Internal Control Policies
Designing, testing, and documenting internal controls that withstand scrutiny. A practitioner's guide.
Internal control is the bedrock of reliable financial reporting. The COSO Internal Control — Integrated Framework defines five components: control environment, risk assessment, control activities, information and communication, and monitoring. A deficiency in any one component undermines the entire system.
For audit purposes, the critical distinction is between entity-level controls and process-level controls. Entity-level controls — tone at the top, governance structure, the ethics policy — set the conditions under which process-level controls operate. A strong control environment cannot compensate for broken process controls, but a weak control environment will eventually corrode even well-designed process controls.
The walkthrough remains the auditor's primary tool for understanding the design of controls. It traces a single transaction from initiation through recording to reporting, confirming that each control point is present, appropriately placed, and operating as described. A walkthrough that reveals gaps in the control design is an early warning that the system cannot be relied upon.
Documentation of controls should be risk-based. Not every control warrants the same depth of testing. The auditor's response should be proportional to the risk of material misstatement — controls over high-risk processes deserve more attention than controls over immaterial or low-risk flows.