Skip to main content
Category: Internal Controls

Control Testing

Also known as: Test of Controls, Tests of Control
Simply put

Control testing is a set of audit procedures used to check whether an organization's internal controls are actually working as intended. It examines both how a control is designed and whether it operates effectively in practice. The results help those responsible for assurance judge how much reliance can be placed on the organization's controls.

Formal definition

Control testing is an audit procedure that evaluates the design and operating effectiveness of internal controls by examining an organization's policies, procedures, and their application. It is distinct from substantive testing: control testing assesses whether controls are functioning to prevent or detect errors and misstatements, whereas substantive procedures directly test the underlying transactions or balances. Within the assurance and internal audit context, control testing typically supports risk management and compliance objectives by informing conclusions about control reliability. The specific scope, methods, and extent of testing generally depend on the applicable audit or assurance framework, the nature of the control, and professional judgment. This entry is educational and not audit, legal, or compliance advice.

Why it matters

Controls that exist only on paper provide no protection. Control testing is how assurance functions move beyond confirming that a policy or procedure has been documented to determining whether it actually operates as intended in day-to-day practice. Without this evidence, boards, audit committees, and management may place unwarranted reliance on controls that are poorly designed or that have quietly broken down, leaving the organization exposed to errors, misstatements, or compliance failures that no one has detected.

The distinction between a control's design and its operating effectiveness is central to why this work matters. A control can be well designed yet fail in operation because it is applied inconsistently, bypassed under pressure, or performed by staff who do not understand its purpose. Control testing surfaces these gaps and gives those responsible for assurance a defensible basis for judging how much reliance can be placed on the control environment. That judgment, in turn, shapes decisions about the scope and extent of further audit work and informs the organization's overall view of its risk management and compliance posture.

Because the results of control testing feed into broader assurance conclusions, weaknesses identified through testing can prompt remediation before they translate into material problems. The value of the exercise depends heavily on the rigor of the procedures applied and the professional judgment exercised in scoping them; testing that is too narrow or superficial can create false comfort. This entry is educational and not audit, legal, or compliance advice.

Who it's relevant to

Internal auditors and assurance functions
Internal auditors are typically the practitioners who plan and perform control testing, exercising professional judgment over its scope, methods, and extent. Their conclusions on control design and operating effectiveness form the evidentiary basis for the reliance that can be placed on the control environment and often shape the nature and extent of further audit work.
Chief compliance and risk officers
Because control testing supports risk management and compliance objectives, these officers rely on its results to understand whether the controls intended to manage risk and meet compliance obligations are actually working. Testing outcomes can highlight where controls need to be redesigned or where operation has broken down, informing remediation priorities.
Audit committees and boards
Boards and their audit committees exercise oversight rather than performing testing themselves. Control testing results give them independent evidence about the reliability of the organization's controls, helping them challenge management and satisfy themselves that the assurance they receive is well founded.
Management and control owners
Management is generally responsible for designing, implementing, and operating internal controls. Findings from control testing tell control owners where controls are deficient in design or failing in operation, enabling them to take corrective action. Testing does not transfer accountability for the controls from management to the assurance function.

Inside Control Testing

Test of Design
An evaluation of whether a control, as designed, is capable of preventing or detecting the risk it is intended to address. Design testing typically occurs before or alongside operating effectiveness testing and considers whether the control, if operating as intended, would achieve its objective.
Test of Operating Effectiveness
An assessment of whether a control actually operated as designed over a defined period, performed by the responsible party at the required frequency. This is distinct from design testing; a well-designed control can still fail in operation.
Testing Methods
Techniques used to gather evidence, which commonly include inquiry, observation, inspection of documentation, and reengagement or reperformance. Methods generally vary in the strength of evidence they provide, and the appropriate method depends on the nature of the control being tested.
Sample Selection
The approach to choosing items for testing from a population, which may be statistical or judgmental. Sample size and selection method typically depend on control frequency, risk significance, and the level of assurance sought.
Population and Completeness
The full set of instances a control operated over the testing period. Establishing a complete and accurate population is generally a prerequisite to drawing reliable conclusions from a sample.
Deficiency Evaluation
The process of assessing exceptions or failures identified during testing to determine severity, such as whether an issue rises to a deficiency, significant deficiency, or material weakness under certain frameworks. Classification thresholds vary by framework and context.
Documentation and Evidence Retention
The records supporting the nature, timing, extent, and results of testing, retained to enable review and support conclusions. Adequate documentation is typically necessary for assurance functions and external parties to rely on the work.

Common questions

Answers to the questions practitioners most commonly ask about Control Testing.

Is testing that a control was designed properly the same as confirming it actually works?
No. These are two distinct dimensions of control testing that should not be conflated. Testing control design (often called a test of design) evaluates whether a control, if operated as intended, would be capable of preventing or detecting the risk it is meant to address. Testing operating effectiveness evaluates whether the control actually functioned as designed over a period of time. A control can be well designed on paper yet fail in practice because it is not consistently performed, is overridden, or lacks the necessary resources. Conversely, a control that appears to operate may be poorly designed and therefore ineffective against the risk. Both dimensions typically need to be assessed to reach a conclusion about a control, and the specific approach depends on the framework, the nature of the control, and the professional's judgment.
Does control testing belong to the internal audit function, or is it also performed elsewhere?
Control testing is not the exclusive province of any single function, and attributing it solely to internal audit is a common oversimplification. Under the three lines model as commonly described, controls are owned and often self-tested or monitored by management in the first line, monitored and challenged by risk and compliance functions in the second line, and independently assured by internal audit in the third line. The purpose, independence, and reporting lines differ across these functions: management's testing supports its own accountability for controls, while internal audit's testing provides independent assurance to the board or audit committee. External auditors may also test certain controls for their own purposes. Identifying which function is performing the testing, and in what capacity, is essential to understanding the reliance that can be placed on the results.
How is a testing sample size typically determined?
Sample size is generally driven by factors such as the frequency with which the control operates, the assessed level of risk, the degree of assurance sought, and whether the control is manual or automated. Higher-frequency controls and higher-risk areas typically call for larger samples, while automated controls that operate consistently may be tested through a smaller sample or through examination of the underlying configuration. Many organizations apply sampling guidance drawn from professional standards or internal methodologies. This entry does not prescribe specific numbers, as appropriate sample sizes depend on the methodology adopted, the population involved, and professional judgment, and can vary by framework and engagement.
What testing methods are commonly used, and when is each appropriate?
Commonly described methods include inquiry, observation, inspection or examination of documentary evidence, and reperformance, and these are often ranked by the strength of evidence they provide. Inquiry alone is generally regarded as the least persuasive and is typically corroborated by other methods. Observation captures a control at a point in time. Inspection of evidence supports testing over a period. Reperformance, where the tester independently executes the control, tends to provide stronger evidence but is more resource-intensive. The choice among methods generally reflects the nature of the control, the assurance required, and the availability of evidence, and testers often combine methods. The suitability of any method is a matter of judgment within the applicable framework.
How should identified control deficiencies be handled once testing is complete?
When testing identifies that a control is not designed or operating effectively, the finding is typically documented, evaluated for severity, and communicated to the appropriate parties, which may include the control owner, management, and, depending on significance, the audit committee or board. Evaluation often considers the potential impact and the likelihood that the deficiency could result in an error or failure, and whether compensating controls mitigate it. Remediation is generally owned by management as the party accountable for the control, while assurance functions may track and later revalidate the fix. The classification of deficiencies and the escalation thresholds depend on the framework, the entity, and applicable requirements, so specific treatment should be determined against the relevant methodology.
How does control testing relate to the distinction between inherent and residual risk?
Control testing informs an assessment of residual risk, the risk that remains after controls are taken into account, as distinct from inherent risk, the level of risk before considering controls. If testing shows that controls are designed and operating effectively, this generally supports a conclusion that residual risk has been reduced toward the level intended. If testing reveals deficiencies, residual risk may be higher than assumed, which can affect risk assessments and reporting. Control testing does not by itself set risk appetite or tolerance; rather, it provides evidence about how well controls are reducing inherent risk, which management and the board can then weigh against the risk levels they have accepted. The interpretation of results depends on the entity's risk framework and judgment.

Common misconceptions

A control that is well designed does not need operating effectiveness testing.
Test of design and test of operating effectiveness address different questions. A control may be soundly designed yet fail to operate consistently, so many frameworks contemplate both evaluations for controls relied upon for assurance.
Control testing and control monitoring are the same activity performed by the same function.
These are generally distinct. Management often performs ongoing monitoring of its own controls as part of its responsibilities, while independent assurance functions such as internal audit may perform separate testing to provide objective assurance. Accountability differs depending on who performs the work and its purpose.
Passing a control test with no exceptions guarantees the underlying risk is fully addressed.
Testing typically provides assurance about a control's operation over a sample and a defined period, not absolute certainty. Sampling limitations, the scope of the control, and residual risk outside the control's coverage mean conclusions are inherently qualified rather than a guarantee against the risk occurring.

Best practices

Define the control objective and the specific risk it addresses before selecting a testing approach, and confirm design adequacy before concluding on operating effectiveness.
Match the testing method to the desired strength of evidence, recognizing that inquiry alone is generally weaker than inspection, observation, or reperformance.
Establish a complete and accurate population and document the basis for sample size and selection, aligning the extent of testing to control frequency and risk significance.
Evaluate and classify identified exceptions consistently against the criteria of the applicable framework, distinguishing isolated instances from systemic issues before assigning severity.
Retain documentation of the nature, timing, extent, and results of testing sufficient to allow an independent reviewer to reperform or rely upon the conclusions.
Clarify who owns each activity, keeping management's monitoring of its own controls separate from independent assurance testing, and treat these outputs as educational inputs to professional judgment rather than a substitute for legal, audit, or compliance advice.