Principle 10 - Design Control Activities: Difference between revisions
No edit summary |
No edit summary |
||
| Line 39: | Line 39: | ||
==== <span id="10.09"></span>'''10.09''' ==== | ==== <span id="10.09"></span>'''10.09''' ==== | ||
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need. | Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.[[File:10.09-fig-7.png|center|800x800px|thumb|'''Figure 7:''' Common Categories of Information Technology Control Activities]] | ||
[[File:10.09-fig-7.png|center|800x800px]] | |||
=== <span id="10.4"></span>10.4 Design of Preventive and Detective Control Activities === | === <span id="10.4"></span>10.4 Design of Preventive and Detective Control Activities === | ||
Revision as of 01:10, 14 August 2026
10.0 Design Control Activities
External Link to US GAO Green Book Principle 10
Overview
10.01
Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.
10.1 Response to Risks
10.02
Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.
10.2 Design of Appropriate Types of Control Activities
10.03
Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.
10.04
The common categories of control activities listed in table 1 [omitted] illustrate the range and variety of control activities that may be useful to management.
The list is not all inclusive and may not include all categories of control activities that an entity may need.
(ADD TABLE)
10.3 Design of Automated and Manual Control Activities
10.05
Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.
10.06
Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.
10.07
Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.
10.08
General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.
10.09
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.

10.4 Design of Preventive and Detective Control Activities
10.10
Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.
10.11
Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.
10.12
Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.
10.13
There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.
10.5 Design of Control Activities at Various Levels
10.14
Management designs control activities at the appropriate levels in the organizational structure.
10.15
Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.
10.16
Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.
10.17
Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.
10.18
When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.
Information processing objectives may include the following:
- Completeness - All transactions and events that occur have been properly recorded.
- Accuracy - Data relating to transactions and events are properly and timely recorded.
- Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.
10.19
While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.
10.20
When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:
- Level of aggregation - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.
- Consistency and timing of performance - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.
- Correlation to relevant business processes - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.
10.6 Segregation of Duties
10.21
Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.
10.22
Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.
10.23
If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.
Assessment Observations Compared to Green Book Components, Principles, & Attributes
Control Environment
Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.
- Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
- Principle 2 - Exercise Oversight Responsibility
- Principle 3 - Establish Structure, Responsibility, and Authority
- Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
- Principle 4 - Demonstrate Commitment to Competence
- Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
- Principle 5 - Enforce Accountability
- Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment
Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.
- Principle 6 - Define Objectives and Risk Tolerances
- Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
- Principle 7 - Identify, Analyze, and Respond to Risks
- Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
- Principle 8 - Assess Fraud, Improper Payment, and Information
- Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
- Principle 9 - Identify, Analyze, and Respond to Change
- Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities
Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.
- Principle 10 - Design Control Activities
- Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
- Principle 11 - Design General Control Activities over Information
- Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
- Principle 12 - Implement Control Activities
- Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication
Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.
- Principle 13 - Use Quality Information
- Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
- Principle 14 - Communicate Internally
- Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
- Principle 15 - Communicate Externally
- Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring
Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.
- Principle 16 - Perform Monitoring Activities
- Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
- Principle 17 - Evaluate Issues and Remediate Deficiencies
- Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)
