The Two-Step Secret for Control Assessment

The Two-Step Secret for Control Assessment

What is the 2-step approach for evaluating a control?

A large part of IT Auditor's job involves assessing the effectiveness of internal controls. But before we delve into the technical aspects, let's understand what "design effectiveness" and "operating effectiveness" mean.

What are controls?

Controls are safeguards put in place to mitigate risks (reduce their likelihood or impact) to an acceptable level for the organization. It's important to remember that no risk can be entirely eliminated.

Operational departments are responsible for implementing these controls. The goal is to bring the risk down to a level that the organization is comfortable with, which is called the organization's risk appetite.

Here's an example: Imagine a risk that costs the organization $1,000. Let's say the organization's risk appetite for this particular risk is $600. The operational team would then implement controls to ensure that the residual risk (the risk remaining after controls are implemented) is less than $600.

Controls are designed to achieve specific objectives, ultimately aiming to mitigate risks to an acceptable level for the organization. Effective design is crucial for a control to function as intended.


Let's consider change management. When an organization implements changes, especially software changes, change management ensures a controlled rollout to the production environment. This control achieves its objective through several steps:

  • Reviewing changes by designated personnel ensures only authorized modifications proceed.
  • Approving changes by authorized individuals adds another layer of control.
  • Testing changes in a non-production environment identifies potential issues before impacting live systems.

This entire process – the change management control – is designed to effectively implement changes and minimize risks like unauthorized modifications reaching production.


How to evaluate the design effectiveness?

As an IT auditor, evaluating control design effectiveness comes first. The key question is:

  • Does the control, like the change management process outlined above, effectively address the risk?
  • In this case, does it prevent unauthorized changes from reaching production?

If the design is flawed, further testing is pointless. Design effectiveness testing ensures the control is well-conceived before moving on to evaluate its actual operation, which is called operating effectiveness. We'll explore operating effectiveness in the next section.


What's the second step in evaluating a control?

Evaluating control design is just the first step. Even a well-designed control might not always be effective in practice. This is where operating effectiveness comes in.

Testing the Control in Action

Operating effectiveness assesses whether a control is functioning as intended. Imagine the change management process we discussed earlier. An IT auditor wouldn't simply verify the existence of those steps; they'd test to see if they're actually followed:

  • Are changes consistently reviewed by designated personnel?
  • Is there a proper approval process to prevent unauthorized changes?
  • Are changes rigorously tested in a non-production environment before deployment?


How to evaluate the operating effectiveness?

As an IT auditor, your job is to gather evidence through interviews, observation, and documentation review. This evidence is then compared to the control's design criteria to determine if the control is operating effectively. Based on this evaluation, you can then form a conclusion about the control's overall effectiveness.

In simpler terms:

  • Design effectiveness asks: Do we have the right controls in place?
  • Operating effectiveness asks: Are the controls working as intended?

Both aspects are crucial. A well-designed control (great security system) won't be effective if it's not functioning properly (never gets tested or used).

So what is the key takeaway?

Demonstrating your understanding of both design and operating effectiveness portrays you as someone who can think critically about risk management and internal control systems.

This concludes our newsletter on control effectiveness!

We've discussed two key aspects of control evaluation:

  1. Design Effectiveness: This assesses whether a control is well-conceived to address the intended risk. Auditors use their expertise to determine if the control, like the change management process we discussed, is designed appropriately.
  2. Operating Effectiveness: This evaluates whether the control is being implemented and followed as designed. In simpler terms, are people actually following the established procedures?

Remember, a poorly designed control is like a faulty umbrella – it won't effectively shield you from the rain (risk). So, auditors prioritize design effectiveness first.

Thanks for reading, and hit me up if you have any other questions!

Until next time,

Signing Off

Chinmay Kulkarni


Thank you for being a part of our IT auditing community! Elevate your IT Audit game by following me on LinkedIn.

Let's continue this journey together.

Great insights, thanks for sharing, Chinmay

Like
Reply

Thank you for sharing

Like
Reply

To view or add a comment, sign in

More articles by Chinmay Kulkarni

  • Issue #3 Clarity with Chinmay

    Issue #3 Clarity with Chinmay

    What's Next in Access Control Testing? Welcome to another edition of Clarity with Chinmay! Last time, we kicked off our…

  • Issue #43

    Issue #43

    Understanding IT Application Controls (ITAC): My Key Learnings In the world of IT audit, IT Application Controls…

    5 Comments
  • Audit - Fault Finding or Issuing Opinion?

    Audit - Fault Finding or Issuing Opinion?

    One question I hear often is, "Is audit just about finding mistakes?" It’s a common misconception. From my experience…

    4 Comments
  • Top 10 Questions for Access Control Walkthroughs - Part 1

    Top 10 Questions for Access Control Walkthroughs - Part 1

    Let's discuss the ten essential access control questions you should ask during your next audit. Access control is a…

    5 Comments
  • How to Conduct Effective IT Audits?

    How to Conduct Effective IT Audits?

    In this newsletter, we're diving into a topic critical for both seasoned auditors and those just starting their audit…

    1 Comment
  • The #1 Habit That Separates Top Auditors

    The #1 Habit That Separates Top Auditors

    Today's newsletter is one of the most important I've written on any topic. Understanding this topic will set you for…

    1 Comment
  • Top 3 Considerations when evaluating IT Application Controls

    Top 3 Considerations when evaluating IT Application Controls

    Do you know the top three key considerations when evaluating IT application controls? This newsletter dives into the…

    2 Comments
  • ITGC - Job Scheduling & Monitoring

    ITGC - Job Scheduling & Monitoring

    Remember the satisfaction of receiving your paycheck on time, every other Friday? It might seem like magic, but a…

    4 Comments
  • Top 10 Audit Interview Questions You Shouldn't Miss (Part 1)

    Top 10 Audit Interview Questions You Shouldn't Miss (Part 1)

    Can you walk me through your resume? We've all been there: staring at a blank page, trying to craft the perfect…

    1 Comment
  • What Does an IT Auditor Do?

    What Does an IT Auditor Do?

    Audit an IT system? What do these folks even do with IT? Hey LinkedIn, welcome to Issue #34 of the "Chinmay's IT Audit…

    7 Comments

Insights from the community

Others also viewed

Explore topics