Skip to main content
Category: Internal Controls

Control Activities

Also known as: Control Procedures
Simply put

Control activities are the specific actions an organization puts in place through its policies and procedures to keep risks at an acceptable level. They are the practical steps, such as approvals, reviews, and separating duties among staff, that help make sure management's instructions to manage risk are actually carried out. They are one component of a broader system of internal control.

Formal definition

Control activities are the actions established through an organization's policies and procedures that help ensure management's directives to mitigate risks to the achievement of objectives are carried out. Within widely used internal control frameworks such as COSO's Internal Control - Integrated Framework, control activities constitute one of several interrelated components of internal control and are typically designed and operated by management as part of business processes at all levels of the entity. They commonly include practices such as segregation of duties, authorization and approval, reconciliation and review, and physical security controls, and are generally selected and developed to reduce identified risks to an acceptable level. Control activities can be preventive or detective and are distinguished from other internal control components; their effectiveness depends on both control design and operating effectiveness, which are assessed separately. The specific mix of control activities and their required rigor vary by entity, sector, and applicable requirements, so this entry is educational and not audit, compliance, or legal advice.

Why it matters

Control activities are where an organization's intentions to manage risk become concrete, repeatable actions. A risk assessment may identify what could go wrong, and management may set directives to address those exposures, but without control activities embedded in day-to-day business processes, those directives remain aspirational. Approvals, reconciliations, reviews, and the separation of incompatible duties are the mechanisms that translate risk management objectives into operational reality, helping keep identified risks at a level the organization considers acceptable.

The design and operation of control activities matter to different stakeholders in different ways. For management, they are a primary means of executing responsibilities for risk mitigation within processes. For assurance functions and external auditors, control activities are a focal point of testing, because their effectiveness depends on both how they are designed and whether they operate as intended over time. A control that is well designed on paper but not consistently performed provides little protection, which is why control design and operating effectiveness are typically assessed separately.

Within widely used frameworks such as COSO's Internal Control - Integrated Framework, control activities are one interrelated component of a broader system of internal control, not a standalone solution. Their appropriate mix and rigor vary by entity, sector, and applicable requirements, and they work in concert with other components rather than substituting for them. Overreliance on any single control, or treating the presence of controls as evidence of their effectiveness, can create a false sense of assurance.

Who it's relevant to

Management and process owners
Control activities are typically designed and operated by management as part of business processes. Process owners are generally responsible for ensuring that approvals, reconciliations, reviews, segregation of duties, and other controls are actually performed as intended, translating risk mitigation directives into day-to-day practice.
Internal auditors and assurance functions
Assurance functions frequently examine control activities to assess whether they are both well designed and operating effectively. Because these two dimensions are evaluated separately, auditors look beyond the existence of a documented control to whether it functions consistently in practice.
Boards and audit committees
While control activities sit largely within management's remit, boards and their audit committees generally exercise oversight of the overall system of internal control. They rely on reporting from management and assurance functions to gain confidence that controls addressing significant risks are designed and operating appropriately, without assuming operational responsibility for performing the controls themselves.
Compliance and risk officers
Risk and compliance professionals often help identify the risks that control activities are meant to address and may advise on the mix and rigor of controls appropriate to the organization's exposures, sector, and applicable requirements. The suitability of any given control set depends on facts and jurisdiction and calls for professional judgment.

Inside Control Activities

Definition and Position within Internal Control
Control activities are the policies and procedures that help ensure management directives are carried out and that responses to risk are executed. Under the COSO Internal Control-Integrated Framework, they are one of the framework's components, working alongside the control environment, risk assessment, information and communication, and monitoring activities rather than standing alone.
Preventive and Detective Controls
Control activities are commonly categorized by timing and intent. Preventive controls are designed to stop errors or irregularities before they occur, while detective controls are designed to identify errors or irregularities after they have occurred. Many control frameworks treat a mix of both as generally appropriate, though the balance depends on the risks being addressed.
Automated and Manual Controls
Control activities may be performed by people (manual controls) or embedded in systems (automated or application controls), and some combine the two (IT-dependent manual controls). The nature of the control affects how its design and operating effectiveness are evaluated.
Common Control Types
Typical examples include authorizations and approvals, verifications, reconciliations, segregation of duties, physical and logical access controls, and reviews of operating performance. The specific controls selected depend on the risks identified and the organization's processes.
Control Design versus Operating Effectiveness
Design effectiveness concerns whether a control, if operated as intended, would address the identified risk. Operating effectiveness concerns whether the control actually functioned as designed over a period. These are distinct assessments and are not interchangeable; a well-designed control can still fail in operation.
Relationship to Risk and Ownership
Control activities are typically implemented and operated by management and process owners as part of the first line, responding to risks identified through risk assessment. Assurance functions such as internal audit generally evaluate rather than own these controls, and accountability for the control environment sits with management under board oversight.

Common questions

Answers to the questions practitioners most commonly ask about Control Activities.

Are control activities the same thing as internal control?
No. Control activities are one component of a broader internal control system, not the whole of it. Under frameworks such as COSO's Internal Control, Integrated Framework, control activities sit alongside other components including the control environment, risk assessment, information and communication, and monitoring activities. Treating control activities as synonymous with internal control overlooks the surrounding conditions, such as governance tone, risk assessment processes, and monitoring, that determine whether those activities actually function as intended. Control activities are the policies and procedures that help ensure risk responses are carried out, but they depend on the other components to be effective.
If a control activity is well designed, does that mean it is working?
Not necessarily. Design effectiveness and operating effectiveness are distinct concepts that should not be conflated. A control may be well designed, meaning that, if operated as intended, it would address the identified risk, yet still fail in practice because it is not performed consistently, is overridden, or is applied by personnel without adequate competence or authority. Assurance functions typically evaluate both dimensions separately: whether the control is capable of addressing the risk (design) and whether it has actually operated as intended over a relevant period (operating effectiveness). Concluding that a control works based on its design alone can leave residual risk unaddressed.
Who is responsible for designing and performing control activities?
Control activities are generally owned and operated by management and operational personnel, commonly described as the first line in three-lines models, because they are embedded in day-to-day business processes. Management typically designs, implements, and maintains these controls as part of its responsibility for managing risk. Risk and compliance functions may support, advise on, and monitor control activities, while internal audit typically provides independent assurance over their design and operating effectiveness. The board and its committees generally exercise oversight rather than performing controls directly. The precise allocation depends on the entity's structure, sector, and applicable framework.
How do you decide which control activities are needed for a given process?
Control activities are generally selected in response to risks identified through a risk assessment, so the starting point is typically understanding the relevant objectives and the risks that threaten them. Under many frameworks, the nature and extent of controls are calibrated to the significance of the risk, considering factors such as likelihood and impact, and to the organisation's risk appetite. This often involves mapping controls to specific risks to confirm that priority risks are addressed and to identify gaps or redundant controls. The appropriate mix depends on the facts of the process, the entity, and the applicable regime, and reflects professional judgment rather than a fixed formula.
What are common types of control activities an organisation might implement?
Control activities are often categorised in several ways, and the categories are not mutually exclusive. They may be described as preventive (intended to stop an error or issue before it occurs) or detective (intended to identify an issue after it has occurred). They may be manual, automated, or a combination. Frequently referenced examples include authorisations and approvals, segregation of duties, reconciliations, verifications, physical controls over assets, and reviews of performance. The specific controls that are appropriate depend on the process, the associated risks, and the organisation's circumstances; this list is illustrative rather than exhaustive or prescriptive.
How can an organisation tell whether its control activities are operating effectively over time?
Operating effectiveness is generally assessed by gathering evidence that a control has been performed as intended over a relevant period, rather than at a single point. This is typically supported by monitoring activities, another component of internal control under frameworks such as COSO, which may include ongoing monitoring embedded in operations, separate evaluations, or a combination. Assurance functions such as internal audit may test controls independently. Approaches vary with the nature of the control, the significance of the risk, and applicable requirements, so the appropriate method and frequency reflect the entity's judgment and context.

Common misconceptions

Control activities are the whole of internal control, so having strong controls means the internal control system is sound.
Under frameworks such as COSO, control activities are only one component. An effective system also depends on the control environment, risk assessment, information and communication, and monitoring. Strong control activities cannot fully compensate for weaknesses in the other components, such as a poor control environment or inadequate risk assessment.
If a control is well designed, it is effective.
Design effectiveness and operating effectiveness are separate assessments. A control may be appropriately designed to address a risk yet still fail to operate as intended over the relevant period. Both dimensions generally need to be evaluated before concluding a control is effective.
Internal audit or the board owns and operates control activities.
Control activities are typically designed, implemented, and operated by management and process owners in the course of running the business. Internal audit generally provides independent assurance over those controls, and the board provides oversight. Attributing ownership of day-to-day controls to assurance functions or the board conflates distinct roles.

Best practices

Map control activities to the specific risks identified through the risk assessment process, so that each significant risk has a corresponding, proportionate control rather than accumulating controls without a clear purpose.
Assess both design effectiveness and operating effectiveness separately, and document the basis for each conclusion, recognizing that a well-designed control can still fail in operation.
Maintain a deliberate balance of preventive and detective controls appropriate to the risks, rather than relying disproportionately on one type.
Clarify and document ownership so that management and process owners are accountable for operating controls, while assurance functions evaluate them and the board provides oversight; avoid blurring these lines of responsibility.
Give particular attention to segregation of duties and access controls, and evaluate whether automated or IT-dependent controls depend on general IT controls that must themselves be reliable.
Periodically reassess control activities as processes, systems, and risks change, and treat framework references such as COSO as guidance to be applied to the entity's own facts, jurisdiction, and judgment rather than as a fixed checklist.