Auditing

Internal Controls

Distinguishing between Preventive and Detective controls and the importance of Segregation of Duties.

Questions use payroll, accounts payable, and purchasing department scenarios to illustrate SOD violations. Control classification questions present procedures as policy descriptions. Audit impact questions link control assessment to the audit risk model (inherent risk × control risk × detection risk).

What the exam tests

Control Classification

Identify whether a business procedure is a Preventive control (stops errors before they occur) or a Detective control (finds errors after they happen). Example: requiring controller approval before paying an invoice = Preventive.

Segregation of Duties Vulnerability Analysis

A scenario shows one person with multiple access rights (add vendors + enter invoices); identify the specific fraud risk, such as paying themselves through a fictitious vendor.

SOD Limitation Identification

Identify the inherent weakness of even well-designed SOD: it does not prevent collusion between multiple individuals.

Internal Control Component Identification

Identify the five components of internal control: Control Environment, Risk Assessment, Control Activities, Information and Communication, Monitoring.

Audit Impact Analysis

Determine how control strength affects the audit: effective controls → no increase in substantive testing, while ineffective controls → higher control risk → more substantive testing required.

Analytical Discrimination (Preventive vs. Detective)

Key rules

  • Preventive: designed to stop an error or fraud before it happens (approval requirements, access restrictions, locked cash drawers).
  • Detective: designed to find an error or fraud after it has happened (reconciliations, audits, variance reports).
  • A control cannot be both; classify by timing, before or after the event.

Common traps

  • !Classifying a bank reconciliation (detective) as preventive because it 'prevents future errors.'

Fraud Vulnerability Identification (SOD)

Key rules

  • Segregation of Duties requires that no single person controls all steps of a transaction.
  • High-risk combinations: hiring + paying employees (fictitious staff); adding vendors + approving invoices (fictitious vendors); recording + reconciling (covers own errors).
  • The risk named in the question is always the specific fraud enabled by the combined access.

Common traps

  • !Naming a general fraud risk instead of the specific one enabled by the described access combination.

SOD Limitations

Key rules

  • SOD does not prevent collusion. Two or more people working together can circumvent it.
  • SOD does not prevent errors caused by a single person within their own authorized scope.

Strategic Auditing Logic

Key rules

  • If internal controls are effective: control risk is low → auditor reduces substantive testing.
  • If internal controls are ineffective or untested: control risk is high → auditor increases substantive testing to compensate.
  • Substantive testing directly verifies account balances and transactions. It is the auditor's fallback when controls fail.

Common traps

  • !Stating that strong controls eliminate the need for all substantive testing. They reduce it, they do not eliminate it.

Try one

An auditor finds that accounts payable employees can add new vendors and create invoices. To reduce risk, the company requires that every invoice be approved by the controller before any payment is made to the vendor. What type of control is the approval requirement?

A.Internal control
B.Preventive control
C.Detective control
D.Directive control

Requiring approval before payment stops an error or fraud from occurring in the first place, which makes it a preventive control. Detective controls, such as reconciliations, only find problems after they have already happened.

Practice these skills offline.

Download GovReady and drill every topic with instant feedback. No internet required.

Download on the App Store