Home
Part 1 · Section E

Internal Controls

Who is responsible for control, how the COSO framework organizes it, what SOX and the FCPA require, how internal audit tests it, and which IT controls protect systems and data. This section is 15% of Part 1, and nearly every question is a short scenario.

About 15 of the 100 multiple-choice questions. Estimated study time: 18 hours.

0%Section readiness
0 / 4Topics complete
—MCQ accuracy
18 hEstimated study time

Your learning path

Four topics in the IMA outline order. Topic 4 (systems controls) produces the most scenario questions.

0% of topics complete
Topic 1 of 4

Governance, risk & compliance

Who sets the tone and who is accountable, how COSO structures internal control, and why every system gives only reasonable assurance.

Corporate governance and rolesBoard, audit committee, management, auditors

Corporate governance is the system of rules and relationships through which a company is directed and controlled on behalf of its shareholders. Internal control is one of its main tools.

Roles in internal control
Party Role in internal control
Board of directors Oversight: sets the tone, approves strategy and risk appetite, appoints and monitors senior management. A majority should be independent.
Audit committee Independent directors (at least one financial expert) who oversee financial reporting, hire and oversee the external auditor, and receive internal audit reports and whistleblower complaints.
Management (CEO, CFO) Owns internal control: designs, implements and maintains it, and certifies it under SOX.
Internal audit Independent assurance that controls work; reports functionally to the audit committee.
External auditor Opines on the financial statements and, for larger public companies, on internal control over financial reporting (ICFR). Not part of the company's control system.

The IIA's three lines model puts the same idea in layers: operating management owns and manages risk (first line); risk, compliance and control functions support and challenge (second line); internal audit gives independent assurance (third line).

Exam trapManagement, not the board and not the auditors, is responsible for establishing and maintaining internal control. The board and audit committee oversee it; auditors evaluate it.
COSO Internal Control–Integrated FrameworkThree objectives, five components, 17 principles

COSO (2013) defines internal control as a process, effected by the board, management and other personnel, designed to provide reasonable assurance about achieving objectives in three categories: operations, reporting and compliance.

flowchart LR
  CE[Control environment] --> RA[Risk assessment]
  RA --> CA[Control activities]
  CA --> IC[Information and communication]
  IC --> MA[Monitoring activities]
  MA -. deficiencies reported .-> CE
COSO components and their principles
Component Principles Typical evidence
Control environment 1–5: integrity and ethical values; board independence and oversight; structures, reporting lines and authority; commitment to competence; accountability Code of conduct, tone at the top, HR policies, organization chart
Risk assessment 6–9: specify clear objectives; identify and analyze risks; consider fraud risk; identify and assess significant change Risk registers, fraud risk assessment, review of new markets or systems
Control activities 10–12: select and develop control activities; general controls over technology; deploy through policies and procedures Approvals, reconciliations, segregation of duties, access controls
Information and communication 13–15: use relevant, quality information; communicate internally; communicate externally Reporting systems, policy manuals, whistleblower hotline
Monitoring activities 16–17: ongoing and separate evaluations; evaluate and communicate deficiencies Internal audit, management self-assessments, follow-up of findings

For a system to be effective, all five components and all relevant principles must be present and functioning, and operating together.

COSO 2013 at a glance

3 objectives: operations, reporting, compliance. 5 components (17 principles): control environment (1–5), risk assessment (6–9), control activities (10–12), information and communication (13–15), monitoring activities (16–17). Effective = all components present, functioning and operating together.

Exam trapA whistleblower hotline is information and communication, not monitoring. Internal audit and follow-up of deficiencies are monitoring. Segregation of duties and reconciliations are control activities.
Types and limits of controlPreventive, detective, corrective; reasonable assurance; cost-benefit
  • Preventive controls stop errors or fraud before they happen (authorization, segregation of duties, passwords, edit checks).
  • Detective controls find problems after they occur (reconciliations, reviews, exception reports, physical counts).
  • Corrective controls fix problems found (backup restores, error-correction procedures). Directive controls (policies, training) encourage good behavior.
  • Inherent limitations: human error and judgment, collusion, management override, and the cost-benefit constraint. So controls give reasonable, never absolute, assurance.
Cost-benefit of a control
$$\text{Expected loss} = p(\text{event}) \times \text{Loss}$$ $$\text{Net benefit} = EL_{\text{without}} - EL_{\text{with}} - \text{Cost of control}$$

Implement the control only if the reduction in expected loss exceeds its cost (qualitative factors aside).

Exam trapNo control system can prevent collusion or management override completely. When a question asks for the main limitation of segregation of duties, the answer is collusion.
Instructor noteFor any control scenario, ask three questions: what could go wrong (the risk), which COSO component the fix belongs to, and whether it prevents or detects. Most distractors fail one of these tests.

Finished Governance, risk & compliance?

Mark it complete when you can place any control in its COSO component and name its owner.

Topic 2 of 4

Legislative & regulatory

The Sarbanes-Oxley Act's certification and internal-control requirements, the PCAOB's audit standard for ICFR, and the FCPA's bribery and accounting rules.

Sarbanes-Oxley Act (2002)The sections the exam tests
Key Sarbanes-Oxley sections
Section Requirement
§101 Creates the PCAOB to register, inspect and set standards for auditors of public companies.
§201 Bans auditors from providing certain non-audit services to audit clients (bookkeeping, systems design, internal audit outsourcing, legal, valuation).
§203 Lead and reviewing audit partners rotate every five years.
§301 Audit committee: independent members, directly responsible for the external auditor, procedures for complaints (whistleblowing).
§302 CEO and CFO certify each quarterly and annual report: they reviewed it, it is not misleading, the statements fairly present, they are responsible for and have evaluated disclosure controls, and they disclosed significant deficiencies and fraud to the auditors and audit committee.
§404 (a) Annual management report on ICFR: management's responsibility and its assessment of effectiveness. (b) The external auditor attests to ICFR (accelerated and large accelerated filers).
§806 Protects employee whistleblowers from retaliation.
§906 Criminal certification: knowingly false certification carries fines up to $1 million / 10 years (willful: $5 million / 20 years).
§302 vs §404

§302: CEO/CFO certification, every 10-Q and 10-K, disclosure controls. §404(a): management's annual ICFR assessment. §404(b): auditor's ICFR attestation (accelerated filers).

Exam trap§302 is quarterly and annual and covers disclosure controls; §404 is annual and covers internal control over financial reporting. Smaller (non-accelerated) filers still need §404(a) management assessment, but not the §404(b) auditor attestation.
PCAOB AS 2201 and deficiency levelsThe integrated audit, top-down

AS 2201 governs the audit of ICFR integrated with the financial-statement audit. The auditor uses a top-down, risk-based approach: start at the financial statements and entity-level controls (control environment, period-end reporting), then focus on significant accounts, relevant assertions and the controls that address their risks. Work is scaled to risk; the auditor may use the work of competent, objective internal auditors.

Deficiency levels (AS 2201)

Control deficiency: a control's design or operation does not allow timely prevention or detection of misstatements. Significant deficiency: less severe than a material weakness but important enough to merit the audit committee's attention. Material weakness: a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.

One or more material weaknesses → ICFR is not effective and the auditor issues an adverse ICFR opinion. Strong indicators: restatement to correct a material error, fraud by senior management (of any size), material misstatement found by the auditor that controls missed, ineffective audit-committee oversight.

Exam trapA deficiency can be a material weakness even if no misstatement occurred. What matters is whether there is a reasonable possibility that a material misstatement would not be prevented or detected.
Foreign Corrupt Practices Act (1977)Anti-bribery and accounting provisions
  • Anti-bribery provisions: prohibit US issuers, US persons and companies, and anyone acting in the US from corruptly offering anything of value to a foreign official (or party, or candidate) to obtain or retain business. Payments through agents count if the company knew or should have known.
  • Accounting provisions (issuers only, whether or not they operate abroad): keep books and records that accurately and fairly reflect transactions in reasonable detail, and maintain a system of internal accounting controls.
  • Exception: facilitating (grease) payments for routine government action (processing visas, connecting utilities), not discretionary decisions.
  • Affirmative defenses: the payment was lawful under the foreign country's written laws, or was a reasonable, bona fide expense (e.g. travel for a product demonstration).
Exam trapThe FCPA's accounting provisions apply to all SEC registrants, including purely domestic ones, and they have no materiality threshold.
Instructor noteWhen an FCPA question describes a payment, decide first whether the official's act is routine (facilitating) or discretionary (bribery), then check whether it was recorded accurately (accounting provisions).

Finished Legislative & regulatory?

Mark it complete when you can grade a deficiency and screen a foreign payment under the FCPA.

Topic 3 of 4

Internal auditing

What internal audit does, how it stays independent, which type of audit fits which question, and how findings are reported.

Purpose and independenceCharter, reporting lines, objectivity

Internal auditing provides independent, objective assurance and advice that improve an organization's governance, risk management and control. Its authority comes from a board-approved charter.

  • Organizational independence: the chief audit executive reports functionally to the audit committee (approval of charter, plan, budget, hiring and removal of the CAE) and administratively to senior management (usually the CEO).
  • Individual objectivity: auditors should not audit operations they managed within the past year or design controls they later audit.
  • Unrestricted access to records, people and property is set in the charter.
  • Internal auditors recommend; management decides and implements. Auditors do not take on operating responsibilities.
Exam trapReporting to the CFO or controller impairs independence when internal audit reviews finance. The best answer is almost always functional reporting to the audit committee of the board.
Types of auditFinancial, compliance, operational, IT, fraud
Types of internal audit engagement
Type Question it answers Example
Financial Are financial records and reports reliable? Testing account balances, reconciliations, ICFR for SOX
Compliance Are laws, regulations, contracts and policies followed? Environmental permits, loan covenants, travel policy, FCPA
Operational (performance) Are operations efficient and effective (economy, efficiency, effectiveness)? Is the purchasing process too slow? Is the warehouse layout wasteful?
Information technology Are IT general and application controls adequate? Access rights, change management, backups
Fraud investigation Did fraud occur, how, and who was involved? Investigating a tip about kickbacks
Exam trapOperational audits have no generally accepted criteria like GAAP; the auditor and management must agree on criteria (benchmarks, targets) before the work starts.
The audit process and reportingPlan, fieldwork, report, follow up
  1. Risk-based annual plan approved by the audit committee.
  2. Engagement planning: objectives, scope, criteria, resources, work program.
  3. Fieldwork: gather sufficient, reliable, relevant evidence; document in working papers.
  4. Communication: draft discussed with management, then a final report including management's response and action plan.
  5. Follow-up: confirm corrective action was taken, or that senior management accepted the risk of not acting.
Elements of an audit finding

Criteria (what should be) · Condition (what is) · Cause (why the gap) · Effect (risk or impact) · Recommendation (action to close the gap).

Instructor noteWhen asked who should decide whether to accept an unremediated risk, the answer is senior management (and, if it is significant, the board) — never internal audit.

Finished Internal auditing?

Mark it complete when you can match an engagement to its audit type and write a five-part finding.

Topic 4 of 4

Systems controls & security

General controls protect the whole IT environment; application controls protect individual transactions. Segregation of duties, access controls and recovery planning hold it together.

Segregation of dutiesAuthorization, custody, recording, reconciliation

Segregation of duties means no one person can both commit an error or fraud and conceal it. Separate four functions:

Incompatible functions
Function Examples Risk if combined with another function
Authorization Approving purchases, credit, write-offs, vendor master changes Approves own fictitious transactions
Custody of assets Handling cash receipts, signing checks, warehouse access Steals assets and approves or records the cover-up
Recording Posting journals, maintaining subledgers Hides theft by false entries (e.g. lapping, fictitious write-offs)
Reconciliation (verification) Bank reconciliations, counts, subledger-to-ledger checks Conceals discrepancies instead of reporting them

In IT, separate systems development (analysts, programmers) from operations (computer operators), and keep the database administrator, security administrator and data control roles apart. Programmers must not have access to live data or move their own changes into production.

Exam trapA programmer who can also run production jobs (operations) or change live data is the classic IT segregation failure. Look for "the developer moved the change into production".
General vs application controlsInput, processing and output

IT general controls apply to the whole environment: access security, change management (program changes tested and approved), IT operations (job scheduling, backups) and systems development. Application controls apply to one application's transactions.

Application controls
Stage Control What it catches
Input Field (format) check Letters in a numeric field
Validity check Customer or employee number not on the master file
Limit check Hours above 60 in a week
Reasonableness check Value out of line with another field (pay rate vs job grade)
Completeness check Required field left blank
Check digit Transposed or mistyped account numbers
Sequence check Missing or duplicate document numbers
Batch totals Lost, added or altered records in a batch
Processing Run-to-run totals, reconciliation of control totals, posting checks Records lost or changed between processing steps
Output Distribution lists, review of reports against control totals, secure disposal Reports to the wrong people; unnoticed errors
Batch control totals

Record count = number of documents. Financial total = sum of a monetary field. Hash total = sum of a field with no meaning in itself (account or part numbers). Recompute after input; any difference means a record was lost, added or changed.

Exam trapA limit check tests a field against a fixed boundary; a reasonableness check compares it with other data. A check digit catches transcription errors in an identifier, not wrong amounts.
Access controlsAuthentication, authorization, logging
  • Physical: locked server rooms, badges, visitor logs, environmental controls (fire suppression, UPS).
  • Authentication: something you know (password), have (token, phone) or are (biometric). Multi-factor combines two different types.
  • Authorization: role-based access and least privilege; review access periodically and remove it promptly when people leave or change jobs.
  • Network: firewalls, encryption in transit and at rest, intrusion detection, patching.
  • Logging: audit trails of who did what, reviewed for unusual activity (detective).
Exam trapA password plus a security question is still single-factor (both are something you know). True MFA needs two different categories.
Backup and disaster recoveryRPO, RTO and recovery sites
Recovery objectives

RPO (recovery point objective): the maximum data loss tolerated, measured in time; it sets backup frequency. RTO (recovery time objective): the maximum downtime tolerated; it sets the recovery site.

Recovery site options
Site What it has Recovery time Cost
Hot site (or mirrored site) Hardware, software and current data, ready to run Minutes to hours Highest
Warm site Hardware and connectivity; data must be restored Hours to days Medium
Cold site Space, power and cabling only Days to weeks Lowest
  • Keep backups off-site (or in a separate cloud region), test restores regularly, and keep at least one copy offline or immutable against ransomware.
  • Grandfather-father-son rotation keeps three generations of backups.
  • A business continuity plan covers the whole business (people, facilities, suppliers); the disaster recovery plan is its IT part.
Instructor noteMatch recovery choices to RTO: an online business that cannot be down for more than a few hours needs a hot or mirrored site; a payroll system run weekly can live with a warm or cold site.

Finished Systems controls & security?

Mark it complete when you can pick the input control for an error and the recovery site for an RTO.

Exercises

Interactive tools

Two exercises that train the judgments the exam tests most in this section: where a control belongs, and which duties must be kept apart.

COSO component matching game

Drag each control or weakness into the COSO component it belongs to, or use the menu on each card if you prefer the keyboard. Then check your answers. Each round draws ten cards from a bank of controls.

Controls to place

    Segregation-of-duties conflict checker

    Assign each duty in the purchasing, payables and cash cycle (plus two IT duties) to an employee. The checker flags incompatible combinations, explains the risk and suggests a fix. It starts with a small company's actual assignments.

    Who does what?

    Print-ready

    Formula sheet

    Every key framework and formula in Internal Controls on one sheet. Print it from here: the sidebar is hidden and the sheet prints black on white.

    Spaced repetition

    Flashcards

    Recall first, then flip. Your grade schedules the next review (SM-2-lite).

    Exam-style questions

    Practice MCQs

    Practice mode gives instant feedback; timed mode allows 1.8 minutes per question, like the exam. Filter by topic, difficulty, or questions you missed.

    Essay section

    Written-response practice

    Write your answer first (aim for about 30 minutes per case), then compare it with the model answer and score yourself against the rubric. Show your calculations: the exam awards marks for method.

    Key terms

    Glossary

    Search the section's vocabulary. Underlined terms in the lessons show these definitions on hover or keyboard focus.