk for manual controls or programming errors for automated ones.
  6. 6If it is a case, apply the types to the facts: identify the gap and suggest the missing type of control.
  7. 7Conclude with a recommendation: a balanced mix of preventive, detective and corrective controls, supported by directive controls and entity-level oversight.

Quickest way: Before, After, Fix, Guide

When to use it: When you have little time and the question asks you to name or distinguish control types.

  1. Write the four purpose words in order: Preventive (before), Detective (after), Corrective (fix), Directive (guide).
  2. Attach one example to each from the same process, for example the payment process.
  3. Add two lines for nature: manual versus automated.
  4. Add two lines for level: entity-level versus process-level.
  5. Close with one line on the limitation of controls, such as collusion, override and cost versus benefit.

Common mistakes in Types and Techniques of Internal Controls

  • Calling a bank reconciliation a preventive control.

    Students think any check stops errors.

    Fix: Ask when it operates. A reconciliation runs after transactions are recorded, so it is detective.

  • Confusing corrective with detective controls.

    Both occur after the error, so they look alike.

    Fix: Detective finds the problem. Corrective repairs it and fixes the cause. Write both words with separate examples.

  • Treating directive controls as the same as preventive controls.

    Policies seem to prevent wrongdoing.

    Fix: A directive control guides and encourages correct behaviour, while a preventive control blocks the action. A manual is directive; a system block is preventive.

  • Saying automated controls never fail or need no review.

    Software seems reliable.

    Fix: Automated controls apply rules consistently, but they depend on correct design, change management and access controls. Manual monitoring and exception handling are still needed.

  • Treating entity-level controls as only the board's role.

    Students link them only with governance.

    Fix: Entity-level controls cover the control environment, risk assessment, policies, monitoring and the vigil mechanism across the whole organisation.

  • Giving only definitions with no example or application.

    Students memorise theory.

    Fix: The paper is case-based. Give a practical example and link it to the facts in the question.

Worked examples

Example 1

Classify each control as preventive, detective, corrective or directive: (a) the accounting system blocks a purchase order above ₹5,00,000 unless a director approves it; (b) the accountant prepares a monthly bank reconciliation; (c) the company issues a written procurement policy; (d) a duplicate payment found is recovered and the system is changed to flag duplicate invoice numbers.

Show the solution
  1. (a) The system stops the order before it is placed without approval. It operates before the event, so it is preventive. It is also automated and process-level.
  2. (b) The reconciliation compares bank and book balances after entries are made and reveals differences. It is detective and manual.
  3. (c) A written policy guides employees on how to buy. It is directive.
  4. (d) Recovering the amount and changing the system fixes the problem and prevents recurrence. It is corrective. The finding of the duplicate itself was detective.

Answer: (a) Preventive (automated); (b) Detective (manual); (c) Directive; (d) Corrective.

Example 2

Explain the difference between entity-level controls and process-level controls and the role of manual and automated elements, with examples. Why does an internal auditor rely on both?

Show the solution
  1. Define entity-level controls: they operate across the whole organisation and set the control environment. Examples: code of conduct, audit committee oversight, risk management framework, vigil mechanism.
  2. Define process-level controls: they operate within a specific process. Examples: three-way match of purchase order, goods receipt note and invoice before payment; approval of payroll changes; segregation of duties.
  3. Explain manual elements: performed by people and suit judgment, unusual or non-recurring transactions and monitoring of automated controls. SA 315 says they can be more easily bypassed or overridden and are more prone to simple errors.
  4. Explain automated elements: built into software and suit high-volume, recurring transactions. IT helps apply predefined rules consistently and reduces the risk of controls being circumvented.
  5. Link them: weak entity-level controls, such as poor tone at the top, undermine process-level controls even if well designed. Strong process-level controls are needed to deal with specific risks in each process.
  6. Conclude: the auditor evaluates both levels and both natures to decide where to test and how much reliance to place on controls.

Answer: Entity-level controls set the overall control environment across the organisation, while process-level controls address risks inside specific processes. Both can be manual or automated, and the auditor assesses all of them together to plan testing and assess reliance.

Exam tips

  • Always give one practical example per control type. Examiners reward application over bare definitions.
  • In case questions, identify which type of control is missing and recommend it. For example, if errors are found late, recommend preventive controls.
  • Remember that the same technique can be preventive or detective depending on when it operates. State the timing in your answer.
  • Mention the limitations of controls, such as collusion, management override and cost versus benefit, in longer answers.
  • Use SA 315 points on manual and automated controls when the question is about IT-based controls.

Practice questions from Internal Controls

Types and Techniques of Internal Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Types and Techniques of Internal Controls: frequently asked questions

What is the difference between preventive and detective controls?

A preventive control acts before an event to stop an error or fraud, such as an approval limit. A detective control acts after the event to find it, such as a reconciliation. Good systems use both.

What are entity-level controls with examples?

Entity-level controls operate across the whole organisation and shape the control environment. Examples are the code of conduct, board and audit committee oversight, the risk management framework and the vigil mechanism.

Are automated controls always better than manual controls?

No. Automated controls suit high-volume, recurring transactions and apply rules consistently. Manual controls suit judgment areas and unusual transactions. Most entities use a mix of both.

Is a directive control the same as a preventive control?

No. A directive control guides behaviour through policies, manuals and training. A preventive control actively blocks an unwanted action, such as a system restriction or an approval requirement.