What Is a Control in Audit? Types, COSO, and Evaluation

A control in an audit is any policy, procedure, or safeguard a company puts in place to keep its financial reporting accurate, its operations running properly, and its compliance obligations met. Auditors examine these controls to decide how much they can trust the company’s own processes versus how deeply they need to test the numbers themselves. Strong controls mean a lighter, faster audit. Weak or missing controls mean the auditor has to expand direct testing of account balances and individual transactions, and for a public company, a serious enough failure produces an adverse opinion that becomes part of the public record.

Controls are not a single thing. They come in different functional types, sit at different levels of the organization, and run either through people or through systems. Auditors care about all of these distinctions because each one changes how a control is tested and how much weight it can carry.

Preventive, Detective, and Corrective Controls

The most common way to classify controls is by when they act relative to a problem.

Preventive controls stop errors or fraud before they happen. Requiring a manager to approve purchases above a certain dollar amount is preventive. So is separating the person who writes checks from the person who reconciles the bank account. These tend to be the most cost-effective because catching a problem at the front end is cheaper than cleaning it up later.

Detective controls catch problems after they have already occurred. Monthly bank reconciliations, physical inventory counts, and exception reports that flag unusual transactions all fit here. No set of preventive controls is perfect, so detective controls act as the safety net.

Corrective controls fix what the detective controls surface. If a reconciliation reveals an unauthorized journal entry, the corrective control is the process for reversing the entry, investigating what happened, and adjusting procedures so it does not recur.

The three work together. A company relying entirely on preventive controls will eventually miss something. A company with only detective controls is constantly cleaning up messes that could have been avoided. Strong control environments layer all three.

Entity-Level and Process-Level Controls

Not all controls operate at the same altitude. Auditing standards distinguish between entity-level controls that affect the organization broadly and process-level controls tied to specific transaction flows.

Entity-level controls include things like the company’s code of ethics, the audit committee’s oversight activities, the risk assessment process, and controls over the period-end financial reporting process.1Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Some entity-level controls operate with enough precision to directly prevent or detect a misstatement on their own. Others, like a company’s general ethical tone, have an indirect but important effect on whether lower-level controls actually get followed.

Process-level controls operate within specific transaction cycles: revenue, purchasing, payroll, inventory. A three-way match comparing a purchase order, receiving report, and invoice before paying a vendor is a classic process-level control. These are the controls auditors most often test directly because they tie to specific financial statement assertions like completeness, accuracy, and valuation.

Automated and Manual Controls

A manual control depends on a person doing something: reviewing a report, signing off on a reconciliation, counting inventory. Manual controls are flexible and can handle judgment calls, but they are vulnerable to human error, fatigue, and inconsistency.

An automated control is built into an information system and executes without manual intervention. A system that rejects duplicate invoice numbers, enforces credit limits, or automatically calculates depreciation is running automated controls. The main advantage is consistency: once properly configured, an automated control performs the same way every time across every transaction.

Automated controls change the auditor’s testing approach. Instead of sampling transactions to see whether someone performed a manual review correctly, the auditor focuses on whether the system itself is reliable. If the automated control was properly designed and the IT general controls protecting that system are sound, the auditor can often get comfortable that the control worked across the entire population of transactions rather than just a sample. Many controls in practice are hybrids, where the system generates a report but a person reviews it for exceptions. Testing those means evaluating both the automated report generation and the manual review.

Segregation of Duties

Segregation of duties deserves its own note because it is one of the most fundamental and most frequently tested controls in any audit. The idea is simple: no single person should control every step of a transaction. The three functions that need to be separated are authorization, recordkeeping, and custody of assets.

When one person can both approve a payment and record it in the books, nothing stops them from creating a fictitious vendor and paying themselves. Splitting these responsibilities across different people means fraud requires collusion, which is harder to pull off and more likely to be detected. Smaller organizations with limited staff sometimes struggle with full segregation, but alternative controls like detailed management review or independent reconciliations by a third party can compensate. Auditors evaluate whether those alternatives are genuinely effective, not just whether they exist on a policy document.

The COSO Framework

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) published its Internal Control—Integrated Framework in 1992 and updated it in 2013. It remains the dominant framework for designing and evaluating internal controls in the United States.2COSO. Internal Control – Integrated Framework The framework breaks internal control into five interrelated components.3Association of International Certified Professional Accountants. COSO Internal Control – Integrated Framework

The control environment is the foundation everything else rests on. It reflects the organization’s commitment to integrity, ethical values, and competence. A company where senior leadership ignores compliance or pressures employees to hit revenue targets at any cost has a weak control environment regardless of what policies exist on paper. Auditors pay close attention to tone at the top because it shapes how seriously employees take the rest of the control system.

Risk assessment is how management identifies the risks that could prevent the organization from achieving its objectives, including both internal risks like employee turnover in key accounting roles and external risks like changes in tax law. The framework specifically calls out fraud risk assessment as one of its principles.

Control activities are the specific actions taken to address the identified risks: approvals, reconciliations, access restrictions, segregation of duties. The 2013 update added a principle specifically addressing technology controls, recognizing that most financial reporting now flows through IT systems.

Information and communication covers the flow of relevant, high-quality information to the right people at the right time, both internally and externally. An employee who discovers a suspicious transaction must have a clear channel to report it. Management needs timely financial data to make decisions.

Monitoring evaluates whether controls are still working as intended. It can be ongoing, like automated exception reports that run continuously, or periodic, like an annual internal audit. When monitoring identifies a deficiency, the organization is expected to communicate it to the people who can fix it.

How Auditors Evaluate Controls

The auditor’s work with controls follows a logical sequence: understand the system, assess whether controls are designed well, confirm they have been put into practice, and then test whether they are actually working.

Walkthroughs

A walkthrough is usually the auditor’s first hands-on look. The auditor follows a single transaction from start to finish through the company’s processes, using the same documents and systems that employees use. Along the way, the auditor asks employees about their understanding of what they are supposed to do, inspects documentation, and sometimes re-performs a step. This is where auditors spot controls that look good on paper but do not function in reality.1Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

Design Effectiveness

The auditor evaluates whether each control, if operated as intended by someone with the right authority and skills, would actually prevent or detect a material misstatement. A control can fail the design test even if everyone follows it perfectly. Having a manager approve journal entries is poorly designed if the manager has no way to verify the entries are legitimate.1Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

Operating Effectiveness

Once the auditor is satisfied a control is well designed, the next question is whether it worked throughout the period. Testing operating effectiveness means examining multiple instances of the control to confirm it was performed consistently, using inquiry, observation, inspection of documents, and re-performance.1Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Sample sizes depend on how often the control runs, how critical it is, and the level of risk. A daily control needs a larger sample than a quarterly one.4Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 2315 – Audit Sampling

When controls test as effective, the auditor can reduce substantive procedures, meaning less direct testing of account balances and transactions. When controls are weak, the auditor has to expand substantive testing to compensate. That is the practical reason companies invest in strong controls. For audits of non-public companies under AICPA standards, control testing is not always required; the auditor must understand the controls but can choose a purely substantive approach as long as the procedures adequately respond to assessed risks.

When a Control Fails: Deficiency, Significant Deficiency, Material Weakness

When an auditor finds a problem with a control, the next step is classifying how serious it is. Auditing standards recognize three levels.

A deficiency exists when a control is designed or operating in a way that does not allow employees to prevent or catch misstatements on a timely basis. Many deficiencies are minor and are reported only to management.5Public Company Accounting Oversight Board. PCAOB Auditing Standard No. 5 – Appendix A Definitions

A significant deficiency is a deficiency, or combination of deficiencies, serious enough to deserve the attention of those overseeing the company’s financial reporting, but not severe enough to qualify as a material weakness.5Public Company Accounting Oversight Board. PCAOB Auditing Standard No. 5 – Appendix A Definitions

A material weakness is a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement in the financial statements will not be prevented or caught in time.5Public Company Accounting Oversight Board. PCAOB Auditing Standard No. 5 – Appendix A Definitions

The distinction matters. A significant deficiency gets reported to management and the audit committee but does not change the auditor’s opinion. A material weakness forces an adverse opinion on internal controls for a public company, and that opinion often triggers heightened SEC scrutiny, restatements of prior financial statements, and a decline in the company’s stock price. Auditors are also prohibited from issuing a written statement that no significant deficiencies were found, because such a statement could give false comfort about controls the audit was not designed to fully evaluate.6Public Company Accounting Oversight Board. PCAOB Auditing Standard AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements

That is the shape of controls in an audit: layered by function, sitting at different levels, running through either people or systems, tested through a defined sequence, and classified by severity when they fail. A control’s label matters less than whether it actually addresses the risk of a material misstatement to a specific financial statement line item.