10.20

From Corrective Action Plan AZ

Control Activities

Principle 10 - Design Control Activities

Attribute 10.20 - When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity's objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity's risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:

  • Level of aggregation - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.
  • Consistency and timing of performance - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.
  • Correlation to relevant business processes - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.

>>>Navigational Buttons<<<


No Examples