Typology of Controls
Effective internal control networks rely on a layered application of various control types across business applications and infrastructure. 

Control Type Definition Example
Preventive Designed to stop errors, omissions, or malicious acts before they occur. Segregation of duties, system authorization tokens.
Detective Designed to find and identify errors or irregularities after they have occurred. Bank reconciliations, physical inventory counts, variance logs.
Corrective Designed to fix issues, reverse errors, or restore systems after a detective control flags an anomaly. Data backups recovery, system patches, disciplinary procedures.

Technical Separation: Application vs. General IT Controls
  • General IT Controls (GITCs): Broad infrastructure controls applying across all computing applications. They encompass data center operations, network security architecture, system acquisition, and identity access management (IAM).
  • Application Controls: Programmed, specific boundaries embedded within software applications to process transactions accurately. Examples include validity checks, range checks, format checks, and automated sequence verifications. 
Control Evaluation Methodologies
Organizations validate control design and operational effectiveness through structured test procedures:
  • Inquiry: Interviewing personnel to ascertain control workflows. (Lowest level of evidence).
  • Observation: Witnessing the execution of a control process by an operator in real-time.
  • Inspection: Examining physical or digital artifacts, signatures, log reports, or system documentation proving execution.
  • Re-performance: Independent execution of the control procedure by an internal auditor or evaluator to verify if it yields identical, accurate results. (Highest level of evidence). 
Â