Module 16 · Intermediate · ⏱ 50 min · 🏆 +275 XP

Control Testing & Evidence Collection

A beautiful policy means nothing if the control behind it does not work. Control testing is how auditors and GRC professionals move from assertion to proof — separating organizations that merely look compliant from those that actually are.

Test of ControlsEvidence QualityDesign EffectivenessOperating EffectivenessPCAOB StandardsAudit Findings

Learning Objectives

  • Distinguish design effectiveness testing from operating effectiveness testing.
  • Apply the five testing techniques: inquiry, observation, inspection, re-performance, and analytical procedures.
  • Evaluate evidence quality using the SRUV criteria (Sufficient, Reliable, Useful, Relevant).
  • Write a professional audit finding using the PCCA structure.
  • Identify when an exception constitutes a significant deficiency vs a material weakness.
  • Explain PCAOB AS 2201 internal control testing standards for public companies.

Lecture

1 · Design vs Operating Effectiveness

Design effectiveness asks: Is this control capable of preventing or detecting the risk? A control can be beautifully designed but never actually performed. Operating effectiveness asks: Is this control consistently performed as designed throughout the testing period? Both must be confirmed — design alone is a paper program.

2 · The Testing Techniques Hierarchy

From most to least evidence reliability: Re-performance (auditor performs the control) → Physical observation → Inspection of documentary evidence → Analytical procedures → Inquiry (interview). In practice, auditors use multiple techniques together. Inquiry alone is never sufficient to conclude a control is operating effectively.

3 · Exception Rate vs Exception Count

An exception rate of 5% (5 errors in 100 tested) may be acceptable for low-risk controls but unacceptable for critical financial controls. Define tolerable deviation rates before testing begins — the standard against which exception rates are compared.

Auditor principle: What you do not test, you cannot conclude. An "unremarkable" finding that a control passed is as important as an exception — it is positive assurance that controls work.

Theory Deep Dive

📋 PCAOB AS 2201 — Internal Control Testing Standards

PCAOB AS 2201 governs the external auditor's assessment of internal control over financial reporting for public companies. Key concepts:

1
Top-Down Approach

Start with entity-level controls (overall governance, culture, management competence), then move to significant accounts and disclosures, then to the controls that address risks in those areas. This prevents over-testing low-risk controls.

2
Significant Account / Disclosure Identification

Identify accounts that could contain misstatements that would materially affect the financial statements. Focus control testing on controls over these accounts.

3
Key Control Selection

Not all controls over an account are equally important. Key controls are those that, if they fail, would allow a material misstatement to reach the financial statements undetected. Key controls receive the most testing rigor.

4
Testing as of Date vs Full Period

If controls are tested only as of year-end, they may have been ineffective earlier. AS 2201 requires testing to cover the full reporting period for key controls, with roll-forward procedures if initial testing is at an interim date.

⚖️ Control Deficiency Classification

Not all control exceptions are equally serious. PCAOB and AICPA provide a classification framework:

Control Deficiency

A control is missing or not designed or operating effectively enough to prevent or detect a misstatement. Lower severity — does not meet the threshold for significant deficiency or material weakness. Still requires management attention and remediation.

Significant Deficiency

A deficiency, or combination of deficiencies, in internal control that is less severe than a material weakness, yet important enough to merit attention by those responsible for oversight. Must be communicated to the audit committee.

Material Weakness

A deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement will not be prevented or detected. Must be publicly disclosed in annual SEC filings (10-K) for public companies. Most serious classification.

Compensating Controls

A compensating control may reduce the severity classification of a deficiency. If a weak primary control is offset by a strong detective control, the overall risk may not rise to material weakness level.

In SOX auditing, a material weakness finding can cause significant stock price impact, trigger regulatory scrutiny, and undermine investor confidence. GRC professionals working in public companies must understand the materiality threshold deeply.

🔬 Evidence Quality — SRUV Framework

Every piece of audit evidence should be evaluated against four quality criteria:

Sufficient

Enough evidence to support the conclusion. More items tested = more confidence. The threshold for "sufficient" depends on risk level and tolerable deviation rate.

Reliable

Trustworthy source. External evidence (bank confirmation) > internal evidence (management report). System-generated evidence is only as reliable as the system's integrity.

Useful

Evidence must help the auditor reach a conclusion. A document that is tangentially related but doesn't address the control objective being tested is not useful evidence.

Relevant

Directly related to the assertion being tested. Testing the wrong evidence — even high-quality evidence — cannot support conclusions about the intended control objective.

🧪 Lab — Control Testing Walkthrough

You are auditing a fintech company's patch management programme. Work through each testing step exactly as an IS auditor would — design review, sample testing, evidence inspection, and finding documentation.

Real-World Scenario

Mission Quiz

Mission Complete

← Module 15 Next: Module 17 →