What Is Internal Audit Testing?

What Is Internal Audit Testing?

A control can look sensible on paper and still fail every time real work moves through it. Approvals may be rushed, reconciliations may be skipped, access may remain open after an employee changes roles, or evidence may exist without proving that anyone reviewed it.

Internal audit testing turns those assumptions into evidence. It gives auditors a structured way to determine whether controls address the right risks, operate as intended, and produce reliable records that management can use.

This article explains the major types of audit tests, how to plan and perform a test of controls, how sampling and evidence support a conclusion, and what to do when a test identifies an exception.

What Is Internal Audit Testing?

Internal audit testing is the systematic use of audit procedures to collect and evaluate evidence about a process, risk, transaction, or control. The auditor compares what should happen with what actually happened, then reaches a supported conclusion about design, operation, compliance, or accuracy.

Testing can cover operational, financial, compliance, technology, quality, and governance objectives. When the subject is financial internal controls, the work often examines authorization, completeness, accuracy, segregation of duties, access, reconciliation, review, and record retention.

Design Effectiveness

A design test asks whether the control, if performed as described, is capable of reducing the identified risk to an acceptable level. The auditor reviews the control objective, responsible role, frequency, evidence, escalation path, and relationship to other controls.

A control may be poorly designed even when employees follow it consistently. For example, a monthly review performed by someone who cannot see the full transaction population may not detect the errors it was created to prevent.

Operating Effectiveness

An operating-effectiveness test asks whether the control was performed by the right person, at the required frequency, throughout the period, with sufficient precision and follow-up. The conclusion depends on evidence, not a statement that the control is usually performed.

Audit Evidence

Evidence must be relevant to the test objective and reliable enough to support the conclusion. The AICPA overview of audit evidence emphasizes evaluating information produced by audit procedures to determine whether sufficient appropriate evidence has been obtained.

What Types of Audit Tests Do Internal Auditors Use?

Auditors select procedures according to the objective, risk, control type, available evidence, and reliability needed. A strong program combines methods because no single procedure proves every aspect of a control.

Internal controls testing dashboard with checklist, sampling table, and exception indicators

Inquiry

Inquiry asks employees and managers to explain the process, control, exceptions, and evidence. It is useful for understanding responsibilities and identifying changes, but inquiry alone is rarely sufficient because a description does not prove performance.

Observation

Observation allows the auditor to watch a control being performed. It can reveal workarounds, unclear responsibilities, physical safeguards, and differences between written procedures and actual behavior. Its limitation is timing: people may behave differently while being observed.

Inspection

Inspection examines documents, system records, approvals, reconciliations, logs, contracts, reports, and other evidence. The auditor should verify that the record relates to the selected item, shows the required action, and was created at the proper time.

Reperformance and Recalculation

Reperformance independently executes the control or part of the process. Recalculation checks mathematical accuracy. These methods often provide stronger evidence because the auditor directly tests whether the expected result can be reproduced.

Data Analysis and Confirmation

Data analysis can scan an entire population for duplicates, gaps, unusual timing, unauthorized values, or other exceptions. Confirmation obtains evidence from an independent party. Both methods can strengthen testing when system data and external information are reliable.

Control Tests and Substantive Tests

A test of controls evaluates whether a control is designed and operating effectively. A substantive test examines transactions, balances, or other outcomes for errors or misstatements. Auditors may use both: control results shape how much direct testing of the underlying activity is needed.

Compliance and Performance Tests

A compliance test compares activity with a law, policy, contract, standard, or approved procedure. A performance test asks whether the process achieves its intended operational result, such as timely service, accurate reporting, controlled cost, or reduced error. The same evidence may inform both questions, but the criteria and conclusions should remain distinct.

How Do You Plan Internal Audit Testing?

Planning starts with risk, not with a generic list of procedures. The auditor needs a clear objective, defined scope, dependable population, relevant criteria, and a direct connection between each risk, control, procedure, and expected evidence.

Define the Objective and Scope

State what the test must determine and which period, location, system, process, and population it covers. A narrow objective such as verifying timely approval of vendor changes produces clearer evidence than a vague instruction to review purchasing controls.

Connect Risks to Controls

Identify the failure the control is intended to prevent or detect. Then determine whether the mix of preventive, detective, corrective, and other types of internal controls addresses that risk. The COSO internal control framework can help place individual activities within the wider control environment, risk assessment, information, monitoring, and control structure.

Select the Population and Sample

Confirm that the population is complete, accurate, and aligned with the period under review. Choose a sample that reflects control frequency, risk, expected deviation, prior findings, and the degree of reliance planned. Document how items were selected so another reviewer can understand the method.

Sampling does not always mean selecting a fixed number of records. An auditor may use random, systematic, stratified, judgmental, or targeted selections. High-value items, unusual transactions, new employees, manual overrides, and periods of organizational change may deserve specific coverage in addition to a representative sample.

Use a Risk-Based Approach

Higher-risk areas generally need more persuasive evidence, broader coverage, or more frequent testing. The SEC staff guidance on internal control reporting explains that testing should focus on areas most likely to have a material impact and that the nature, timing, and extent of work should reflect risk.

How Do You Perform a Test of Controls?

Each test should identify the control, expected result, procedure, evidence, sample, exception criteria, and conclusion. The workpaper should make the logic visible without requiring the reviewer to reconstruct the audit from scattered notes.

Internal auditor reviewing evidence and exceptions on a control testing dashboard

Step 1: Perform a Walkthrough

Trace one transaction or activity from initiation through completion. Ask the process owner to show the records, decisions, systems, and handoffs. Compare the walkthrough with the documented procedure and investigate differences before finalizing the test.

Step 2: Inspect the Selected Evidence

For every sampled item, verify the attributes that matter. Testing cash security controls, for example, may require evidence of restricted access, independent counts, deposit timeliness, reconciliation, exception review, and management approval.

Step 3: Record Exceptions Precisely

Document the item, expected condition, actual condition, evidence source, date, responsible role, and initial explanation. Avoid labels such as failed or weak without facts. A precise exception supports follow-up and helps distinguish an isolated error from a broader control problem.

Keep the original evidence or a controlled reference to its location when permitted. Screenshots, exports, and copied records should retain enough context to show the source, period, and selected item. Sensitive information should be protected according to access and retention requirements.

Step 4: Expand or Redirect Testing When Needed

An unexpected exception may require a larger sample, a different period, another location, or a related control test. The reason for changing scope should be documented. Expanding testing should answer a defined question, not merely produce more paperwork.

How Do You Evaluate and Report Test Results?

The final conclusion should answer the test objective and reflect the quality of evidence obtained. Counting exceptions is not enough. The auditor considers their nature, frequency, cause, impact, relationship to other controls, and whether compensating controls reduce the remaining risk.

Evaluate the Pattern

One missing approval may be isolated, or it may reveal that approvals are routinely completed after the transaction. Compare exceptions across people, locations, dates, systems, and transaction types. Repeated or concentrated failures often point to a design, training, access, supervision, or data-quality issue.

Write a Supported Conclusion

State whether the control is designed effectively, operating effectively, partially effective, or ineffective under the audit criteria. Explain the evidence and limitations. If the population was incomplete or access was restricted, describe how that limitation affects assurance.

A supported conclusion also distinguishes the tested period from future performance. A control that worked during the sample period can later deteriorate because of staff turnover, system changes, volume growth, or management override. Ongoing monitoring and scheduled retesting help management detect that change.

Assign and Verify Corrective Action

Management owns the control and the response. That principle aligns with management’s responsibility for internal controls. Internal audit should evaluate whether the planned action addresses the cause and risk, then verify implementation and effectiveness before closing the finding.

What Internal Audit Testing Mistakes Should You Avoid?

Relying on Inquiry Alone

Interviews explain the process but do not prove operation. Corroborate important statements with inspection, observation, reperformance, system data, or another reliable source.

Testing Evidence Without Testing the Control

A signature or status mark may show that someone touched a record, but not that the review was timely or precise enough to detect an error. Test the attributes that make the control effective, not merely the presence of a document.

Using an Unverified Population

A perfect sample from an incomplete population produces false confidence. Reconcile the source data, confirm filters and dates, and understand system-generated fields before selecting items.

Treating Every Exception the Same

Exceptions differ in cause, likelihood, impact, and reach. Evaluate whether each one is isolated, systematic, intentional, repeated, or offset by another control. Escalation should reflect risk, not just a count.

Effective internal audit testing connects risk, controls, procedures, evidence, conclusions, and corrective action. When that chain is visible, management can rely on the work to strengthen governance instead of treating the audit as a compliance exercise.

Frequently Asked Questions

What Is the Main Purpose of Internal Audit Testing?

The main purpose is to obtain evidence about whether a process, transaction, or control is designed appropriately and operates as intended. Testing allows the auditor to replace assumptions with a supported conclusion.

What Are the Most Common Types of Audit Tests?

Common methods include inquiry, observation, inspection, reperformance, recalculation, confirmation, and data analysis. Auditors combine methods according to the test objective, risk, control type, and reliability of available evidence.

What Is the Difference Between a Test of Controls and a Substantive Test?

A test of controls evaluates whether a control is designed and operating effectively. A substantive test directly examines transactions, balances, or outcomes for errors, misstatements, or other exceptions.

How Large Should an Internal Audit Sample Be?

Sample size depends on control frequency, population size, risk, expected deviation, prior results, and the assurance needed. The auditor should document why the selected size and method are appropriate for the objective.

What Happens When an Internal Audit Test Finds an Exception?

The auditor documents the facts, evaluates the cause and risk, and determines whether more testing is needed. Management then owns the corrective response, while internal audit verifies that the action was implemented and works.

Discover Dash

Best Manual Deals