Resources · Professional guides
Internal control evaluation guide
What “good enough” control means
A control is useful if it reduces a real risk to an acceptable level and leaves evidence. Fancy manuals that nobody follows are not controls.
Walkthrough habit (every key process)
- Pick a sample transaction and follow it from start to posting.
- Ask: who initiates, who approves, who records, who reconciles?
- Check segregation: can one person complete a fraud without detection?
- Confirm the control operates on time (not only “exists on paper”).
Common weak points in trading & manufacturing
| Area | What often goes wrong |
|---|---|
| Sales & receivables | Unauthorised credit, delayed invoicing, weak collection follow-up |
| Purchases & payables | GRN without PO, duplicate vendors, payment without 3-way match |
| Inventory | Open access to store, weak cut-off, no variance investigation |
| Cash & bank | Unreconciled accounts, single signatory, delayed banking |
| Payroll | Ghost employees, unrestricted master-file access |
| Period-end | Journals without review, recurring entries never revalidated |
Evaluation output (keep it practical)
- Risk → control → frequency → evidence → owner → gap (if any).
- Rate design (is it capable?) and operation (did it work on samples?).
- Agree remediation dates with management; re-test later.
Worked example: a walkthrough that finds something
Take the "purchases and payables" cycle at a mid-sized trading company. Pick one recent purchase invoice and follow it end to end: a store supervisor raised a purchase requisition, a purchase order was issued, goods arrived and a GRN was recorded, the supplier invoice was matched to the PO and GRN, and it was posted for payment.
On paper this looks fine. The walkthrough earns its keep when you ask the harder questions: who can create a new vendor in the master file, and is that person different from whoever approves payments to that vendor? Can the same person who raises a requisition also approve the PO above a certain value? Is the three-way match (PO, GRN, invoice) actually enforced by the system, or can someone override it with a note? In smaller Nepali trading and manufacturing firms specifically, it's common to find one finance person holding requisition, approval, and payment authority simultaneously — the walkthrough is where that gets caught, not the year-end audit.
Where this sits in the ACCA syllabus
Internal control evaluation is a core theme in Audit and Assurance (AA) — understanding, documenting, and testing controls (walkthroughs, tests of control) — and it resurfaces in Advanced Audit and Assurance (AAA) where you're expected to evaluate control environments in more complex group and IT-dependent settings, including general IT controls and segregation of duties within ERP systems.
Common pitfalls
- Confusing "documented" with "operating" — a control that exists in a procedures manual but isn't actually followed on the shop floor gives false comfort.
- Testing design but not operation — a control can be well-designed (capable of preventing/detecting the risk) yet fail in practice because of staff turnover, workload, or simple habit.
- Treating segregation of duties as binary — in small teams, full segregation often isn't realistic; the practical fix is a compensating control (independent review, exception reporting) rather than pretending the gap doesn't exist.
- No follow-up on remediation — agreeing a fix with management without a re-test date means the same weakness is often still there next year.