Principle 10 - Design Control Activities: Difference between revisions

From Corrective Action Plan AZ
Auto-created by CAP AZ bot
 
No edit summary
 
(13 intermediate revisions by the same user not shown)
Line 1: Line 1:
== 10.0 Design Control Activities ==
[https://guides.gaoinnovations.gov/greenbook/2025/principle-10-design-control-activities/ External Link to US GAO Green Book Principle 10]


10.01 Management should design control activities to mitigate risks to
=== Overview ===
achieving the entity’s objectives to acceptable levels.


Response to Risks
==== <span id="10.01"></span>'''10.01''' ====
Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.


10.02 Management designs control activities in response to risks to
=== <span id="10.1"></span>10.1 Response to Risks ===
achieve an effective internal control system. Control activities are the
actions management establishes through policies and procedures to
specifically mitigate risks to achieving the entity’s objectives to
acceptable levels. Control activities support all the components of
internal control but are particularly aligned with the risk assessment
component. As part of periodic and ongoing risk assessments, management
identifies objectives; the risks related to the entity and its
objectives, including its service organizations; the entity’s risk
tolerance; and risk responses. Management designs control activities or
modifies existing control activities to mitigate risks to acceptable
levels within management’s defined risk tolerance. Typically, control
activities are needed when an entity chooses to either reduce or share a
risk. The nature and extent of the risk response and any associated
control activities will depend, at least in part, on management’s
defined risk tolerance.


Design of Appropriate Types of Control Activities
==== <span id="10.02"></span>'''10.02''' ====
Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.


10.03 Management designs appropriate types of control activities for the
=== <span id="10.2"></span>10.2 Design of Appropriate Types of Control Activities ===
entity’s internal control system, including the entity’s information
technology, by considering all aspects of its internal control
components, relevant business processes, and operating environment. An
entity’s internal control is flexible to allow management to tailor
control activities to meet the entity’s unique needs. The specific
control activities used by a given entity may be different from those
used by others based on several factors. These factors could include
specific threats the entity faces and the risks involved, differences in
objectives, managerial judgment, size and complexity of the entity,
operational environment, and sensitivity and value of data.


10.04 The common categories of control activities listed in table 1
==== <span id="10.03"></span>'''10.03''' ====
[omitted] illustrate the range and variety of control activities that
Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.
may be useful to management. The list is not all inclusive and may not
include all categories of control activities that an entity may need.


Design of Automated and Manual Control Activities
==== <span id="10.04"></span>'''10.04''' ====
The common categories of control activities listed illustrate the range and variety of control activities that may be useful to management.


10.05 Control activities can be designed and implemented in an
The list is not all inclusive and may not include all categories of control activities that an entity may need.
automated, partially automated, or a manual manner. Automated control
activities may be wholly or partially performed using the entity’s
information technology. Manual control activities are performed by
individuals without relying on the entity’s information technology.
Automated control activities tend to be more reliable because they are
less susceptible to human error and are typically more efficient.


10.06 Management designs information technology control activities to
==== Common Categories of Control Activities ====
support the operation and security of the entity’s information
* Top-level reviews of actual performance
technology and automated business processes. Information technology
* Reviews by management at the functional or activity level
control activities consist of general, application, and user control
* Establishment and review of performance measures and indicators
activities.
* Management of human capital
* Control activities over information processing
* Physical control activities over vulnerable assets
* Access restrictions to and accountability for resources and records
* Authorization of transactions
* Control activities over complete, accurate, and timely recording of valid transactions
* Appropriate documentation of transactions and control activities
* Oversight of entity business processes assigned to service organizations
* Segregation of duties
* Program-related control activities
* Fraud-related control activities
* Improper-payment-related control activities
* Compliance-related control activities


10.07 Application and user control activities rely on the entity’s
=== <span id="10.3"></span>10.3 Design of Automated and Manual Control Activities ===
information technology. Application control activities are automated
control activities that are incorporated directly into application
software to achieve the completeness, accuracy, and validity of
transactions and data. Application control activities include control
activities over the input, processing, and output of data. User control
activities, sometimes referred to as information technology-dependent
controls, are partially automated control activities that are performed
by individuals using the entity’s information technology or by relying
on the information processed through technology. For example, management
may authorize a transaction as part of an automated workflow or may
respond to incidents flagged in system log reports.


10.08 General control activities are designed to mitigate information
==== <span id="10.05"></span>'''10.05''' ====
security risks and are the actions established through policies and
Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.
procedures that apply to all or a large segment of an entity’s
information technology. General control activities support the proper
operation of the entity’s information technology by creating a suitable
environment for effective operation of application and user control
activities. General control activities can be designed and implemented
in either an automated or a manual manner.


10.09 Common categories of information technology control activities and
==== <span id="10.06"></span>'''10.06''' ====
how they align with information processing and information security
Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.
objectives are illustrated in figure 7.The common categories of
information technology control activities listed in figure 7 are meant
only to illustrate the range and variety of control activities that may
be useful to management. This list is not all inclusive and may not
include all information technology control activities that an entity may
need.


Design of Preventive and Detective Control Activities
==== <span id="10.07"></span>'''10.07''' ====
Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.


10.10 Control activities can be either preventive or detective. The main
==== <span id="10.08"></span>'''10.08''' ====
difference between preventive and detective control activities is
General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.
timing, that is, when the control activity occurs within an entity’s
operations. A preventive control activity is designed to avoid an
unintended event or result before it occurs. A detective control
activity is designed to discover and timely correct an unintended event
or result after it occurs. The effectiveness of a detective control
activity depends on timeliness of the corrective action to address the
unintended event or result. Corrective action may address the event that
occurred or may correct the deficiencies in the process that led to the
event.86


10.11 Management evaluates the purpose of the control activity as well
==== <span id="10.09"></span>'''10.09''' ====
as the likelihood of an unintended event or result occurring and the
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.[[File:10.09-fig-7.png|center|1000x1000px|thumb|'''Figure 7:''' Common Categories of Information Technology Control Activities]]
magnitude of impact it would have on the entity in achieving its
objectives. Management may design both preventive and detective control
activities to effectively mitigate the risks to achieving the
objectives, particularly in circumstances where the risk of an
unintended event or result occurring is high. Generally, the higher the
risk of an unintended event or result occurring, the stronger or more
robust the control activities need to be to effectively mitigate the
higher risk to acceptable levels.


10.12 Management designs an appropriate mix of preventive and detective
=== <span id="10.4"></span>10.4 Design of Preventive and Detective Control Activities ===
control activities to mitigate risks to an acceptable level,
prioritizing preventive control activities where appropriate. When
designing control activities, management first considers preventive
control activities, as they generally offer the most cost-efficient use
of resources and are generally effective at mitigating fraud and
improper payment risks. Management next considers detective control
activities and may design both preventive and detective control
activities when necessary to mitigate a particular risk.


10.13 There may be rare situations where management determines through
==== <span id="10.10"></span>'''10.10''' ====
its evaluation that a preventive control activity would better mitigate
Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.
a particular risk but is unable to implement it. In these situations,
management strengthens and expedites detective control activities and
may also expedite monitoring activities to enable the entity to
effectively mitigate the risk to acceptable levels, considering the risk
related to the likelihood of an unintended event or result occurring and
the magnitude of impact it would have on the entity in achieving its
objectives.


Design of Control Activities at Various Levels
==== <span id="10.11"></span>'''10.11''' ====
Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.


10.14 Management designs control activities at the appropriate levels in
==== <span id="10.12"></span>'''10.12''' ====
the organizational structure.
Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.


10.15 Management designs control activities for appropriate mitigation
==== <span id="10.13"></span>'''10.13''' ====
of risks in the entity’s business processes. Business processes
There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.
transform inputs into outputs through a series of transactions or
activities to achieve the entity’s objectives. Management designs
entity-level control activities, business process-level control
activities (commonly referred to as transaction control activities), or
both depending on the level of precision needed so that the entity
mitigates risks to an acceptable level related to its business
processes. Entity-level and transaction control activities can be
implemented in an automated, partially automated, or a manual manner.


10.16 Entity-level control activities are controls designed to mitigate
=== <span id="10.5"></span>10.5 Design of Control Activities at Various Levels ===
risks that have a pervasive effect on an entity’s internal control
system and may pertain to multiple components. Entity-level control
activities may include controls related to the entity’s risk assessment
process, control environment, service organizations, management
override, and performance or analytical reviews.


10.17 Transaction control activities are controls that directly mitigate
==== <span id="10.14"></span>'''10.14''' ====
information processing risks in the entity’s business processes. The
Management designs control activities at the appropriate levels in the organizational structure.
term transaction tends to be associated with business processes
addressing reporting objectives (e.g., financial transactions), while
the term activity is more often associated with business processes
addressing operations or compliance objectives. In the Green Book,
“transactions” and “transaction control activities” can cover both
transactions and activities. Management may design a variety of
transaction control activities for business processes, which may include
verifications, reconciliations, authorizations and approvals, physical
control activities, and supervisory control activities.


10.18 When designing transaction control activities, management
==== <span id="10.15"></span>'''10.15''' ====
evaluates information processing objectives to meet the entity’s
Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.
objectives and mitigate related risks. Information processing objectives
may include the following:


*  Completeness - All transactions and events that occur have been
==== <span id="10.16"></span>'''10.16''' ====
    properly recorded.
Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.


*  Accuracy - Data relating to transactions and events are properly and
==== <span id="10.17"></span>'''10.17''' ====
    timely recorded.
Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.


*  Validity - All recorded transactions and events actually occurred,
==== <span id="10.18"></span>'''10.18''' ====
    are related to the entity, and were executed according to prescribed
When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.
    procedures.


10.19 While the information processing objectives are most often
Information processing objectives may include the following:
associated with financial processes and transactions, information
processing objectives can be applied to any activity in an organization.
For example, information processing objectives and related control
activities can be applied to management’s decision-making processes that
use nonfinancial data.


10.20 When designing entity-level and transaction control activities,
* Completeness - All transactions and events that occur have been properly recorded.
management evaluates the level of precision needed for the business
* Accuracy - Data relating to transactions and events are properly and timely recorded.
processes to meet the entity’s objectives and mitigate related risks.
* Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.
The precision of a control activity refers to how exact the control
activity will be in preventing or detecting an unintended event or
result. Control activity precision is closely linked to the entity’s
risk tolerance for a particular objective; a lower risk tolerance will
require a more precise control activity. In determining the necessary
level of precision for a control activity, management evaluates the
following:


*  Level of aggregation - A control activity that is performed at a
==== <span id="10.19"></span>'''10.19''' ====
    more granular level generally is more precise than one performed at
While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.
    a higher level. For example, an analysis of obligations by budget
    object class normally is more precise than an analysis of total
    obligations for the entity.


*  Consistency and timing of performance - A control activity that is
==== <span id="10.20"></span>'''10.20''' ====
    performed routinely, consistently, and timely generally is more
When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:
    precise than one performed sporadically.


*   Correlation to relevant business processes - A control activity that
* '''Level of aggregation''' - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.
    is directly related to a business process generally is more likely
* '''Consistency and timing of performance''' - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.
    to prevent or detect and correct an error than a control activity
* '''Correlation to relevant business processes''' - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.
    that is only indirectly related.


Segregation of Duties
=== <span id="10.6"></span>10.6 Segregation of Duties ===


10.21 Management considers segregation of duties in designing control
==== <span id="10.21"></span>'''10.21''' ====
activities so that incompatible duties are segregated. Where such
Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.
segregation is not practical, management designs alternative control
activities to mitigate the risk.


10.22 Segregation of duties helps prevent fraud, waste, and abuse in the
==== <span id="10.22"></span>'''10.22''' ====
internal control system. Management considers the need to separate
Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.
control activities related to authority, custody, and accounting of
operations to achieve adequate segregation of duties within the entity’s
business processes. Segregation of duties can mitigate the risk of
management override. Management override circumvents existing control
activities and increases risk of fraud, waste, and abuse. Management
mitigates this risk through segregation of duties but cannot absolutely
prevent it because of the risk of collusion, where two or more employees
act together to commit fraud, waste, or abuse.


10.23 If segregation of duties is not practical within a business
==== <span id="10.23"></span>'''10.23''' ====
process because of limited personnel or other factors, management
If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.
designs alternative control activities to mitigate the risk of fraud,
 
waste, or abuse in the business process.
{{Principles}}
 
== Related Story Events ==
 
* [[2020: The Event|🗳️ 2020: The Event]]
* [[May 15, 2025: Let's Play Hot Potato|🥔 May 2025: PRR Issues]]

Latest revision as of 01:17, 14 August 2026

10.0 Design Control Activities

External Link to US GAO Green Book Principle 10

Overview

10.01

Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.

10.1 Response to Risks

10.02

Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.

10.2 Design of Appropriate Types of Control Activities

10.03

Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.

10.04

The common categories of control activities listed illustrate the range and variety of control activities that may be useful to management.

The list is not all inclusive and may not include all categories of control activities that an entity may need.

Common Categories of Control Activities

  • Top-level reviews of actual performance
  • Reviews by management at the functional or activity level
  • Establishment and review of performance measures and indicators
  • Management of human capital
  • Control activities over information processing
  • Physical control activities over vulnerable assets
  • Access restrictions to and accountability for resources and records
  • Authorization of transactions
  • Control activities over complete, accurate, and timely recording of valid transactions
  • Appropriate documentation of transactions and control activities
  • Oversight of entity business processes assigned to service organizations
  • Segregation of duties
  • Program-related control activities
  • Fraud-related control activities
  • Improper-payment-related control activities
  • Compliance-related control activities

10.3 Design of Automated and Manual Control Activities

10.05

Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.

10.06

Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.

10.07

Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.

10.08

General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.

10.09

Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.

Figure 7: Common Categories of Information Technology Control Activities

10.4 Design of Preventive and Detective Control Activities

10.10

Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.

10.11

Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.

10.12

Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.

10.13

There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.

10.5 Design of Control Activities at Various Levels

10.14

Management designs control activities at the appropriate levels in the organizational structure.

10.15

Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.

10.16

Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.

10.17

Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.

10.18

When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.

Information processing objectives may include the following:

  • Completeness - All transactions and events that occur have been properly recorded.
  • Accuracy - Data relating to transactions and events are properly and timely recorded.
  • Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.

10.19

While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.

10.20

When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:

  • Level of aggregation - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.
  • Consistency and timing of performance - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.
  • Correlation to relevant business processes - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.

10.6 Segregation of Duties

10.21

Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.

10.22

Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.

10.23

If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.

Assessment Observations Compared to Green Book Components, Principles, & Attributes

Control Environment

Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.

  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
  • Principle 4 - Demonstrate Commitment to Competence
    • Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
  • Principle 5 - Enforce Accountability
    • Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment

Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.

  • Principle 6 - Define Objectives and Risk Tolerances
    • Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities

Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.

  • Principle 10 - Design Control Activities
    • Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
  • Principle 11 - Design General Control Activities over Information
    • Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
  • Principle 12 - Implement Control Activities
    • Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication

Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.

  • Principle 13 - Use Quality Information
    • Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
  • Principle 14 - Communicate Internally
    • Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
  • Principle 15 - Communicate Externally
    • Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring

Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.

  • Principle 16 - Perform Monitoring Activities
    • Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)

Related Story Events