A compensating control is a backup procedure that reduces financial reporting risk when a primary internal control is missing, poorly designed, or not operating as intended. Instead of repairing the broken control itself, it takes a different route to the same result: keeping errors and fraud out of the financial statements. Companies subject to the Sarbanes-Oxley Act rely on compensating controls to hold the internal control environment together while they work on a longer-term fix.
How It Differs From a Primary Control
A primary control is the safeguard built into a process from the start. An automated three-way match that compares a purchase order, receiving report, and vendor invoice before releasing payment is a primary control. When it works, no one has to think about it.
A compensating control exists because something in that design went wrong. Maybe the automated match misses certain invoice types, or the system allows overrides without approval. The compensating control covers the gap, often through a different method entirely. Where the primary control is automated, the compensating control might be a manual review. Where the primary control is preventive, blocking bad transactions before they post, the compensating control is often detective, catching them after the fact through reconciliation.
That difference matters. Compensating controls tend to be more labor-intensive, lean harder on individual judgment, and introduce lag between when an error happens and when someone catches it. Auditors know this and evaluate them with that reality in mind.
When You Need One
Not every control problem calls for a compensating control. Internal control deficiencies exist on a spectrum, and the response should match the severity. PCAOB standards recognize three tiers.
A control deficiency exists when a control’s design or operation doesn’t allow employees to prevent or catch misstatements on a timely basis. That includes controls that are missing, poorly designed, or not being followed.1Public Company Accounting Oversight Board. AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements A significant deficiency is more serious: important enough for the audit committee and management to address, though not for outside disclosure.2Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements A material weakness is the most severe: a reasonable possibility that a material misstatement won’t be prevented or detected in time. Under PCAOB standards, “reasonable possibility” covers outcomes that are either reasonably possible or probable, a lower bar than many people expect.
A well-designed compensating control can keep a deficiency from escalating. PCAOB guidance shows scenarios where a compensating detective control operating monthly reduces the likelihood of a material misstatement slipping through, keeping the finding at the significant deficiency level rather than a material weakness.3U.S. Securities and Exchange Commission. PCAOB Appendix D – Examples of Significant Deficiencies and Material Weaknesses
What Makes One Hold Up to an Auditor
Auditors won’t accept just any workaround. PCAOB Auditing Standard 2201 sets the bar: a compensating control must operate at a level of precision that would prevent or detect a misstatement that could be material.1Public Company Accounting Oversight Board. AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements That single requirement drives several practical characteristics.
Precision comes first. The control has to target the exact risk left exposed by the failed primary control. A generic management review of financial results won’t compensate for a specific breakdown in revenue recognition. It needs to catch the same type of error the original control was supposed to stop.
Timing comes next. The control must run often enough to catch problems before they compound into material amounts. A monthly reconciliation might work for a low-volume account, but high-volume processing can demand daily or even real-time review. The volume and dollar value of exposed transactions should drive the frequency.
Independence matters too. The person performing the compensating control should be separate from the people involved in the deficient process. If the same team that created the problem is also checking for it, the control loses credibility. Competence sits alongside independence: the reviewer needs enough expertise to actually spot the errors. A junior clerk rubber-stamping a reconciliation prepared by a senior accountant doesn’t provide meaningful oversight.
Finally, the control has to produce evidence. Sign-off sheets, review memos, annotated exception reports, email trails. Without documentation proving the control ran consistently across the period, it effectively doesn’t exist from an audit perspective.
Practical Examples
Segregation of Duties in Small Organizations
This is where compensating controls show up most often. Smaller companies frequently can’t split financial duties across multiple employees, so one person might handle both entering vendor invoices and initiating payments. That combination creates an obvious fraud risk: the employee could set up a fictitious vendor and pay themselves.
The COSO Internal Control framework acknowledges this reality and notes that where segregation of duties isn’t practical, management should select and develop alternative control activities. A common compensating control has the CFO or owner perform a detailed daily review of the payment register and bank activity, comparing each disbursement against approved invoices and known vendors. Sign-off on exception reports provides the evidence trail.
Overly Broad System Access
Enterprise systems sometimes grant too many users the ability to modify sensitive data like vendor bank account numbers or product pricing. Restricting access through system configuration can take months, so a compensating control bridges the gap. A typical approach automatically logs all changes to master data, with the IT director or data owner reviewing those logs daily and investigating anything that happened outside an approved change request. It doesn’t prevent unauthorized modifications, but it catches them fast.
Failed Automated Credit Checks
When an ERP system’s automated credit limit enforcement isn’t reliable, the risk of shipping to customers who can’t pay goes up. A compensating control might require dual approval from sales and credit management for any order above a defined threshold, so high-value orders receive independent credit review before fulfillment, with documented approvals for the audit trail.
Manual Financial Statement Disclosures
Some complex footnote disclosures can’t be generated automatically. The compensating control usually involves a detailed reconciliation of the final disclosure figures back to source data. The controller ties out every number, prepares a memo documenting the work, and a second reviewer independently verifies it.
What Happens If the Compensating Control Fails Testing
Auditors test compensating controls with the same rigor as primary controls, and in some ways more closely, because a compensating control is already an admission that something in the environment isn’t working as designed. Testing focuses on operating effectiveness across the entire audit period. If the control was a daily review, the auditor expects evidence for every business day, not just most of them. A review performed three weeks after the underlying transaction may technically have been “performed,” but an auditor will likely consider it ineffective if the lag allowed errors to accumulate.
When a compensating control doesn’t pass, the underlying deficiency is no longer considered mitigated. The auditor then evaluates that deficiency on its own terms, considering both the likelihood and magnitude of potential misstatement.1Public Company Accounting Oversight Board. AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
If the unmitigated deficiency rises to a material weakness, the consequences are significant. Under 15 U.S.C. ยง 7262, public companies must include an internal control report in their annual filing containing management’s assessment of control effectiveness.4GovInfo. 15 USC 7262 – Management Assessment of Internal Controls A material weakness means management cannot assert that internal controls are effective, and that disclosure appears in the 10-K. For larger public companies subject to auditor attestation under Section 404(b), the auditor must express an adverse opinion on internal controls when one or more material weaknesses exist.1Public Company Accounting Oversight Board. AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Smaller issuers that aren’t accelerated filers are exempt from the auditor attestation requirement, though they still must perform their own management assessment.
A failed compensating control doesn’t automatically produce an adverse opinion. That outcome depends on whether the underlying deficiency, standing alone without mitigation, meets the threshold for a material weakness. A deficiency that would only qualify as a significant deficiency even without the compensating control won’t trigger an adverse opinion, though auditors must still communicate it in writing to management and the audit committee.2Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements
Pitfalls to Avoid
The biggest risk is treating a compensating control as a permanent solution. It’s a bridge while the underlying problem gets fixed, not a substitute for a properly functioning primary control. Organizations that let compensating controls run indefinitely accumulate manual workarounds that grow more expensive to maintain and more likely to fail as staff turns over.
Compensating controls also create a real risk of false assurance. A control that looks good on paper but hasn’t been rigorously tested may satisfy a compliance checklist without actually reducing risk. This shows up most often when controls rely on individual judgment rather than systematic processes. A reviewer who signs off on a daily exception report without actually investigating the exceptions provides no real protection.
Another common failure is building a compensating control that doesn’t match the precision of the risk it addresses. A high-level monthly financial review won’t compensate for a broken automated control that processes thousands of transactions daily. Match the frequency and granularity to the exposed volume and dollar value.
Every compensating control should come with a transition plan: timelines and milestones for fixing or replacing the primary control. Without one, “temporary” measures tend to become permanent fixtures of the control environment, growing more fragile with each audit cycle.