Internal controls and internal audit get confused often enough that it is worth stating the distinction plainly at the outset: management designs and operates internal controls, and internal audit independently evaluates whether those controls are actually working. The two are closely connected, but they are not the same function, and understanding where one ends and the other begins clarifies who is responsible for what inside an organization.
What Are Internal Controls?
Internal controls are the processes, policies, and procedures an organization puts in place to provide reasonable assurance that its objectives will be achieved, covering the reliability of financial reporting, the effectiveness and efficiency of operations, and compliance with applicable laws and regulations. Internal controls are built and operated by management, embedded into how the organization runs on a day-to-day basis rather than existing as a separate oversight function.
A requirement for dual authorization on large payments, a system that automatically flags unusual transactions, and a monthly bank reconciliation are all examples of internal controls, each designed to address a specific risk that management has identified.
Also check: Internal Audit Services
What Does Internal Audit Evaluate?
Internal audit is the independent, objective function that evaluates whether the internal controls management has put in place are actually functioning as intended. Internal audit does not design or operate controls itself, since doing so would compromise the independence needed to assess them credibly. Instead, it tests controls, examines whether they are structured appropriately, and reports its conclusions to management and the board.
This distinction matters in practice. If internal audit were responsible for both designing controls and evaluating them, it would effectively be reviewing its own work, undermining the objectivity that gives its conclusions credibility. Keeping the two functions separate, management owns and operates controls, internal audit independently assesses them, is what allows internal audit’s findings to be trusted as an unbiased check rather than a self-assessment.
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
How Internal Auditors Test Controls
Internal auditors test controls using a combination of techniques, selected based on what kind of control is being tested and what evidence will best support a conclusion. Inquiry involves asking staff how a control is supposed to work and how it is applied in practice. Observation involves watching a control being performed in real time, rather than relying solely on a description of it. Inspection examines documentation evidencing that a control took place, such as a signed approval form. Reperformance involves the auditor independently carrying out the control themselves to confirm that the original result was correct.
Which combination of techniques an auditor uses depends on the nature of the control. A control that leaves a clear paper trail, such as a signed authorization, lends itself well to inspection. A control that depends on judgment in the moment, such as a manager reviewing a transaction for reasonableness, may require observation or reperformance to properly assess.
Types of Internal Controls
Preventive Controls
Preventive controls are designed to stop an error, irregularity, or unauthorized action before it happens. Examples include requiring dual authorization for payments above a certain value, restricting system access based on job role, and requiring pre-approval before a new vendor is added to the payment system. Preventive controls are generally considered the most effective type, since they address risk before it results in an actual loss or error.
Detective Controls
Detective controls are designed to identify an error or irregularity after it has already occurred. Examples include bank reconciliations, periodic inventory counts, and exception reports flagging unusual transactions. Detective controls do not prevent an issue from happening, but they limit how long it can go unnoticed, which matters considerably for how much damage it can ultimately cause.
Corrective Controls
Corrective controls are designed to fix an issue once it has been identified, typically through detective controls surfacing it in the first place. Examples include a defined process for correcting and reprocessing a rejected transaction, or a formal procedure for recovering funds after an overpayment is discovered. An organization with strong detective controls but weak corrective controls can still suffer real damage, since identifying a problem without a defined process to resolve it leaves the underlying issue unaddressed.
Control Design
Control design refers to whether a control, as structured, is actually capable of preventing or detecting the specific risk it is meant to address. A control can be poorly designed even if everyone follows it perfectly. A dual authorization requirement that allows the same two people to approve every transaction regardless of amount, for instance, is a design flaw, since it does not scale the level of scrutiny to the size of the risk involved. Internal audit evaluates control design by examining whether a control’s structure logically addresses the risk it targets, independent of whether it is currently being followed in practice.
Control Effectiveness
Control effectiveness refers to whether a control, assuming it is well designed, is actually operating consistently in practice. A well-designed control that is only followed some of the time provides limited real protection, and internal audit evaluates effectiveness by testing a sample of instances where the control should have applied, confirming whether it genuinely did. This is why control testing distinguishes between design and effectiveness as two separate questions: a control can pass one test and fail the other, and each failure points to a different kind of fix.
Control Deficiencies
A control deficiency exists where a control is missing entirely, poorly designed, or not operating effectively, leaving the organization exposed to the risk that control was meant to address. Internal audit distinguishes between a design deficiency, where the control itself is inadequate even when followed correctly, and an operating deficiency, where an adequately designed control simply is not being applied consistently. Making this distinction matters because the appropriate fix is different in each case: a design deficiency requires redesigning the control itself, while an operating deficiency may require better training, clearer accountability, or closer supervision of an already-adequate control.
Internal Control Testing
Internal control testing is the practical process auditors use to determine whether a specific control is functioning as intended. It typically involves selecting a sample of transactions or instances where the control should have operated, then verifying whether it actually did, whether that means confirming a required approval was obtained, checking that a reconciliation was performed on schedule, or reviewing system access logs to confirm only authorized personnel accessed a given system. Sample sizes and testing depth generally scale with the risk level of the control being tested, with higher-risk controls receiving more extensive testing than lower-risk ones.
Recommendations for Improving Controls
Once internal audit identifies a control deficiency, its role includes providing practical, proportionate recommendations for addressing it. This might mean redesigning a control entirely, adding an additional layer of review for higher-risk transactions, automating a manual step that is prone to human error, or improving training and communication around an existing control that is not being followed consistently. The most useful recommendations are specific enough for management to act on directly, rather than general statements that leave the actual solution undefined, and they should be proportionate to the risk involved, since over-engineering a control for a low-risk process can create unnecessary operational burden without a meaningful reduction in risk.
Frequently Asked Questions (FAQs)
What is the relationship between internal controls and internal audit?
What are the three main types of internal controls?
What is the difference between control design and control effectiveness?
What is a control deficiency?
How does internal audit test internal controls?
Why doesn't internal audit design the controls it evaluates?
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
How Farahat & Co. Can Help
Internal controls and internal audit are two connected parts of a complete governance framework. For a full overview of internal audit objectives, types, process, and standards, see our complete internal audit guide.
Farahat & Co. helps UAE businesses test the design and effectiveness of their internal controls, identify deficiencies, and implement practical, proportionate improvements.
Contact Farahat & Co. today to discuss your internal audit requirements.
