These notes provide a comprehensive, exam‑focused guide to AUI3702: The Internal Audit Process with a particular emphasis on tests of controls, aligned to the expectations of UNISA (University of South Africa) students in Accounting, Auditing and related qualifications. Concepts and approaches are also applicable for similar internal auditing and assurance modules at South African universities such as CUT (Central University of Technology) and others.
1. Overview of the Internal Audit Process and Tests of Controls
1.1 Positioning AUI3702 within UNISA’s Auditing Curriculum
AUI3702 at UNISA forms part of the intermediate to advanced auditing stream in Accounting and Auditing degrees and diplomas (for example, BCom in Internal Auditing, BCompt, and various UNISA College of Accounting Sciences programmes). The module builds on introductory internal audit topics and focuses on:
- The internal audit process as a structured, professional methodology.
- How internal auditors obtain assurance on internal controls.
- How to plan, design, perform, and evaluate tests of controls.
- How to integrate test‑of‑controls results into audit conclusions and reporting.
Within the South African context, the module aligns with frameworks and standards such as:
- International Standards for the Professional Practice of Internal Auditing (IPPF) issued by The IIA.
- COSO Internal Control – Integrated Framework.
- Relevant King IV™ Report on Corporate Governance for South Africa principles.
- ISA 315 and ISA 330 for comparison with external audit approaches (though AUI3702 is internal-audit focused).
1.2 The Internal Audit Process in High‑Level Phases
Across UNISA and CUT auditing syllabi, the internal audit process is usually taught as a cycle with distinct but interrelated phases:
- Engagement Planning
- Understanding the business and its risks.
- Defining engagement objectives and scope.
- Developing the engagement work programme (including planned tests of controls).
- Fieldwork / Execution
- Performing tests of controls and, where relevant, substantive procedures.
- Collecting and documenting audit evidence.
- Evaluating control design and operating effectiveness.
- Evaluation & Conclusion
- Assessing whether controls are adequate and effective.
- Forming an opinion or conclusion regarding objectives and risks.
- Reporting
- Communicating findings, recommendations, and management action plans.
- Grading residual risk or control ratings (e.g., satisfactory, needs improvement).
- Follow‑up
- Monitoring implementation of management’s corrective actions.
- Re‑testing controls as needed.
- Updating risk assessments in the internal audit plan.
Throughout all phases, internal auditors must adhere to professional standards regarding independence, objectivity, competence, and due professional care.
1.3 Definitions: Internal Control and Tests of Controls
To answer AUI3702 exam questions effectively, definitions must be clear, concise and accurate.
Internal control (based on COSO and IPPF context) is:
A process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.
Key aspects for exams:
- It is a process, not a single event.
- It is effected by people, not just policies and systems.
- It aims for reasonable, not absolute, assurance.
- It addresses operations, reporting and compliance.
Tests of controls are:
Procedures performed by the internal auditor to obtain evidence about the design and operating effectiveness of internal controls in preventing, or detecting and correcting, material misstatements, errors, or irregularities.
In a UNISA AUI3702 context, tests of controls:
- Focus on how controls are designed and whether they operate as intended.
- Are used to evaluate the control environment and specific control activities.
- Are distinct from substantive procedures, which aim primarily to verify account balances, classes of transactions, and disclosures.
1.4 Why Tests of Controls Matter in AUI3702 and in Practice
For internal auditors (and students preparing for exams):
-
Risk-based assurance
Effective tests of controls allow internal auditors to:- Identify weaknesses that increase risk.
- Confirm where controls reduce residual risk to acceptable levels.
- Advise the audit committee and management on areas needing improvement.
-
Efficiency of internal audit work
- Where controls are strong and effective, internal auditors can:
- Place more reliance on the control system.
- Perform targeted substantive work rather than 100% substantive testing.
- This is especially relevant in resource‑constrained environments common in the public sector and at South African SOEs.
- Where controls are strong and effective, internal auditors can:
-
Compliance, fraud prevention and governance
- Thorough tests of controls support:
- King IV™ principles on adequate and effective internal control.
- PFMA and MFMA requirements in public entities.
- Fraud prevention strategies (e.g., segregation of duties, authorisation controls, monitoring).
- Thorough tests of controls support:
-
Exam success in AUI3702
- Many exam questions at UNISA require:
- Identifying relevant controls for a given business process.
- Designing and describing appropriate tests of controls.
- Discussing results and implications for audit conclusions or further testing.
- Many exam questions at UNISA require:
Mastery of tests of controls is therefore central to both academic performance and professional internal audit practice.
2. Internal Control Frameworks and Types of Controls
AUI3702 exam questions often test theoretical understanding of internal control frameworks, especially COSO, and expect students to apply this knowledge when designing tests of controls over typical business cycles (e.g., revenue, procurement, payroll).
2.1 COSO Internal Control – Integrated Framework: Components
The COSO framework structures internal control into five interrelated components. Knowing each component and typical controls is essential.
-
Control Environment
- “Tone at the top”; the foundation of internal control.
- Includes:
- Integrity and ethical values.
- Commitment to competence.
- Board of directors and audit committee oversight.
- Organisational structure and assignment of authority.
- Human resource policies and practices.
- Example controls:
- Formal code of conduct and ethics training.
- Disciplinary procedures for ethics violations.
- Independent audit committee that regularly reviews internal audit reports.
-
Risk Assessment
- Identification and analysis of relevant risks to achieving objectives.
- Includes:
- Establishing clear objectives (operations, reporting, compliance).
- Identifying and analysing risks such as fraud, IT breakdown, compliance failure.
- Considering changes in the environment, organisation and systems.
- Example controls:
- Regular enterprise risk assessments with documented risk registers.
- Formal fraud risk assessment process.
- Management workshops to assess risk likelihood and impact.
-
Control Activities
- Policies and procedures that help ensure management directives are carried out.
- Categories:
- Authorisation and approval controls.
- Segregation of duties.
- Physical controls (safeguarding assets).
- IT general controls and application controls.
- Reconciliations and reviews.
- Example controls:
- Purchase orders must be approved by an authorised manager before ordering goods.
- System‑enforced segregation between creation and approval of vendor master records.
-
Information and Communication
- Systems that capture and communicate information needed to manage and control operations.
- Includes:
- Accounting systems, ERP systems, management reports.
- Internal communication (policies, procedures, performance reports).
- External communication (regulators, shareholders, customers).
- Example controls:
- Monthly management accounts distributed to cost centre managers.
- Automatic exception reports for unusual transactions.
-
Monitoring Activities
- Ongoing and separate evaluations of control performance over time.
- Includes:
- Management reviews and supervision.
- Internal audit function activities.
- Follow‑up on exceptions and audit findings.
- Example controls:
- Quarterly internal audit reviews focused on high‑risk processes.
- Formal process for tracking implementation of audit recommendations.
In AUI3702, students must be able to:
- Identify which COSO component a control belongs to.
- Explain how that control mitigates a specific risk.
- Design a test of control suited to that component (e.g., inquiry, re-performance, inspection).
2.2 Types of Controls: Preventive, Detective, Corrective and Directive
Understanding control objectives and types is crucial when deciding what tests to perform.
-
Preventive Controls
- Aim: Prevent errors or irregularities before they occur.
- Examples:
- System validation checks (e.g., cannot process a sale without a valid customer code).
- Segregation of duties between capturing, authorising and recording transactions.
- Pre‑approval limits for purchase requisitions.
- Impact on testing:
- Testing preventive controls often requires assessing design (are they properly set up?) and operation (do they consistently prevent errors?).
-
Detective Controls
- Aim: Detect errors or irregularities after they have occurred.
- Examples:
- Bank reconciliations.
- Exception reports (e.g., negative inventory balances).
- Internal audit reviews and surprise cash counts.
- Impact on testing:
- The internal auditor evaluates timeliness and completeness of detective controls and whether identified variances are investigated and resolved.
-
Corrective Controls
- Aim: Correct identified problems and prevent recurrence.
- Examples:
- Procedures to correct master data errors identified during detective reviews.
- Disciplinary actions for policy violations, combined with retraining.
- Impact on testing:
- Internal auditors evaluate whether remedial actions are actually implemented and if they are effective.
-
Directive Controls
- Aim: Provide guidance on desired behaviour to facilitate achieving objectives.
- Examples:
- Policy manuals, standard operating procedures, and job descriptions.
- Formal training programmes.
- Impact on testing:
- Internal auditors inspect documentation and assess awareness and understanding among staff through inquiry and observation.
Exam questions may ask students to:
- Classify given controls as preventive, detective, corrective or directive.
- Propose additional controls to strengthen a process, specifying which category they fall into.
- Design suitable tests of controls for different control types (e.g., testing a detective control via re-performance of reconciliations).
2.3 Entity-Level vs Process-Level Controls
In AUI3702, it is important to distinguish between:
-
Entity-level controls
High‑level controls that have a pervasive effect on the organisation’s internal control system.- Examples:
- Governance structures (board and audit committee).
- Enterprise‑wide risk management processes.
- Corporate policies (e.g., anti‑fraud policy, IT security policy).
- Organisation‑wide performance review processes.
- Impact:
- Strong entity‑level controls can reduce residual risk across multiple processes.
- Weak entity‑level controls can undermine otherwise strong process-level controls.
- Examples:
-
Process-level / Activity-level controls
Controls within specific business processes or cycles, such as:- Revenue and receivables.
- Procurement and payables.
- Inventory management.
- Payroll and HR.
- Fixed assets.
- Treasury and cash management.
For exams, students must:
- Identify controls at both levels in given case studies (e.g., UNISA-style scenario questions).
- Explain how entity-level control weaknesses (such as a weak “tone at the top”) can lead to process-level control failures.
- Design tests of controls appropriate to the level (e.g., board minutes review for entity-level; sample-based invoice review for process-level).
2.4 Control Objectives and Assertions Relevant to Tests of Controls
When planning tests of controls, internal auditors articulate control objectives that align with:
- Financial reporting assertions often used in external audit (existence, completeness, accuracy, valuation, rights & obligations, presentation & disclosure).
- Operational objectives (efficiency, effectiveness, safeguarding assets).
- Compliance objectives (adherence to laws, regulations, internal policies).
Example: Procurement and Payables Cycle
Common control objectives include:
- All goods and services purchased are authorised and necessary.
- Purchases are properly recorded in the accounting records in the correct period.
- Liabilities are complete and accurate.
- Company assets (e.g., inventory) are safeguarded against loss or theft.
- Procurement complies with company policy and, for public entities, PFMA/MFMA and SCM regulations.
Internal auditors then identify specific controls that address each objective and design tests of controls to verify that these controls function as intended.
3. Planning Tests of Controls in the Internal Audit Process
Planning is heavily examined in AUI3702, especially the linkage between risk assessment, control design, and testing strategy. Efficient, risk‑based planning ensures the internal audit function provides maximum assurance with available resources.
3.1 Engagement-Level Risk Assessment and Planning
Before designing tests of controls, the internal auditor performs an engagement‑level risk assessment.
Key steps:
-
Understand the audited area
- Review prior internal and external audit reports.
- Study process documentation, policies, and procedures.
- Understand the IT systems and data flows involved.
- Perform preliminary interviews with key personnel.
-
Identify risks
- Operational risks (e.g., stock‑outs, production delays).
- Financial reporting risks (e.g., misstatements in revenue or expenses).
- Compliance risks (e.g., breaches of environmental or labour laws).
- Fraud risks (e.g., procurement fraud, payroll “ghost employees”).
-
Assess inherent risk
- Consider complexity of transactions.
- Volume and value of transactions.
- Susceptibility to fraud or error.
- Use of judgement or estimation.
-
Understand existing controls
- Map the process and identify control points.
- Classify controls (preventive/detective/etc., manual/automated).
- Determine whether controls are key or non‑key (key controls directly address significant risks).
-
Assess control risk
- Initial assessment based on design (before testing operation).
- Decide how much assurance is needed from tests of controls.
- Determine whether substantive testing will also be required for certain objectives.
-
Define engagement objectives and scope
- Example: “To evaluate the adequacy and effectiveness of controls over the revenue cycle for the financial year ended 31 December 20X5, focusing on completeness and accuracy of recorded revenue and compliance with credit policies.”
-
Develop an audit programme
- List specific tests of controls to be performed.
- Allocate responsibilities, timing, and sample sizes.
- Consider reliance on ITGCs and application controls.
In an AUI3702 exam context, students may be required to draft a short audit programme for a specific cycle, showing clear linkage from risk to control to test.
3.2 Selecting Controls to Test (Key Controls vs Non‑Key Controls)
Given limited internal audit resources, not all controls can be tested. Internal auditors must identify key controls that:
- Directly address significant risks.
- Are necessary for the control system to function effectively.
- If they fail, material misstatement or serious operational/compliance failure could result.
Non‑key controls:
- Provide additional comfort but are not critical for mitigating the highest risks.
- May be omitted from detailed testing, especially if key controls are robust.
Example – Payroll Process:
-
Key controls might include:
- Authorisation of new employees and changes to pay rates (to mitigate risk of “ghost employees” or unauthorised pay changes).
- Segregation between HR, payroll processing, and payment authorisation.
- Monthly reconciliation of payroll listing to GL and bank payments.
-
Non‑key controls might include:
- Weekly distribution of payslips via email (supporting communication but not a primary risk mitigator).
AUI3702 exams often require students to:
- Identify which controls are key in a given scenario.
- Justify why those controls warrant detailed testing.
- Propose specific tests of controls for the selected key controls.
3.3 Designing Tests of Controls: Nature, Timing and Extent
Nature of tests of controls
Common types (which often appear in exam questions):
-
Inquiry
- Asking staff how a process or control is performed.
- Often combined with other procedures; alone, inquiry is rarely sufficient.
-
Observation
- Watching a process being performed (e.g., stock counts, approval workflow).
- Limited in that it only provides evidence for the time of observation.
-
Inspection of documentation
- Examining documents for signatures, stamps, or evidence of review.
- Checking whether policies and procedures are updated and approved.
-
Re-performance
- Independently executing the control to assess whether it operates correctly (e.g., recalculating a payroll run, re‑performing a bank reconciliation).
-
Computer‑assisted audit techniques (CAATs)
- Using data analysis tools (e.g., ACL, IDEA, Excel) to test the operation of automated controls or detect anomalies.
Timing of tests
-
Interim testing (e.g., mid‑year):
- Suitable for controls that operate consistently throughout the year.
- Requires roll‑forward procedures if the internal auditor plans to rely on controls for the full period.
-
Year‑end testing:
- Appropriate when risks are highest at year‑end (e.g., cut‑off, valuation of inventory).
- Often used for controls directly affecting year‑end reporting.
Extent of testing
-
Determined by factors such as:
- Desired level of assurance.
- Frequency of the control (daily, weekly, monthly, annual).
- Expected deviation rate (how often the control might fail).
- Population size and materiality.
-
For manually operated controls:
- Larger sample sizes are typically needed.
- If a weekly control is key, the population might be ~52 occurrences per year; the internal auditor might select a sample of, for example, 8–15 items, depending on risk and methodology.
-
For automated controls:
- If the internal auditor confirms appropriate system development and change controls, fewer items may be tested (sometimes “one test” per control plus design evaluation, depending on methodology and reliance on ITGCs).
In exams, internal auditing students are not expected to calculate statistically precise sample sizes, but they should:
- Show awareness of factors affecting extent of tests.
- Indicate reasonable sample sizes in test descriptions (e.g., “Select a sample of 20 purchase orders from the financial year and inspect…”).
3.4 Documenting Planned Tests of Controls
Proper documentation is emphasised by both the IPPF and UNISA study material.
A typical test of control description in an internal audit working paper includes:
- Objective of the test: What risk/control objective is being tested?
- Control description: What is the control and who performs it?
- Procedure: Step‑by‑step actions the internal auditor will take.
- Population and sample: What is the population, and how many items will be tested?
- Expected evidence: What evidence indicates that the control is operating?
- Conclusion criteria: How will the internal auditor interpret deviations?
Example (Procurement approvals):
- Objective: To determine whether purchase orders above R50,000 are properly authorised in accordance with the delegation of authority policy.
- Control description: All purchase orders > R50,000 must be approved electronically by the Procurement Manager and the Finance Manager.
- Procedure:
- Obtain a report of all purchase orders > R50,000 for the period 1 January to 31 December 20X5.
- Select a sample of 25 purchase orders using random sampling.
- For each sampled PO, inspect the system approval history to confirm that both the Procurement Manager and Finance Manager approved the order before issue.
- Expected evidence: Evidence of electronic approval by both required roles, dated prior to order issuance.
- Conclusion criteria: If more than one deviation is identified, reassess reliance on this control and consider extended sample testing.
In AUI3702 exams, full working paper‑style detail is not always required, but clear, structured descriptions similar to the above are highly regarded and can earn high marks.
4. Performing Tests of Controls: Techniques, Evidence and Evaluation
Once planning is completed, the internal auditor proceeds to execute tests of controls. This phase focuses on applying the selected techniques consistently, obtaining sufficient appropriate evidence, and evaluating the results against control objectives.
4.1 Sources and Quality of Audit Evidence
The IPPF and common internal audit guidance define audit evidence as the information used by the internal auditor to reach conclusions on which the engagement results are based.
Key characteristics:
- Sufficient – enough quantity to support conclusions.
- Appropriate – relevant and reliable.
Sources of evidence:
- Internal documentation (invoices, purchase orders, reconciliations, policy documents).
- External documentation (bank statements, customer confirmations, supplier statements).
- Written and oral representations (management assertions, staff explanations).
- Physical evidence (observation of assets, stock counts).
- Electronic data and logs (system reports, access logs).
Evidence reliability ranking (generally, from most to least reliable):
- External evidence obtained directly, e.g., confirmation letters.
- Internally generated evidence where controls over its preparation are strong.
- Oral representations and inquiry (usually require corroboration).
In AUI3702, students should be able to:
- Discuss what constitutes appropriate evidence for different controls.
- Explain the need for corroborating inquiry with other procedures.
4.2 Applying Test Techniques: Practical Examples
4.2.1 Inquiry and Observation
Use inquiry to understand how controls are supposed to work and observation to confirm actual practice.
Example – Cash Handling at Retail Store:
- Control: Daily cash counts are performed by the cashier and independently reviewed by the supervisor; discrepancies are investigated.
- Test of control:
- Inquire from the cashier and supervisor about procedures followed at end of day.
- Observe a cash count at closing time:
- Ensure the cashier counts the cash drawer.
- Confirm the supervisor independently recounts or verifies.
- Note whether variances are recorded and explained.
Evaluation:
- If observation confirms procedures are followed and no discrepancies are left unexplained, the control appears to be operating effectively (subject to corroborative tests on other days via documentation).
4.2.2 Inspection of Documentation
This is a core technique in tests of controls, particularly for manual approvals and reconciliations.
Example – Credit Note Authorisation:
- Control: All customer credit notes must be approved by the Credit Manager.
- Test of control:
- Select a sample of credit notes during the period under review.
- Inspect each for evidence of Credit Manager approval (signature/electronic stamp).
- Confirm approval date precedes posting of the credit note.
Evaluation:
- Deviations (e.g., missing or post‑dated approvals) may indicate control failure.
- Impact depends on severity and frequency of deviations.
4.2.3 Re-performance
Re-performance is highly persuasive as it allows the internal auditor to independently trigger the control process and verify its effectiveness.
Example – Bank Reconciliation Review:
- Control: The Financial Accountant prepares a monthly bank reconciliation; the Finance Manager reviews and signs off.
- Test of control:
- Obtain the bank reconciliation for a selected month.
- Re-perform the reconciliation:
- Agree bank statement balance to GL.
- Test the accuracy of reconciling items.
- Confirm that the Finance Manager has signed and dated the reconciliation.
- Inspect evidence of follow‑up on long outstanding reconciling items.
Evaluation:
- If reconciliation is accurate and reviewed monthly, the control is effective.
- Errors, missing sign‑offs, or unresolved reconciling items indicate possible control deficiencies.
4.2.4 CAATs and Data Analytics
UNISA and CUT syllabi increasingly highlight CAATs as part of modern internal audit practice.
Example – Automated Three‑Way Match in Accounts Payable:
- Control: System automatically matches purchase orders, goods received notes (GRNs) and supplier invoices before posting; mismatches are blocked and routed for investigation.
- Test of control:
- Perform walkthrough to understand system configuration.
- Using CAATs, extract a dataset of all purchase orders, GRNs and invoices.
- Identify any posted invoices without matching PO or GRN.
- Investigate any exceptions (if system allowed them, control might not be effective).
Evaluation:
- If no exceptions exist, and ITGCs are reliable, the internal auditor can place strong reliance on this automated control.
- If exceptions appear, the internal auditor may need to expand testing and question the reliability of the system configuration.
4.3 Sampling in Tests of Controls
Although AUI3702 does not require deep statistical sampling calculations, students must understand:
- Why sampling is used: time and cost constraints, large populations.
- Sampling risk: risk that the sample is not representative, leading to incorrect conclusions.
- Non‑sampling risk: errors in test application, misinterpretation of results.
Types of sampling (in exam‑relevant terms):
- Judgemental (non‑statistical) sampling:
- Based on auditor judgement (e.g., high‑value items, high‑risk months).
- Common in internal audit practice.
- Random sampling:
- Each item has an equal chance of being selected.
- Reduces selection bias.
- Systematic sampling:
- Selecting every nth item after a random start.
- Haphazard sampling:
- Non‑structured selection, avoiding known patterns, but still prone to bias.
In a test of controls answer, students should:
- State an appropriate sampling approach.
- Indicate that sample size increases with risk and decreases when control environment is strong or when automation is high (subject to good ITGCs).
4.4 Evaluating Deviations and Control Effectiveness
During tests of controls:
- A deviation occurs when a control is not performed as designed (e.g., missing approval, late reconciliation).
Internal auditors must:
-
Quantify deviations
- Number of deviations vs sample size (e.g., 3 deviations in 25 items).
- Nature (e.g., critical, moderate, minor).
-
Assess cause and impact
- Cause: Staff negligence, inadequate training, system errors, management override.
- Impact:
- Potential financial misstatement.
- Increased fraud risk.
- Operational inefficiencies.
-
Decide on further actions
- Extend sample testing if deviations are frequent.
- Test compensating controls (other controls that may mitigate the risk).
- Increase substantive procedures (e.g., extended substantive testing of account balances).
-
Rate control effectiveness
- Effective: low or no deviations, deviations are not systematic or high risk.
- Partially effective: some deviations indicating weaknesses but overall functioning.
- Ineffective: frequent or severe deviations undermining control objectives.
AUI3702 exam questions often expect students to explain what they would conclude and what additional steps they would take if deviations are found.
5. Integrating Test of Control Results into Conclusions, Reporting and Exam Application
The final phase in the internal audit process is to integrate the results of tests of controls into overall conclusions, reports, and recommendations. In the AUI3702 exam, students are frequently asked to analyse a scenario and recommend findings, ratings and remedial actions.
5.1 Forming Conclusions from Tests of Controls
Internal auditors synthesise evidence from multiple tests and form conclusions regarding:
- Design effectiveness – Are controls suitably designed to achieve objectives?
- Operating effectiveness – Have controls operated as designed throughout the period?
Steps:
-
Summarise test results
- For each key control, summarise:
- Nature of the test.
- Sample size.
- Results (number and nature of deviations).
- For each key control, summarise:
-
Assess against control objectives
- Example: In the revenue cycle, objectives might include completeness and accuracy of recorded revenue, proper authorisation of credit limits, and approval of price overrides.
-
Determine residual risk
- If controls are effective: residual risk may be low and acceptable.
- If partially effective or ineffective: residual risk may be medium or high, requiring management attention.
-
Consider compensating controls
- Sometimes, weaknesses in one control are mitigated by other controls (e.g., strong monthly management reviews compensating for weaker transaction‑level checks).
-
Form overall engagement opinion
- Internal audit functions often use scales such as:
- Satisfactory / Effective.
- Needs Improvement / Partially Effective.
- Unsatisfactory / Ineffective.
- Opinion relates to the overall control environment within the audited process or function.
- Internal audit functions often use scales such as:
In exam answers, students should use clear phrases like:
- “Based on the tests of controls performed, it appears that controls over [process] are generally effective in mitigating risks relating to [objective], although some weaknesses were noted in [specific area].”
5.2 Reporting Findings and Recommendations
Internal audit reports, as covered in AUI3702, typically include:
- Executive summary:
- Overall opinion.
- Main findings and residual risks.
- Detailed findings:
- Background/context.
- Criteria (what should be – policy, law, best practice).
- Condition (what is – test of control results).
- Cause (why the problem exists).
- Effect (actual or potential consequences).
- Recommendation.
- Management response and action plan.
Example Finding – Inadequate Review of Supplier Reconciliations:
- Criteria:
- The Supply Chain Management Policy requires that supplier reconciliations are prepared monthly and reviewed by the Finance Manager.
- Condition:
- Based on a test of controls over 12 months, reconciliations were prepared in 10 months but the Finance Manager’s review sign‑off was evident in only 5 of those months.
- Cause:
- Finance Manager indicated workload pressure and absence during certain months; no delegated backup reviewer appointed.
- Effect:
- Increased risk that errors or unauthorised balances on supplier accounts may not be timely identified, potentially resulting in overpayments or disputes.
- Recommendation:
- Ensure that supplier reconciliations are reviewed and signed off monthly. In the Finance Manager’s absence, a suitably qualified deputy should be formally assigned to perform the review.
- Management response:
- Management agrees with the recommendation and commits to implementing a deputy reviewer system by 30 June 20X6.
In exam scenarios, even a shortened version of this criteria‑condition‑cause‑effect‑recommendation structure can gain high marks.
5.3 Follow‑up and Continuous Improvement
Internal audit standards require that auditors perform follow‑up to evaluate whether management’s corrective actions have been effectively implemented.
Activities:
- Tracking agreed actions and deadlines.
- Requesting evidence of implementation (e.g., updated policies, evidence of new controls running).
- Re‑testing controls where necessary.
- Updating risk assessments and audit plans based on new control status.
In AUI3702 context:
- Students should emphasise that tests of controls are not one‑off; they feed into a continuous cycle of improvement.
- Exam questions may ask how the internal audit function ensures that identified control weaknesses are sustainably resolved.
5.4 Example: Applying Test of Control Concepts to a Revenue Cycle Case Study
To consolidate exam‑relevant understanding, consider a simplified case similar to those often found in UNISA’s AUI3702 exams.
Scenario summary
- Entity: A medium‑sized retail company operating multiple branches in South Africa.
- Process under review: Revenue and Receivables Cycle.
- Key risks:
- Sales may be recorded without delivery of goods (fictitious sales).
- Sales may be understated or omitted (incomplete revenue).
- Cash collected may not be completely recorded (misappropriation of cash).
- Credit sales may be made to customers who exceed credit limits (bad debt risk).
Key controls and possible tests:
-
Segregation of duties
- Control:
- Sales staff capture orders but cannot approve credit.
- Credit department approves new customers and credit limit changes.
- Finance department records receipts and performs bank reconciliations.
- Test of control:
- Inspect system access profiles to confirm that sales staff do not have access to credit limit fields.
- Select a sample of credit limit changes and inspect evidence of credit department approval.
- Evidence:
- System access logs, approval logs, role descriptions.
- Control:
-
Credit approval process
- Control:
- New customer accounts and credit limits must be approved by the Credit Manager based on credit checks.
- Test of control:
- Select a sample of new customers created during the year.
- Inspect credit application forms, credit check documentation, and evidence of Credit Manager approval.
- Evidence:
- Approved application forms, signed-off credit checking documents.
- Control:
-
Three-way match and invoice generation
- Control:
- For credit sales, invoices are generated only after matching approved sales orders to dispatch notes indicating goods delivered.
- Test of control:
- Select a sample of invoices and trace each to:
- An authorised sales order.
- A dispatch note signed by the customer or courier.
- Confirm system settings prevent invoice generation without a valid dispatch note.
- Select a sample of invoices and trace each to:
- Evidence:
- Signed dispatch notes, sales orders, system configuration reports.
- Control:
-
Cash collection and banking
- Control:
- Daily cash takings recorded at each branch must be reconciled to cash counted and deposited the next business day; variances investigated.
- Test of control:
- For a sample of days, obtain daily cash reports, deposit slips, and bank statements.
- Reconcile reported takings to deposit amounts and bank credits.
- Inspect evidence of branch manager review and explanation of variances.
- Evidence:
- Signed daily cash reconciliations, bank deposit slips.
- Control:
-
Monthly revenue monitoring
- Control:
- The Finance Manager prepares and reviews monthly revenue analytical reports, comparing to budget and prior periods, investigating variances.
- Test of control:
- Inspect monthly revenue variance reports.
- Confirm Finance Manager’s review and sign‑off.
- Examine documentation supporting investigation and resolution of significant variances.
- Evidence:
- Variance analysis reports with annotations and supporting schedules.
- Control:
Evaluation:
- If tests reveal:
- Strong segregation of duties.
- Consistent credit approval documentation.
- Accurate three-way matching with few or no deviations.
- Reliable cash and banking reconciliations.
- Active monthly monitoring of revenue trends.
Then the internal auditor can conclude:
- Controls over revenue and receivables are adequately designed and operating effectively.
- Residual risk of material misstatement or fraud in the revenue cycle is low to moderate, subject to any isolated weaknesses.
If significant deviations are found (e.g., many invoices without dispatch documents, weak cash reconciliations), the internal auditor must:
- Reassess risk as high.
- Extend substantive procedures (e.g., direct confirmation of receivables, detailed cut‑off testing).
- Raise findings and recommendations in the audit report.
5.5 Exam Strategy for AUI3702: Test of Controls Questions
To perform well in AUI3702 and similar modules at UNISA and CUT, students should adopt a structured approach to “test of controls” questions.
-
Read the scenario carefully
- Identify:
- Business process (revenue, procurement, payroll, etc.).
- Key risks (implicit and explicit).
- Existing controls described.
- Identify:
-
Link risks to controls
- For each major risk, identify or propose a specific control that addresses it.
-
Design tests of controls systematically
- For each key control:
- State the objective of the test.
- Describe what evidence you will obtain.
- Indicate the nature of the test (inspection, observation, re‑performance, CAATs).
- Mention timing (period under review) and extent (reasonable sample size).
- For each key control:
-
Use exam‑appropriate structure
- Bullet points or numbered lists are acceptable and often clearer.
- Keep wording precise and concise while including critical elements.
-
Show evaluation and impact
- Briefly indicate:
- What a deviation would mean.
- How it would affect further audit work (e.g., increase substantive testing, report a deficiency).
- Briefly indicate:
-
Demonstrate understanding of frameworks
- Where relevant, refer to:
- COSO components.
- Types of controls (preventive/detective).
- The internal audit process phases (planning, fieldwork, reporting, follow‑up).
- Where relevant, refer to:
By integrating technical knowledge with a methodical approach, students at UNISA and other South African universities can write high‑quality, exam‑ready answers on the internal audit process and tests of controls, demonstrating both theoretical understanding and practical application.
