Internal Control Evaluation: Scoping, Testing, and Deficiencies

An internal control evaluation is a structured review that tests whether your organization’s controls over financial reporting are properly designed and actually operating as intended. Done well, it follows a defined sequence: scope the work using a top-down, risk-based approach against a recognized framework (almost always COSO); walk through the processes in scope; test the individual controls for design and operating effectiveness; classify any failures by severity; and report and remediate. The rest of this guide takes each of those steps in order.

What the Evaluation Has to Prove

Every evaluation is answering two separate questions about each control in scope. Design effectiveness asks whether the control, if performed properly, would prevent or detect a material misstatement. Operating effectiveness asks whether the control is actually being performed as designed, consistently, by the people responsible for it.

These are not the same thing, and mixing them up is a common failure mode. A control can be beautifully designed on paper and completely ineffective in practice if the person responsible skips the review or signs off without looking at the underlying data. Your testing has to cover both dimensions for every control you evaluate.

The Framework You Evaluate Against

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control—Integrated Framework is the most widely accepted benchmark for designing and evaluating internal controls over financial reporting.1Committee of Sponsoring Organizations of the Treadway Commission (COSO). Internal Control It organizes internal control into five components, and all five must be present and functioning for the system to be effective.

The Control Environment sets the tone: board independence, organizational structure of authority, ethical values, and the commitment to hiring competent people. A weak control environment can quietly undermine every other control in the organization, which is why experienced evaluators start here.

Risk Assessment identifies and analyzes what could go wrong, including external threats like regulatory changes and internal risks like personnel turnover. The framework explicitly requires management to consider the potential for fraud.

Control Activities are the specific actions that address identified risks: approvals, reconciliations, segregation of duties, supervisory reviews, and technology-related controls.

Information and Communication ensures relevant, high-quality information reaches the right people at the right time, internally and externally.

Monitoring Activities are the ongoing and periodic evaluations that confirm the other four components are working. The formal evaluation you’re performing is itself a monitoring activity.

Underneath those five components sit 17 principles that give evaluators a concrete checklist. Each principle should be present and functioning; a gap in any one can mean the related component is defective. When the evaluation report says a component is effective, you should be able to point to the principles that support that conclusion.

Scoping the Evaluation From the Top Down

The SEC’s interpretive guidance describes a top-down, risk-based approach as the most efficient way to structure an evaluation. Start at the financial statement level, identify where a material misstatement is most likely, then work downward to the specific controls that address those risks.2U.S. Securities and Exchange Commission. Commission Guidance Regarding Management’s Report on Internal Control Over Financial Reporting This prevents the common mistake of testing every control with equal intensity regardless of risk.

Start With Entity-Level Controls

Entity-level controls are policies, governance structures, and oversight mechanisms that operate across the whole organization rather than within a single process. Examples include the board’s oversight of financial reporting, the code of conduct, the risk assessment process led by senior finance leadership, and the company’s monitoring systems.

These controls vary in precision. Some, like a code of conduct, create an environment where process-level controls are more likely to work but don’t directly catch misstatements. Others, like management’s detailed budget-to-actual variance analysis, may operate precisely enough to address a specific risk without any additional lower-level testing.3Public Company Accounting Oversight Board. PCAOB Auditing Standard 2201 – An Audit of Internal Control Over Financial Reporting

Evaluating entity-level controls first lets you calibrate how much process-level testing you actually need. Strong, precise entity-level controls can reduce the volume of downstream testing. Weak ones (a board that rubber-stamps everything without challenge, for instance) should prompt you to expand testing at the process level.

Then Identify Significant Accounts and Assertions

Next, identify the financial statement accounts and disclosures where a material misstatement is reasonably possible. High-risk areas like revenue recognition, inventory valuation, and complex estimates typically land in scope because of their inherent complexity and the judgment involved in recording them. Use quantitative materiality thresholds to guide the decisions, but apply qualitative judgment too. An account that’s small in dollar terms can still matter if a misstatement there would change an investor’s perception.

Each control in scope should then map to one or more financial statement assertions. Auditing standards define these in categories that include existence (recorded assets and liabilities actually exist), completeness (all transactions that should be recorded are recorded), and valuation (amounts are stated at appropriate figures).4Public Company Accounting Oversight Board. Auditing Standard No. 15 – Audit Evidence A three-way match in the purchasing cycle — comparing purchase order, receiving report, and vendor invoice before paying — directly addresses the existence assertion for accounts payable.

The scope document should also explicitly identify which business units, IT systems, and specific control owners are included. Nailing this down upfront prevents scope creep during testing.

Walk Through Each Process Before Testing Controls

Before testing individual controls, perform a walkthrough of each significant process in scope. A walkthrough traces a single transaction from its origin through every processing step to the point where it hits the general ledger. PCAOB standards describe four objectives for walkthroughs: understanding how transactions flow, identifying points where misstatement could arise, identifying the controls management has implemented at those points, and identifying controls over unauthorized use of company assets.3Public Company Accounting Oversight Board. PCAOB Auditing Standard 2201 – An Audit of Internal Control Over Financial Reporting

During the walkthrough, ask the people who actually perform the work how they handle the transaction, what they check, and what happens when something looks off. These conversations often reveal more than any documentation review. A control that looks robust in a policy manual may turn out to be performed inconsistently, or the person performing it may not fully understand what they’re looking for.

Testing Individual Controls

Once you understand the process, you test the controls within it. Four evidence-gathering methods carry different weight:

  • Inquiry: Asking personnel how they perform their control responsibilities. This is the least persuasive method on its own and must always be corroborated by at least one other method. People will tell you they perform a control even when the evidence suggests otherwise.
  • Observation: Watching someone perform the control in real time, such as observing a physical inventory count or a system access review.
  • Inspection: Examining documents or system records that prove the control was performed — approval signatures, reconciliation reports, exception logs showing supervisory review.
  • Reperformance: Independently executing the control yourself to confirm the results. Recalculating depreciation expense or re-executing a bank reconciliation gives you the most direct evidence that the control works.

Reperformance is the strongest evidence because you’re not relying on someone else’s word or a signature on a page. Most evaluations use a combination of all four methods, with the mix driven by the risk of the control being tested.

Sampling

You can’t test every instance of a control that runs daily across hundreds of transactions. Sampling lets you draw conclusions about the full population from a representative subset. Appropriate sample size depends on how often the control operates, the risk of the account or assertion it addresses, whether the control is manual or automated, and the competence and consistency of the person performing it.3Public Company Accounting Oversight Board. PCAOB Auditing Standard 2201 – An Audit of Internal Control Over Financial Reporting

A daily manual control needs a significantly larger sample than a quarterly management review, because there are more opportunities for failure and more transactions at risk. Automated controls supported by effective IT general controls typically require smaller samples because the system performs the control the same way every time. Whatever method you use, apply it consistently and document both your rationale for the sample size and your selection method.

IT General Controls

Nearly every financial control today depends on technology, so IT general controls (ITGCs) are the foundation that makes application-level controls trustworthy. PCAOB standards specifically reference controls over program changes, access to programs, and computer operations as categories that must be effective for automated application controls to be reliable.3Public Company Accounting Oversight Board. PCAOB Auditing Standard 2201 – An Audit of Internal Control Over Financial Reporting

ITGC testing covers whether the right people have the right access (and only the right access) to financial systems, whether changes to those systems go through a controlled approval and testing process before deployment, and whether backups and system operations run reliably. If an organization has strong ITGCs and can verify that an automated control hasn’t changed since it was last tested, you may be able to rely on that automated control without repeating full operational testing every period. Weak ITGCs undermine confidence in every automated control that depends on them.

Classifying Deficiencies

When testing reveals a control that didn’t work as designed, the next step is determining how serious the problem is. Deficiencies fall into three tiers, and the classification drives what happens next.

  • Control deficiency: The control’s design or operation doesn’t allow the people responsible to catch misstatements while performing their normal work. An example is a required review that happens but isn’t documented, making it impossible to verify later. The vast majority of deficiencies identified in practice fall into this category.5U.S. Securities and Exchange Commission. Sarbanes-Oxley Section 404 Costs and Remediation of Deficiencies
  • Significant deficiency: A deficiency, or combination of deficiencies, less severe than a material weakness but important enough to merit attention from those overseeing financial reporting. Multiple smaller deficiencies affecting the same process or assertion can aggregate into a significant deficiency.3Public Company Accounting Oversight Board. PCAOB Auditing Standard 2201 – An Audit of Internal Control Over Financial Reporting
  • Material weakness: A deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis. “Reasonable possibility” means the likelihood is either reasonably possible or probable, which is a lower bar than many people assume.3Public Company Accounting Oversight Board. PCAOB Auditing Standard 2201 – An Audit of Internal Control Over Financial Reporting

Classifying a deficiency is a judgment call, not a formula. You’re estimating both the likelihood that the control failure could lead to a misstatement and the magnitude of that potential misstatement. A small likelihood of a massive misstatement can be just as serious as a high likelihood of a moderate one.

Reporting Results

The evaluation report should describe each deficiency clearly: what the control was supposed to do, what actually happened, and why. Identifying the root cause matters more than most teams realize. A failed reconciliation might trace back to a training gap, an understaffed accounting team, a poorly designed approval workflow, or a system that doesn’t flag exceptions properly. Each root cause points to a different fix, and getting this wrong means the problem recurs in the next evaluation cycle. Where possible, quantify the potential financial exposure, because abstract descriptions of risk don’t generate the urgency that dollar figures do.

For public companies, the stakes escalate at the material weakness level. SEC rules require management’s annual assessment to disclose any material weaknesses identified, and management cannot conclude that internal controls are effective if even one material weakness exists.6U.S. Securities and Exchange Commission. Management’s Report on Internal Control Over Financial Reporting Companies subject to auditor attestation under Section 404(b) must also have their auditor publicly report on material weaknesses existing as of the assessment date.5U.S. Securities and Exchange Commission. Sarbanes-Oxley Section 404 Costs and Remediation of Deficiencies This public disclosure can affect stock price, investor confidence, and regulatory scrutiny.

Remediation and Re-Testing

An evaluation that identifies deficiencies and stops there hasn’t accomplished much. Every deficiency needs a remediation plan with three elements: a clear owner (a specific person, not a department), concrete corrective actions (new automated controls, revised procedures, targeted training), and a realistic deadline. Vague commitments to “improve the process” accomplish nothing.

After enough time has passed for the corrective actions to take effect, re-test the remediated controls. Successful re-testing confirms the fix is designed properly and has been performing consistently, and closes the loop. Failed re-testing means the root cause analysis was wrong or the fix was inadequate, and you’re back to the drawing board. This is where many organizations lose discipline: the initial evaluation gets done rigorously, but the follow-through on remediation quietly drops off the priority list.

Between formal evaluations, embed monitoring into daily operations. Automated system checks, supervisory reviews built into transaction approval workflows, and ongoing reconciliations generate real-time signals about whether controls are holding up. This continuous feedback catches minor deviations before they compound into reportable deficiencies.

Who Is Required to Do This

Section 404(a) of the Sarbanes-Oxley Act requires management of every public company to include an assessment of internal control over financial reporting in its annual filing.7GovInfo. Sarbanes-Oxley Act of 2002 Section 404(b) adds a separate obligation: the independent auditor must attest to management’s assessment, though accelerated and large accelerated filers are the only companies subject to that second requirement, and emerging growth companies are exempt by statute.8Securities and Exchange Commission. Study of the Sarbanes-Oxley Act Section 404

Private companies aren’t subject to SOX, but many perform internal control evaluations voluntarily when preparing for an IPO, seeking financing, or responding to board or investor expectations. Federal agencies follow the GAO’s Standards for Internal Control in the Federal Government (the “Green Book”), which was revised in 2025 and takes effect for fiscal year 2026.9U.S. GAO. Standards for Internal Control in the Federal Government The methodology in this guide applies whether the evaluation is required by regulation or done by choice; the difference is only in what has to be publicly disclosed at the end.