1. Defining Internal Controls
Internal control is the comprehensive process designed, implemented, and maintained by those charged with governance and management to provide reasonable assurance about the achievement of an entity’s objectives regarding financial reporting reliability, operational efficiency, and regulatory compliance.
2. The COSO Framework Components
Both European and US standards (specifically SOX 404 compliance) rely heavily on the COSO (Committee of Sponsoring Organizations) framework, which splits internal control environments into five interconnected components:
- Control Environment: The overarching tone-at-the-top. Includes management’s philosophy, ethical values, and oversight commitment.
- Risk Assessment Process: How the client entity internally identifies, prioritizes, and manages operational and financial reporting risks.
- Information System and Communication: The infrastructure that captures, processes, logs, and reports transactions, maintaining audit trails.
- Control Activities: Specific policies and preventative/detective protocols executed across operations (e.g., Segregation of Duties, authorization locks, physical security, reconciliations).
- Monitoring of Controls: Continuous assessments performed by management to verify that the internal controls are functioning as intended over time (often driven by an internal audit department).
3. Auditing Approach: Tests of Controls vs. Substantive Testing
- Strategy 1: Combined Approach. If the auditor’s initial assessment indicates that internal controls are well-designed and operating effectively, they perform Tests of Controls (e.g., inspecting approval signatures, re-performing system matching). If controls pass testing, the auditor can reduce their year-end substantive testing.
- Strategy 2: Substantive-Only Approach. If the auditor discovers that the client’s internal control environment is completely broken, flawed, or non-existent, they skip tests of controls entirely and execute 100% intensive substantive testing at year-end.