Internal Controls
Who is responsible for control, how the COSO framework organizes it, what SOX and the FCPA require, how internal audit tests it, and which IT controls protect systems and data. This section is 15% of Part 1, and nearly every question is a short scenario.
About 15 of the 100 multiple-choice questions. Estimated study time: 18 hours.
Your learning path
Four topics in the IMA outline order. Topic 4 (systems controls) produces the most scenario questions.
Governance, risk & compliance
Who sets the tone and who is accountable, how COSO structures internal control, and why every system gives only reasonable assurance.
Corporate governance and rolesBoard, audit committee, management, auditors
Corporate governance is the system of rules and relationships through which a company is directed and controlled on behalf of its shareholders. Internal control is one of its main tools.
| Party | Role in internal control |
|---|---|
| Board of directors | Oversight: sets the tone, approves strategy and risk appetite, appoints and monitors senior management. A majority should be independent. |
| Audit committee | Independent directors (at least one financial expert) who oversee financial reporting, hire and oversee the external auditor, and receive internal audit reports and whistleblower complaints. |
| Management (CEO, CFO) | Owns internal control: designs, implements and maintains it, and certifies it under SOX. |
| Internal audit | Independent assurance that controls work; reports functionally to the audit committee. |
| External auditor | Opines on the financial statements and, for larger public companies, on internal control over financial reporting (ICFR). Not part of the company's control system. |
The IIA's three lines model puts the same idea in layers: operating management owns and manages risk (first line); risk, compliance and control functions support and challenge (second line); internal audit gives independent assurance (third line).
COSO Internal Control–Integrated FrameworkThree objectives, five components, 17 principles
COSO (2013) defines internal control as a process, effected by the board, management and other personnel, designed to provide reasonable assurance about achieving objectives in three categories: operations, reporting and compliance.
flowchart LR CE[Control environment] --> RA[Risk assessment] RA --> CA[Control activities] CA --> IC[Information and communication] IC --> MA[Monitoring activities] MA -. deficiencies reported .-> CE
| Component | Principles | Typical evidence |
|---|---|---|
| Control environment | 1–5: integrity and ethical values; board independence and oversight; structures, reporting lines and authority; commitment to competence; accountability | Code of conduct, tone at the top, HR policies, organization chart |
| Risk assessment | 6–9: specify clear objectives; identify and analyze risks; consider fraud risk; identify and assess significant change | Risk registers, fraud risk assessment, review of new markets or systems |
| Control activities | 10–12: select and develop control activities; general controls over technology; deploy through policies and procedures | Approvals, reconciliations, segregation of duties, access controls |
| Information and communication | 13–15: use relevant, quality information; communicate internally; communicate externally | Reporting systems, policy manuals, whistleblower hotline |
| Monitoring activities | 16–17: ongoing and separate evaluations; evaluate and communicate deficiencies | Internal audit, management self-assessments, follow-up of findings |
For a system to be effective, all five components and all relevant principles must be present and functioning, and operating together.
3 objectives: operations, reporting, compliance. 5 components (17 principles): control environment (1–5), risk assessment (6–9), control activities (10–12), information and communication (13–15), monitoring activities (16–17). Effective = all components present, functioning and operating together.
Mapping weaknesses at a growing distributor
An audit of Kessel Supply finds: (1) the CEO regularly overrides credit limits for friends' companies and nobody challenges this; (2) the company opened a branch in a new country without considering local bribery risk; (3) no one reconciles the inventory subledger to the general ledger; (4) staff do not know how to report suspected fraud; (5) internal audit findings from two years ago are still open.
Types and limits of controlPreventive, detective, corrective; reasonable assurance; cost-benefit
- Preventive controls stop errors or fraud before they happen (authorization, segregation of duties, passwords, edit checks).
- Detective controls find problems after they occur (reconciliations, reviews, exception reports, physical counts).
- Corrective controls fix problems found (backup restores, error-correction procedures). Directive controls (policies, training) encourage good behavior.
- Inherent limitations: human error and judgment, collusion, management override, and the cost-benefit constraint. So controls give reasonable, never absolute, assurance.
Implement the control only if the reduction in expected loss exceeds its cost (qualitative factors aside).
Is three-way matching worth it?
Without automated three-way matching (purchase order, receiving report, invoice), management estimates a 10% annual chance of a $500,000 duplicate or fictitious payment loss. The control would cut the probability to 2% and cost $25,000 a year.
Finished Governance, risk & compliance?
Mark it complete when you can place any control in its COSO component and name its owner.
Legislative & regulatory
The Sarbanes-Oxley Act's certification and internal-control requirements, the PCAOB's audit standard for ICFR, and the FCPA's bribery and accounting rules.
Sarbanes-Oxley Act (2002)The sections the exam tests
| Section | Requirement |
|---|---|
| §101 | Creates the PCAOB to register, inspect and set standards for auditors of public companies. |
| §201 | Bans auditors from providing certain non-audit services to audit clients (bookkeeping, systems design, internal audit outsourcing, legal, valuation). |
| §203 | Lead and reviewing audit partners rotate every five years. |
| §301 | Audit committee: independent members, directly responsible for the external auditor, procedures for complaints (whistleblowing). |
| §302 | CEO and CFO certify each quarterly and annual report: they reviewed it, it is not misleading, the statements fairly present, they are responsible for and have evaluated disclosure controls, and they disclosed significant deficiencies and fraud to the auditors and audit committee. |
| §404 | (a) Annual management report on ICFR: management's responsibility and its assessment of effectiveness. (b) The external auditor attests to ICFR (accelerated and large accelerated filers). |
| §806 | Protects employee whistleblowers from retaliation. |
| §906 | Criminal certification: knowingly false certification carries fines up to $1 million / 10 years (willful: $5 million / 20 years). |
§302: CEO/CFO certification, every 10-Q and 10-K, disclosure controls. §404(a): management's annual ICFR assessment. §404(b): auditor's ICFR attestation (accelerated filers).
PCAOB AS 2201 and deficiency levelsThe integrated audit, top-down
AS 2201 governs the audit of ICFR integrated with the financial-statement audit. The auditor uses a top-down, risk-based approach: start at the financial statements and entity-level controls (control environment, period-end reporting), then focus on significant accounts, relevant assertions and the controls that address their risks. Work is scaled to risk; the auditor may use the work of competent, objective internal auditors.
Control deficiency: a control's design or operation does not allow timely prevention or detection of misstatements. Significant deficiency: less severe than a material weakness but important enough to merit the audit committee's attention. Material weakness: a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.
One or more material weaknesses → ICFR is not effective and the auditor issues an adverse ICFR opinion. Strong indicators: restatement to correct a material error, fraud by senior management (of any size), material misstatement found by the auditor that controls missed, ineffective audit-committee oversight.
Grading three deficiencies
At Orbis Corp. (materiality $2 million): (A) a supervisor's review of travel expenses was skipped for one month; monthly travel spend is $40,000. (B) Revenue cut-off controls failed; the auditor found $3.5 million of next year's shipments recorded this year, which management had not caught. (C) Reconciliations of a $6 million reserve account were done but not reviewed for two quarters; no misstatement was found, but one could have reached $1.5 million.
Foreign Corrupt Practices Act (1977)Anti-bribery and accounting provisions
- Anti-bribery provisions: prohibit US issuers, US persons and companies, and anyone acting in the US from corruptly offering anything of value to a foreign official (or party, or candidate) to obtain or retain business. Payments through agents count if the company knew or should have known.
- Accounting provisions (issuers only, whether or not they operate abroad): keep books and records that accurately and fairly reflect transactions in reasonable detail, and maintain a system of internal accounting controls.
- Exception: facilitating (grease) payments for routine government action (processing visas, connecting utilities), not discretionary decisions.
- Affirmative defenses: the payment was lawful under the foreign country's written laws, or was a reasonable, bona fide expense (e.g. travel for a product demonstration).
Screening payments at a foreign subsidiary
A US-listed company's subsidiary made four payments: (1) $200 to a customs clerk to process routine paperwork on time; (2) $150,000 to a "consultant" related to a minister, just before winning a state contract; (3) hotel and airfare for officials to visit the US plant for a product demonstration; (4) $5,000 to a tax inspector to reduce an assessment, recorded as "miscellaneous expense".
Finished Legislative & regulatory?
Mark it complete when you can grade a deficiency and screen a foreign payment under the FCPA.
Internal auditing
What internal audit does, how it stays independent, which type of audit fits which question, and how findings are reported.
Purpose and independenceCharter, reporting lines, objectivity
Internal auditing provides independent, objective assurance and advice that improve an organization's governance, risk management and control. Its authority comes from a board-approved charter.
- Organizational independence: the chief audit executive reports functionally to the audit committee (approval of charter, plan, budget, hiring and removal of the CAE) and administratively to senior management (usually the CEO).
- Individual objectivity: auditors should not audit operations they managed within the past year or design controls they later audit.
- Unrestricted access to records, people and property is set in the charter.
- Internal auditors recommend; management decides and implements. Auditors do not take on operating responsibilities.
Types of auditFinancial, compliance, operational, IT, fraud
| Type | Question it answers | Example |
|---|---|---|
| Financial | Are financial records and reports reliable? | Testing account balances, reconciliations, ICFR for SOX |
| Compliance | Are laws, regulations, contracts and policies followed? | Environmental permits, loan covenants, travel policy, FCPA |
| Operational (performance) | Are operations efficient and effective (economy, efficiency, effectiveness)? | Is the purchasing process too slow? Is the warehouse layout wasteful? |
| Information technology | Are IT general and application controls adequate? | Access rights, change management, backups |
| Fraud investigation | Did fraud occur, how, and who was involved? | Investigating a tip about kickbacks |
Choosing the engagement
The audit committee asks internal audit to look at: (1) why customer orders take nine days to ship when competitors take three; (2) whether the company met the reporting conditions in its bank loan agreement; (3) whether the inventory reserve is fairly stated at year end.
The audit process and reportingPlan, fieldwork, report, follow up
- Risk-based annual plan approved by the audit committee.
- Engagement planning: objectives, scope, criteria, resources, work program.
- Fieldwork: gather sufficient, reliable, relevant evidence; document in working papers.
- Communication: draft discussed with management, then a final report including management's response and action plan.
- Follow-up: confirm corrective action was taken, or that senior management accepted the risk of not acting.
Criteria (what should be) · Condition (what is) · Cause (why the gap) · Effect (risk or impact) · Recommendation (action to close the gap).
Writing up a finding
Testing of 60 vendor-master changes found 14 made by accounts payable clerks with no independent approval.
Finished Internal auditing?
Mark it complete when you can match an engagement to its audit type and write a five-part finding.
Systems controls & security
General controls protect the whole IT environment; application controls protect individual transactions. Segregation of duties, access controls and recovery planning hold it together.
Segregation of dutiesAuthorization, custody, recording, reconciliation
Segregation of duties means no one person can both commit an error or fraud and conceal it. Separate four functions:
| Function | Examples | Risk if combined with another function |
|---|---|---|
| Authorization | Approving purchases, credit, write-offs, vendor master changes | Approves own fictitious transactions |
| Custody of assets | Handling cash receipts, signing checks, warehouse access | Steals assets and approves or records the cover-up |
| Recording | Posting journals, maintaining subledgers | Hides theft by false entries (e.g. lapping, fictitious write-offs) |
| Reconciliation (verification) | Bank reconciliations, counts, subledger-to-ledger checks | Conceals discrepancies instead of reporting them |
In IT, separate systems development (analysts, programmers) from operations (computer operators), and keep the database administrator, security administrator and data control roles apart. Programmers must not have access to live data or move their own changes into production.
A small office with three people
At a 12-person nonprofit, the bookkeeper opens the mail, deposits checks, posts receipts to donor accounts and prepares the bank reconciliation. The director signs all checks; the office manager approves invoices.
General vs application controlsInput, processing and output
IT general controls apply to the whole environment: access security, change management (program changes tested and approved), IT operations (job scheduling, backups) and systems development. Application controls apply to one application's transactions.
| Stage | Control | What it catches |
|---|---|---|
| Input | Field (format) check | Letters in a numeric field |
| Validity check | Customer or employee number not on the master file | |
| Limit check | Hours above 60 in a week | |
| Reasonableness check | Value out of line with another field (pay rate vs job grade) | |
| Completeness check | Required field left blank | |
| Check digit | Transposed or mistyped account numbers | |
| Sequence check | Missing or duplicate document numbers | |
| Batch totals | Lost, added or altered records in a batch | |
| Processing | Run-to-run totals, reconciliation of control totals, posting checks | Records lost or changed between processing steps |
| Output | Distribution lists, review of reports against control totals, secure disposal | Reports to the wrong people; unnoticed errors |
Record count = number of documents. Financial total = sum of a monetary field. Hash total = sum of a field with no meaning in itself (account or part numbers). Recompute after input; any difference means a record was lost, added or changed.
Which total catches the error?
A payables batch has three invoices: vendor 1203 for $1,250.50, vendor 1307 for $2,400.00 and vendor 1402 for $1,000.25. The clerk keys vendor 1307 as 1370, with the correct amount.
Access controlsAuthentication, authorization, logging
- Physical: locked server rooms, badges, visitor logs, environmental controls (fire suppression, UPS).
- Authentication: something you know (password), have (token, phone) or are (biometric). Multi-factor combines two different types.
- Authorization: role-based access and least privilege; review access periodically and remove it promptly when people leave or change jobs.
- Network: firewalls, encryption in transit and at rest, intrusion detection, patching.
- Logging: audit trails of who did what, reviewed for unusual activity (detective).
Backup and disaster recoveryRPO, RTO and recovery sites
RPO (recovery point objective): the maximum data loss tolerated, measured in time; it sets backup frequency. RTO (recovery time objective): the maximum downtime tolerated; it sets the recovery site.
| Site | What it has | Recovery time | Cost |
|---|---|---|---|
| Hot site (or mirrored site) | Hardware, software and current data, ready to run | Minutes to hours | Highest |
| Warm site | Hardware and connectivity; data must be restored | Hours to days | Medium |
| Cold site | Space, power and cabling only | Days to weeks | Lowest |
- Keep backups off-site (or in a separate cloud region), test restores regularly, and keep at least one copy offline or immutable against ransomware.
- Grandfather-father-son rotation keeps three generations of backups.
- A business continuity plan covers the whole business (people, facilities, suppliers); the disaster recovery plan is its IT part.
Paying for a hot site
An online retailer estimates a 5% annual chance of a major data-center outage. With its current warm site, an outage would cost $2,000,000 in lost sales; a hot site would cut the loss to $400,000. The hot site costs $60,000 a year more than the warm site.
Finished Systems controls & security?
Mark it complete when you can pick the input control for an error and the recovery site for an RTO.
Interactive tools
Two exercises that train the judgments the exam tests most in this section: where a control belongs, and which duties must be kept apart.
COSO component matching game
Drag each control or weakness into the COSO component it belongs to, or use the menu on each card if you prefer the keyboard. Then check your answers. Each round draws ten cards from a bank of controls.
Controls to place
Segregation-of-duties conflict checker
Assign each duty in the purchasing, payables and cash cycle (plus two IT duties) to an employee. The checker flags incompatible combinations, explains the risk and suggests a fix. It starts with a small company's actual assignments.
Formula sheet
Every key framework and formula in Internal Controls on one sheet. Print it from here: the sidebar is hidden and the sheet prints black on white.
Flashcards
Recall first, then flip. Your grade schedules the next review (SM-2-lite).
Practice MCQs
Practice mode gives instant feedback; timed mode allows 1.8 minutes per question, like the exam. Filter by topic, difficulty, or questions you missed.
Written-response practice
Write your answer first (aim for about 30 minutes per case), then compare it with the model answer and score yourself against the rubric. Show your calculations: the exam awards marks for method.
Glossary
Search the section's vocabulary. Underlined terms in the lessons show these definitions on hover or keyboard focus.