3.1 The Architecture of Testing of Design Effectiveness (ToD)
During the fieldwork phase of an internal control audit, the evaluation team performs a strict Testing of Design Effectiveness (ToD) review. The core objective of ToD is to determine whether the control, as engineered, documented, and approved in the standard operating procedure, possesses the structural capability to prevent or detect material errors, process failures, or compliance breaches.
Auditors execute policy walkthroughs, review process flowcharts, and examine database schema configurations to confirm that the control design contains no inherent structural flaws.
3.2 The Architecture of Testing of Operating Effectiveness (ToO)
Once the design is certified valid, the audit team executes Testing of Operating Effectiveness (ToO). The core objective of ToO is to determine whether the control is being executed consistently by the workforce according to its design specification during daily business operations.
Auditors select a statistically weighted sample of process instances across the audit timeline and verify empirical evidence—including checked system signature logs, verified approval timestamps, and independent reconciliation records:
The Control Evaluation Lifecycle:
[Review Process Manual] ──► Execute ToD ──► [Design Valid?] ──► Execute ToO ──► [Consistently Executed?] ──► Control Certified Safe
                                                │                                    │
                                             (If No)                              (If No)
                                                â–¼                                    â–¼
                                        Design Deficiency                    Operating Deficiency

3.3 Classifying Control Deficiencies and Remediation Triggers
If testing uncovers that a control has an excellent design on paper but suffers from an operating deficiency because employees skip steps, the finding is logged in the GRC database.
The audit team classifies the severity of the exception using a standardized hierarchy:

Control Exception Tier Technical Definition and Regulatory Impact Criteria
Control Deficiency A minor operational slip where a control is skipped but secondary checks prevent a material failure —> Requires localized management fix.
Significant Deficiency A material control gap that compromises data tracking but lacks an immediate financial misstatement threat —> Merits executive attention.
Material Weakness A severe control breakdown such that there is a reasonable possibility that a material compliance breach or financial misstatement will not be blocked.