Control Objectives Examples: Cycles, Assertions, and COSO

Examples of control objectives are easiest to understand when you see them written out cycle by cycle, because an objective is the outcome a control is meant to achieve, not the procedure that achieves it. The PCAOB defines a control objective as a “specific target against which to evaluate the effectiveness of controls,” one that generally ties back to a financial statement assertion and states whether the company’s procedures give reasonable assurance that misstatements are prevented or caught in time.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements The examples below show what that looks like in practice across the revenue, expenditure, payroll, inventory, fixed asset, and IT areas most companies need to cover.

Objective vs. Activity: Read the Examples Correctly

Before working through the examples, keep one distinction clear. A control objective states the what: the outcome you need. A control activity is the how: the specific procedure that gets you there. Documentation that skips the objective ends up describing tasks without ever explaining their purpose, which makes it nearly impossible to evaluate whether controls are working.

Take the objective “all cash disbursements are for authorized business purposes.” The corresponding activity might be dual approval on payments above a set threshold, or an automated match between the purchase order, receiving report, and invoice before payment is released. The objective stays constant; activities can change as the business evolves. If a company swaps manual check signing for an electronic approval workflow, the objective hasn’t budged. Only the activity changed.

Another: the objective that revenue is recorded in the correct accounting period. A supporting activity might be an automated cutoff procedure that blocks backdating of sales entries. The objective tells you what to test for. The activity tells you where to look.

The Five Assertions Every Objective Should Touch

Every well-written control objective ties back to at least one financial statement assertion. Auditing standards identify five categories that matter for evaluating controls.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

  • Existence or occurrence: recorded transactions and balances actually happened and exist.
  • Completeness: every transaction that should be recorded is recorded.
  • Valuation or allocation: assets, liabilities, and transactions are recorded at appropriate amounts.
  • Rights and obligations: the company actually owns or owes what the statements show.
  • Presentation and disclosure: financial information is properly classified and described.

An objective that doesn’t connect to at least one of these is usually too vague to test meaningfully. As you read the examples below, notice which assertion each one is protecting.

Revenue and Cash Receipts Examples

The revenue cycle runs from customer order through cash collection, and it’s where most financial statement fraud occurs. Objectives here protect against fictitious revenue, premature recognition, and misapplied payments.

Order Entry and Recognition

The foundational objective at order entry: all recorded sales represent valid, authorized transactions with real customers (existence). A second objective addresses credit risk: customer creditworthiness is evaluated and approved before goods ship. Without that, the company books revenue it may never collect, inflating both sales and receivables.

Revenue recognition itself generates several objectives under the FASB’s five-step model, which requires companies to identify the contract, identify performance obligations, determine the transaction price, allocate that price across obligations, and recognize revenue only when each obligation is satisfied.2Financial Accounting Standards Board. Revenue from Contracts with Customers Topic 606 Written as objectives: the transaction price is determined using consistent methodology; variable consideration is estimated and constrained appropriately; revenue is recognized only when the customer obtains control of the promised goods or services.

Shipping, Billing, and Cash Receipts

Once an order is approved, the shipping objective is that all goods leaving the warehouse match the corresponding sales order. Any mismatch creates downstream billing errors that are expensive to unwind.

The billing objective is that all shipped goods are invoiced accurately and promptly. Delayed billing is one of the quieter ways companies leak revenue. Each invoice should be supported by shipping documentation before it’s recorded as a receivable.

Three cash receipts objectives dominate:

  • All cash and checks received are deposited intact, without alteration. This is the anti-skimming objective.
  • Payments are applied to the correct customer and the correct open invoice. Misapplied payments create phantom aging in receivables.
  • Receipts are recorded in the period they arrive. Holding the books open to pull next-period cash into the current period distorts revenue and receivables.

Expenditure and Accounts Payable Examples

Risks in this cycle flip from the revenue side: instead of overstating income, the concern is unauthorized spending, duplicate payments, and understated liabilities.

Purchasing and Receiving

The core purchasing objective: all purchase commitments are initiated only for legitimate business needs and approved by someone with proper authority. This prevents employees from ordering personal items on the company’s account or approving contracts that exceed their spending limits.

On the receiving end: all goods and services received are inspected and documented against the original purchase order. The receiving report captures what actually arrived, which becomes critical for the matching process downstream. Sloppy receiving means paying for goods that never arrived or accepting goods that don’t meet specifications.

Accounts Payable and Disbursements

The accounts payable objective is that all liabilities are recorded completely and in the correct period (completeness, cutoff). Unrecorded liabilities are one of the most common audit findings, and they directly understate expenses and overstate income.

Cash disbursements carry the highest fraud risk in this cycle. The primary objective: payments go out only for goods and services actually received and properly authorized. The standard supporting activity is a three-way match among purchase order, receiving report, and vendor invoice on descriptions, quantities, and prices. A secondary but equally important objective: all disbursements are recorded completely and accurately in the general ledger. Off-book disbursements are a red flag that internal controls have broken down.

Payroll Examples

Payroll is one of the largest expenses for most companies, with risks distinct from the general expenditure cycle. Ghost employees, unauthorized rate changes, and misclassified workers can all slip through without targeted objectives.

Compensation and Master Data

Primary objective: all employees are paid at authorized rates for properly documented hours worked. This covers both the accuracy of pay calculations and the validity of the underlying time records.

A related objective addresses master data integrity: all changes to employee records, including pay rates, bank account details, and tax withholding elections, are authorized before they take effect. Unauthorized changes to direct deposit information are one of the more common payroll fraud schemes, and controls typically require separation between who requests changes and who processes them.

Withholding, Deposits, and Recordkeeping

Payroll creates significant compliance obligations, and each one becomes a written objective.

All federal, state, and local tax withholdings are calculated correctly and deposited on time. The IRS imposes escalating penalties for late employment tax deposits, running from 2% for deposits one to five days late up to 15% if the deposit remains unpaid after the IRS sends a demand notice.3Internal Revenue Service. Failure to Deposit Penalty These tiers are not cumulative; the highest applicable tier is what you pay.

All quarterly Form 941 returns are filed accurately and on time, with supporting records reconciled to the general ledger. Form 941 reports wages, tips, withheld income tax, and both the employer and employee shares of Social Security and Medicare taxes, and is due by the last day of the month following each quarter.4Internal Revenue Service. Instructions for Form 941 03/2026

All wage and hour records required by federal law are maintained completely and accurately. That includes hours worked each day and each workweek, the regular hourly rate, straight-time and overtime earnings, and all additions to or deductions from wages for each nonexempt employee.5U.S. Department of Labor. Recordkeeping and Reporting

Inventory and Fixed Asset Examples

Inventory and fixed assets together often make up the largest line items on the balance sheet. Both carry heavy valuation and existence risk and both need periodic physical verification that recorded amounts reflect reality.

Inventory

Existence: everything recorded in the perpetual inventory system physically exists in the warehouse. The supporting activity is a periodic physical count reconciled to book records. Variances typically trace back to receiving errors, unrecorded scrap or spoilage, inaccurate production reporting, flawed bills of material, or shipping mistakes.

Completeness works in the other direction: all inventory the company physically possesses is recorded. This catches goods received but not yet entered, or finished goods sitting on the dock that haven’t been logged.

Valuation: inventory is carried at the lower of cost or net realizable value, with slow-moving and obsolete stock evaluated regularly. Companies that skip this evaluation often face sudden write-downs.

Fixed Assets

Capitalization: purchases above the company’s dollar threshold are recorded as assets rather than expensed, and the capitalized cost includes all directly related expenditures like freight, installation, and sales tax. A clear capitalization policy prevents inconsistent treatment that distorts both the balance sheet and the income statement.

Depreciation: all assets are depreciated using appropriate methods and useful lives, applied consistently. Useful life estimates are reviewed periodically. Changes are acceptable under GAAP but must be authorized, documented, and applied prospectively.

Disposal: all asset retirements (whether through sale, scrapping, or donation) are authorized and recorded promptly, the asset register is updated, and any gain or loss on disposal is calculated and recorded. Regular physical verification against the register catches items that were disposed of but never removed from the books.

IT General Control Examples

Nearly every objective above depends on information systems. An automated three-way match is worthless if someone can change the matching parameters without authorization. Auditing standards treat IT controls as an integral part of assessing whether business-cycle controls are effective.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

IT general control objectives fall into three areas:

  • Access: only authorized personnel can view or change data in financial systems.
  • Program change: modifications to financial applications are tested and approved before deployment.
  • Computer operations: processing runs completely, and backups protect data integrity.

When these objectives are met, the automated application controls that support cycle-level objectives operate consistently. When they aren’t, an automated control that produces the wrong answer will produce that wrong answer perfectly every time.

Grouping Objectives With the COSO Framework

Most organizations structure their objectives around the COSO Internal Control — Integrated Framework, which sorts them into three categories. Reading examples this way is a quick check that your set of objectives isn’t clustered in one area while leaving another exposed.

  • Operations objectives target the efficiency and effectiveness of business processes and the safeguarding of assets. Example: production output meets established quality benchmarks with minimal waste.
  • Reporting objectives address the reliability, timeliness, and transparency of financial and non-financial reporting. Example: quarterly financial statements are prepared in accordance with GAAP and delivered to the board within 30 days of quarter-end.
  • Compliance objectives focus on following applicable laws and regulations. Example: all employment tax deposits are made within the deadlines prescribed by the IRS.

COSO also identifies 17 principles across five components. For control activities specifically, Principle 10 calls for selecting activities that mitigate risks to acceptable levels, Principle 11 requires general controls over technology, and Principle 12 requires deploying controls through established policies and procedures. Where segregation of duties isn’t practical, the framework expects alternative controls that compensate for the concentration of responsibility.

Where to Focus: Materiality and Risk

No company builds equally robust controls around every transaction. Prioritization starts with materiality, the point at which a misstatement would influence the judgment of a reasonable investor.6Public Company Accounting Oversight Board. AS 2105 – Consideration of Materiality in Planning and Performing an Audit Objectives concentrate on the accounts and processes where the risk and potential magnitude of misstatement are highest.

Materiality isn’t purely a dollar test. Related-party transactions, executive compensation disclosures, and areas with a history of errors or fraud all justify tighter controls even when the dollar amounts are modest.6Public Company Accounting Oversight Board. AS 2105 – Consideration of Materiality in Planning and Performing an Audit When identifying which accounts deserve the most attention, factors include the size and composition of the account, its susceptibility to fraud, the volume and complexity of transactions, and whether the accounting involves significant estimates or judgment.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements That analysis is what tells you which of the examples above deserve the most careful design work in your own environment.