A beautiful policy means nothing if the control behind it does not work. Control testing is how auditors and GRC professionals move from assertion to proof — separating organizations that merely look compliant from those that actually are.
Design effectiveness asks: Is this control capable of preventing or detecting the risk? A control can be beautifully designed but never actually performed. Operating effectiveness asks: Is this control consistently performed as designed throughout the testing period? Both must be confirmed — design alone is a paper program.
From most to least evidence reliability: Re-performance (auditor performs the control) → Physical observation → Inspection of documentary evidence → Analytical procedures → Inquiry (interview). In practice, auditors use multiple techniques together. Inquiry alone is never sufficient to conclude a control is operating effectively.
An exception rate of 5% (5 errors in 100 tested) may be acceptable for low-risk controls but unacceptable for critical financial controls. Define tolerable deviation rates before testing begins — the standard against which exception rates are compared.
PCAOB AS 2201 governs the external auditor's assessment of internal control over financial reporting for public companies. Key concepts:
Start with entity-level controls (overall governance, culture, management competence), then move to significant accounts and disclosures, then to the controls that address risks in those areas. This prevents over-testing low-risk controls.
Identify accounts that could contain misstatements that would materially affect the financial statements. Focus control testing on controls over these accounts.
Not all controls over an account are equally important. Key controls are those that, if they fail, would allow a material misstatement to reach the financial statements undetected. Key controls receive the most testing rigor.
If controls are tested only as of year-end, they may have been ineffective earlier. AS 2201 requires testing to cover the full reporting period for key controls, with roll-forward procedures if initial testing is at an interim date.
Not all control exceptions are equally serious. PCAOB and AICPA provide a classification framework:
A control is missing or not designed or operating effectively enough to prevent or detect a misstatement. Lower severity — does not meet the threshold for significant deficiency or material weakness. Still requires management attention and remediation.
A deficiency, or combination of deficiencies, in internal control that is less severe than a material weakness, yet important enough to merit attention by those responsible for oversight. Must be communicated to the audit committee.
A deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement will not be prevented or detected. Must be publicly disclosed in annual SEC filings (10-K) for public companies. Most serious classification.
A compensating control may reduce the severity classification of a deficiency. If a weak primary control is offset by a strong detective control, the overall risk may not rise to material weakness level.
In SOX auditing, a material weakness finding can cause significant stock price impact, trigger regulatory scrutiny, and undermine investor confidence. GRC professionals working in public companies must understand the materiality threshold deeply.
Every piece of audit evidence should be evaluated against four quality criteria:
Enough evidence to support the conclusion. More items tested = more confidence. The threshold for "sufficient" depends on risk level and tolerable deviation rate.
Trustworthy source. External evidence (bank confirmation) > internal evidence (management report). System-generated evidence is only as reliable as the system's integrity.
Evidence must help the auditor reach a conclusion. A document that is tangentially related but doesn't address the control objective being tested is not useful evidence.
Directly related to the assertion being tested. Testing the wrong evidence — even high-quality evidence — cannot support conclusions about the intended control objective.
You are auditing a fintech company's patch management programme. Work through each testing step exactly as an IS auditor would — design review, sample testing, evidence inspection, and finding documentation.