Preventative vs Detective Controls: SOX and Audit Testing

Preventive controls stop problems before they happen. Detective controls find problems after they occur. That single difference in timing drives everything else about how the two types of internal controls are designed, what they cost, and where each one belongs in your organization. The federal government’s own internal control standards frame the distinction the same way: a preventive control avoids an unintended event before it materializes, while a detective control discovers and corrects one after the fact.1U.S. Government Accountability Office. Standards for Internal Control in the Federal Government A working control system needs both, because neither type catches everything the other misses.

What Preventive Controls Do

Preventive controls are the locks on the door. They sit inside a workflow or system and block an unwanted action from completing, so if the control works correctly, the error or fraud never happens at all.

A system that refuses to release an invoice payment above $10,000 without manager approval is a preventive control. So is requiring two separate people to initiate and approve a wire transfer, which keeps any single employee from moving money alone.2NCUA. Wire Transfer Internal Controls – Examiners Guide The three-way match in accounts payable is another common one: before a check goes out, the system checks the purchase order, receiving report, and invoice against each other, and blocks payment if they don’t line up. In IT, multi-factor authentication is preventive because even a stolen password will not, on its own, get an attacker in.3National Institute of Standards and Technology. Multi-Factor Authentication

These controls tend to cost more upfront. Designing, programming, and testing an automated approval rule takes real investment before it blocks a single transaction. That front-loaded cost usually pays for itself by eliminating the cleanup that follows an undetected error. A miscoded payment stopped at the gate costs you nothing; the same payment discovered six months later during a reconciliation can trigger restatements, audit findings, and regulatory attention.

The limitation is straightforward. Preventive controls only handle the risks you anticipated when you designed them. A rule that blocks payments over $10,000 does nothing about a fraudulent payment for $9,999. Collusion between two employees can defeat a segregation-of-duties requirement. System misconfigurations can silently disable an approval gate. This is exactly why detective controls exist.

What Detective Controls Do

Detective controls are the surveillance cameras. They monitor what already happened and flag anything that looks wrong. A monthly bank reconciliation comparing the general ledger balance to the bank statement is the classic example. It will not stop an unauthorized withdrawal, but it will reveal one after it clears the bank.1U.S. Government Accountability Office. Standards for Internal Control in the Federal Government

The output of a detective control is usually an exception report, an alert, or a log entry showing that something did not match expectations. A daily review of wire transfer logs by an independent analyst is detective. A nightly scan of firewall logs for repeated failed login attempts is detective. A quarterly check of user access rights, confirming that people who changed roles lost their old permissions, is detective. Each one catches problems that slipped past the preventive barriers.

Detective controls carry lower startup costs but create ongoing operational expense. Someone has to review the reports, investigate exceptions, and escalate findings. When organizations understaff that review process, the detective controls become decorative: reports pile up, exceptions go unread, and the control exists only on paper. Their value depends entirely on how quickly you act once the control surfaces the issue.

The Core Differences Side by Side

The core difference is timing. Preventive controls operate before the risk event, blocking it from completing. Detective controls operate after the event, discovering it so the damage can be measured and contained. Every other distinction flows from that.

Objectives follow naturally. A well-designed preventive control aims for zero occurrences of the targeted risk. A well-designed detective control aims for rapid identification, so losses stay small and corrective action starts quickly. If your detective control only catches a problem at the end of the quarter, you’ve had months of compounding damage.

Cost structures also differ in predictable ways. Preventive controls concentrate their costs at implementation: system development, configuration, testing. Detective controls spread their costs over time: staffing the review function, maintaining monitoring systems, investigating exceptions. Organizations that invest heavily in preventive controls generally see fewer exceptions, which reduces the workload on the detective side.

Reliability is the last big split. Automated preventive controls, like system-enforced approval thresholds, operate consistently every time a transaction hits the rule. They do not get tired or distracted. Manual detective controls, like a human reviewer scanning an exception report, are more susceptible to fatigue, turnover, and inconsistency. Organizations that rely heavily on manual detective controls need to test them more often to confirm they are actually working.

Examples in the Same Process

The two control types usually work best when they cover the same risk from different angles. A few pairings show how that looks in practice.

In accounts payable, the three-way match prevents payment for goods you didn’t order or receive. The monthly bank reconciliation then catches anything that slipped through, along with unauthorized transactions, posting errors, and timing differences. In cash-heavy businesses, an unannounced cash count plays the same detective role: a manager physically counts what is on hand and compares it to what the books say should be there.

Segregation of duties is preventive across the whole financial cycle. No single person should be able to create a vendor, approve an invoice, and release payment. Splitting those responsibilities forces collusion rather than solo fraud. The detective complement is a periodic review of who actually performed each step, looking for patterns where one person handled too many parts of a transaction.

In IT, restricting production database access to authorized staff is preventive: a marketing employee’s credentials cannot reach the database at all, so they cannot accidentally or intentionally alter records. Quarterly user access reviews then catch privilege creep, where someone who transferred departments months ago still has permissions from their old role.

Physical controls follow the same pattern. A key card and biometric scan at a data center entrance make unauthorized access nearly impossible without defeating the hardware. Weekly review of CCTV footage and access logs then identifies tailgating, propped doors, or any other bypass. Time-delay safes in retail and banking work as a less obvious preventive control by building in a waiting period that deters theft, with the unannounced cash count providing detective coverage.

Why You Need Both

Relying exclusively on either type creates blind spots. An organization with only preventive controls has no way of knowing when those controls fail, and they will fail eventually. An organization with only detective controls is stuck in a permanent cycle of discovering and cleaning up problems that better design could have prevented.

The practical approach is layered. Preventive controls go where the risk is highest and the transaction volume makes after-the-fact review impractical. Automated approval gates, access restrictions, and segregation of duties handle the bulk of routine risk. Detective controls then cover the gaps: they catch edge cases the preventive rules did not anticipate, confirm that automated controls are still configured correctly, and surface patterns that suggest systemic weaknesses.

The most valuable thing detective controls produce is not the individual exception. It is the intelligence about why the preventive layer failed. When your reconciliation keeps catching the same vendor mismatch, or your access review keeps finding the same orphaned accounts, that pattern tells you where to invest in better prevention. The GAO’s standards define corrective actions as changes that address either the event itself or the deficiencies in the process that allowed the event to happen.1U.S. Government Accountability Office. Standards for Internal Control in the Federal Government Organizations that treat detective findings as a to-do list for preventive improvement build control environments that get stronger over time rather than just staying busy.

What This Means Under Sarbanes-Oxley

For public companies, the mix of preventive and detective controls is not just operational hygiene. It is a legal requirement. Under Section 404 of the Sarbanes-Oxley Act, every annual report must include management’s own assessment of whether internal controls over financial reporting are effective, and for larger public companies the independent auditor must also examine and report on that assessment.4Office of the Law Revision Counsel. 15 U.S. Code 7262 – Management Assessment of Internal Controls

A material weakness, meaning a deficiency serious enough that a material misstatement in the financial statements could go undetected, must be disclosed.5U.S. Securities and Exchange Commission. Small Business Compliance Assistance – Section 404 of the Sarbanes-Oxley Act of 2002 That disclosure requirement is why detective controls matter so much from a regulatory standpoint. Without functioning detective mechanisms, a company cannot credibly claim its controls are effective, because it has no way of knowing whether its preventive barriers have failed. The SEC has charged public companies that reported material weaknesses year after year without fixing them, with penalties ranging from $35,000 to $200,000 in one group of cases along with required independent consultants to oversee remediation.6U.S. Securities and Exchange Commission. SEC Charges Four Public Companies With Longstanding ICFR Failures

How Auditors Test Whether Controls Actually Work

Saying a control exists is not the same as proving it works. Auditors test controls in two dimensions: design effectiveness (is the control built to achieve its objective?) and operating effectiveness (has it actually worked throughout the period?).7PCAOB. Auditing Standard No. 13 – The Auditors Responses to the Risks of Material Misstatement

To evaluate design, auditors typically perform walkthroughs: they trace a single transaction through the entire process, asking questions, observing operations, and inspecting documentation at each step. For operating effectiveness, they use four procedures, ranked from least to most persuasive:

  • Inquiry, meaning asking personnel how the control works and whether they follow it. Useful context, but never sufficient on its own.
  • Observation, meaning watching the control being performed in real time.
  • Inspection, meaning reviewing documentation that the control produced, such as signed reconciliations or approval logs.
  • Re-performance, meaning the auditor independently performs the control procedure and compares their result to the company’s. This is the most persuasive test because it leaves no room for ambiguity.

Automated controls generally require less frequent testing once an auditor confirms the system logic is correct, because they execute identically every time. Manual controls demand larger sample sizes and more frequent testing because human execution varies. If your control environment leans heavily on manual processes, expect auditors to spend more time and your audit fees to reflect it.