In an audit, tests of controls are the procedures an auditor uses to determine whether a company’s internal controls actually operated effectively throughout the reporting period, not just whether they exist on paper. The results decide how much detailed transaction testing the rest of the audit requires: reliable controls mean smaller samples and lighter substantive work, while broken controls force the auditor to dig into the numbers directly.
What Tests of Controls Actually Prove
Internal controls are the policies, procedures, and system checks a company uses to keep its financial reporting accurate. A purchasing manager signs off on orders above a set threshold. The accounting system blocks a warehouse supervisor from editing the general ledger. Someone independent of cash handling reconciles the bank statement each month. Each of these is a checkpoint designed to catch or prevent errors and fraud before they reach the financial statements.
The whole reason auditors test these checkpoints rather than just cataloguing them comes down to a blunt principle: a control that exists on paper but isn’t actually followed provides zero protection. Tests of controls focus on whether the process worked, not whether the dollar amounts are correct. That’s what separates them from substantive procedures, which examine transactions and balances themselves. If the controls hold up, the auditor can rely on the system and cut back on substantive work. If they don’t, the auditor compensates by expanding detailed testing.
When Auditors Have to Run Them
Tests of controls are not always required. In a standard financial statement audit, the auditor has a choice: assume the worst about controls, set control risk at the maximum, and rely entirely on substantive procedures; or test the controls and, if they work, reduce the substantive effort.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement The decision usually comes down to efficiency. For a company with well-designed systems, testing controls and shrinking substantive work saves time overall.
Public companies are a different story. Under Sarbanes-Oxley Section 404, management must include an assessment of internal control effectiveness in every annual report,2Office of the Law Revision Counsel. 15 USC 7262 – Management Assessment of Internal Controls and the external auditor must attest to that assessment. The result is an integrated audit, where the same testing work supports both an opinion on internal controls and a reduction in substantive procedures.3Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements In an integrated audit, tests of controls are mandatory.
One rule holds either way. If the auditor wants to rely on a control to justify less substantive testing, the evidence has to show the control worked during the entire period of reliance, not just on the day someone checked.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement
The Four Techniques, Weakest to Strongest
PCAOB standards recognize four techniques for gathering evidence about whether a control works, and they rank in a clear order of persuasiveness: inquiry, observation, inspection, and reperformance.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement Auditors almost always combine them. Inquiry alone is never enough.
Inquiry
Inquiry means asking the people who perform the control how they do it, how often, and what they do when something looks wrong. It’s the starting point for almost every test because it orients the auditor to the process. But people describe what they’re supposed to do, not necessarily what they actually do. Treat it as reconnaissance, not proof.
Observation
Observation means watching someone perform the control in real time. The auditor might stand in the warehouse during a physical inventory count or watch a clerk match receiving reports to purchase orders. It’s especially useful for controls that leave no paper trail. The limitation is obvious: people tend to follow procedures more carefully when they’re being watched, and observation only proves the control worked at that moment.
Inspection
Inspection means examining the documents, records, or reports that the control produces. The auditor pulls a purchase order and checks for the required authorizing signature, or reviews a printed exception report to confirm management investigated and resolved each flagged item. Because the documentation exists independent of whether the auditor is present, inspection provides strong evidence. For controls built around approvals and sign-offs, it’s usually the primary evidence source.
Reperformance
Reperformance means the auditor independently executes the control procedure and compares results. If the company’s control involves recalculating sales commissions, the auditor plugs the same data into the same formula and checks whether the numbers match. For automated controls, reperformance may mean feeding test transactions into the system to confirm it rejects what it should reject and processes what it should process. This produces the most persuasive evidence because the auditor isn’t relying on anyone else’s work.
Walkthroughs
A walkthrough combines all four techniques. The auditor follows a single transaction from start to finish through the company’s processes, using the same documents and systems that employees use. Along the way, the auditor asks questions at each processing point, watches how people handle the transaction, inspects the documents it generates, and sometimes reperforms a control step.3Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Walkthroughs both confirm the auditor’s understanding of how transactions flow and help identify points where a misstatement could arise without being caught.
What Gets Tested
Not every control gets tested the same way, so auditors sort them into categories before designing procedures.
Preventive controls stop problems before they happen. A system that blocks unauthorized journal entries and a policy requiring two signatures on large checks are preventive. Detective controls catch problems after the fact. Monthly bank reconciliations, budget-to-actual variance reviews, and exception reports that flag unusual transactions are detective. The label doesn’t determine whether a control gets tested, but it influences how the auditor tests it and how they read a failure.
Manual controls depend on people. A supervisor physically reviews and signs an invoice before payment. An accountant compares shipping documents to sales records. These leave a paper trail the auditor can inspect but are vulnerable to human error and fatigue. Automated controls are built into the IT system. An application that refuses a sales order when a customer has exceeded their credit limit, or system-enforced access restrictions that keep unauthorized users out of sensitive functions, are automated. Once programmed correctly, they perform identically every time.
Automated controls depend on the IT infrastructure beneath them. The controls governing that infrastructure, known as IT general controls, cover who can change programs, how system access is granted and revoked, and how data is backed up. If these foundational IT controls fail, every automated control running on that system becomes suspect. Auditors test IT general controls first for exactly this reason.
Entity-level controls operate across the whole organization: the control environment, management’s ethical tone, board oversight of financial reporting, and company-wide monitoring programs. Transaction-level controls operate where individual transactions are initiated, authorized, processed, and recorded. Some entity-level controls influence every other control but don’t directly prevent or detect specific misstatements. Others, like a centralized monitoring function that reviews all journal entries over a materiality threshold, operate precisely enough that the auditor may not need to test additional controls for that risk.3Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
How Sampling Works
Auditors rarely test every occurrence of a control. They select a sample and use those results to draw conclusions about the entire population. Sampling for tests of controls differs from substantive sampling because the question is binary: did the control work, or didn’t it?
That binary focus leads auditors to attribute sampling, where each item is evaluated for a single characteristic, specifically the correct performance of the control. The goal is to estimate the deviation rate, meaning how often the control failed, across the full population.4Public Company Accounting Oversight Board. AS 2315 – Audit Sampling
Two inputs drive the sample size. The tolerable deviation rate is the maximum failure rate the auditor will accept while still concluding the control works. An auditor planning to set control risk low and rely heavily on the sample might use a tolerable rate of 5 percent or less. An auditor drawing corroborating evidence from other sources might accept 10 percent or higher.4Public Company Accounting Oversight Board. AS 2315 – Audit Sampling The expected deviation rate is the auditor’s estimate, before testing begins, of how often the control actually fails. When the expected rate creeps close to the tolerable rate, required sample sizes balloon. Eventually the math makes testing impractical, and the auditor abandons the plan to rely on that control.
Both statistical and non-statistical sampling are permitted. Statistical methods let the auditor quantify sampling risk, the chance that the sample doesn’t reflect the true population. Non-statistical methods rely on professional judgment for selection and evaluation but, applied properly, should produce sample sizes comparable to a well-designed statistical sample.4Public Company Accounting Oversight Board. AS 2315 – Audit Sampling Common selection methods include random number generation and systematic selection at fixed intervals.
After testing, the auditor projects the sample deviation rate to the entire population. If the projected rate exceeds the tolerable rate, the control is ineffective for reliance purposes, and substantive testing has to expand to compensate.
Interim Testing and the Roll-Forward
Auditors don’t have to wait until year-end. Testing controls at an interim date is common, especially on large engagements where compressing all the work into January would be impossible.
When controls are tested before year-end, the auditor performs roll-forward procedures to bridge the gap between the interim date and the reporting date. How much extra work depends on the nature and results of the interim testing, how much time remains in the period, and whether anything has changed in the control environment.3Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements In a low-risk situation where nothing has changed, inquiry may be enough. In higher-risk scenarios, the auditor has to repeat some combination of inspection, observation, or reperformance for the remaining period.
What Happens When a Control Fails
When a control fails during testing, the auditor doesn’t just record it and move on. Every failure gets evaluated for severity, and the classification has real consequences.
There are three levels. A control deficiency exists when a control’s design or operation doesn’t allow the responsible people to prevent or catch misstatements on a timely basis. A significant deficiency is a deficiency, or combination of deficiencies, less severe than a material weakness but important enough to warrant the attention of those overseeing financial reporting. A material weakness is a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement of the financial statements will not be prevented or detected on a timely basis.5Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements
The line between significant deficiency and material weakness matters enormously. A company with a material weakness cannot be considered to have effective internal control over financial reporting.3Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements For public companies, that means an adverse opinion on internal controls and mandatory disclosure in the annual report.
How the Results Change the Rest of the Audit
The results of control testing feed directly into the audit risk model, which governs how much substantive work the auditor has to perform. The model creates an inverse relationship between control risk and detection risk, where detection risk is the chance the auditor’s own substantive procedures miss a material misstatement.
When tests of controls show the system works and control risk is assessed as low, the auditor can tolerate higher detection risk. That means smaller sample sizes for confirmations, more reliance on analytical procedures rather than detailed transaction testing, and flexibility to test at interim dates rather than at year-end.
When controls fail and control risk is assessed as high, the auditor has to drive detection risk down. Larger samples. More detailed testing of individual transactions. Procedures shifted closer to the balance sheet date. The nature of the work changes too. Instead of comparing this year’s revenue trends to last year’s and investigating differences, the auditor might pull individual invoices, trace them to shipping documents, and confirm balances directly with customers.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement
When the auditor finds control deficiencies but still wants to rely on controls for a particular assertion, two options exist: test other controls that address the same assertion, or drop the reliance strategy and increase substantive testing.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement There is no middle ground where the auditor notes the failure and proceeds with the original plan.
Documentation Requirements
Every test of controls has to be documented well enough that an experienced auditor with no prior connection to the engagement could understand what was done, what evidence was obtained, and what conclusion was reached. The workpapers should include the specific control tested, who performs it, the population from which samples were drawn, the sampling method and sample size, the testing procedures applied to each item, any deviations found, and the auditor’s final conclusion on operating effectiveness.
For public company audits, federal rules require the accounting firm to retain these records for seven years after concluding the audit. The retention requirement covers not just the formal workpapers but also memos, correspondence, emails, and any other documents containing conclusions, opinions, analyses, or financial data connected to the audit, including records containing information inconsistent with the auditor’s final conclusions.6eCFR. 17 CFR Part 210 – Form and Content of and Requirements for Financial Statements
Using Internal Audit and Third-Party Reports
External auditors don’t always have to do every bit of control testing themselves. Two common sources of leverage exist: the company’s own internal audit function and service organization control reports from third-party vendors.
Before relying on internal audit’s work, the external auditor evaluates the function’s competence and objectivity. PCAOB standards direct the auditor to consider internal auditors’ education, professional certifications, audit policies, and organizational status within the company. The auditor also looks at whether internal audit has unrestricted access to records and whether management has limited their scope.7Public Company Accounting Oversight Board. AS 2605 – Consideration of the Internal Audit Function An internal audit team that reports directly to the audit committee and holds professional certifications carries more weight than one that reports to the CFO with limited training.
When companies outsource significant processes to third-party vendors, like payroll processing or cloud-based financial systems, the controls at those vendors matter too. Service Organization Control (SOC 1) reports provide a standardized way for the vendor’s own auditor to examine and report on the vendor’s controls related to financial reporting. A Type 1 report evaluates whether controls are suitably designed as of a specific date. A Type 2 report goes further, testing whether those controls actually operated effectively over a defined period. For reliance purposes, the Type 2 report is what matters, because it includes testing results rather than just a design evaluation.