A control review evaluates whether an internal control is appropriately designed for the risk it addresses and whether it operates as intended. For managers, control owners, risk and compliance teams, and internal auditors, a useful review connects the risk to the control, tests relevant evidence, documents any gaps, and tracks corrective action through completion.
What is a control review?
A control review is an assessment of a measure intended to manage risk. It asks two distinct questions: would the control, if performed as designed, address the relevant risk; and did it actually operate as required during the period being reviewed?
Controls can be preventive, detective, or corrective. Preventive controls aim to reduce the chance of an unwanted event, as with approvals or separation of duties. Detective controls identify errors or failures, such as reconciliations or exception reports. Corrective controls address consequences, for example through continuity or disaster-recovery plans. One control may serve more than one of these functions. The Australian Department of Finance describes these categories in its RMG 211 guidance on maintaining and reviewing controls.
What should an internal control review include?
- Set the scope. Define the process, objective, and risk in view. Identify the control owner, the control being reviewed, the period covered, and any applicable internal framework or jurisdiction-specific requirements.
- Assess the design. Consider whether the control is capable of addressing the risk, whether responsibilities are clear, and whether the control is proportionate to the risk. A documented policy can help explain the intended design, but does not show that anyone followed it.
- Gather evidence of operation. Choose evidence suited to the control, such as records, observation, inquiry, reconciliations, exception reports, or transaction testing. Determine whether the control occurred as required and whether exceptions were handled.
- Document the assessment. Record the work performed, evidence examined, results, exceptions, and limitations in enough detail for another reviewer to understand how the conclusion was reached.
- Assign and follow up on actions. For a deficiency, record the corrective action, accountable owner, and follow-up. Verify that remediation has been implemented and is working; identifying a gap alone does not resolve it.
- Set the next review point. Base timing on risk and relevant change, and coordinate with other reviews where that avoids unnecessary duplication without leaving important risks uncovered.
How do you test whether a control is operating effectively?
Start with what the control is meant to do and how often it should happen. Then select a method that can establish whether it did so. A review may inspect dated approvals, examine a reconciliation and its resolution of exceptions, observe a process, ask the responsible person how it is performed, or test transactions. The method should fit the control: inquiry can clarify a process, but by itself may not establish that the control operated.
Recommended Free Tools
#1 Best Overall
- Used Book in Good Condition
Keep design and operation conclusions separate. A control may be well designed but inconsistently performed; a control may also be performed consistently yet fail to address the risk adequately. Document the evidence and any limitations so the conclusion does not claim more than the work supports.
How often should internal controls be reviewed?
There is no universal interval established by the sources cited here. The Australian Department of Finance states that “The frequency of control reviews should be guided by the nature, velocity and severity of the risks.” It also identifies control criticality, risk appetite, and changes such as introducing a new IT system or turnover in control owners as relevant considerations. Its guidance says, “The effectiveness of controls must be periodically reviewed,” and recommends documenting the review process and outcomes (RMG 211, Element 5).
Rank #2
NASA’s federal financial-management procedures provide a narrower example: they describe annual risk assessments and transaction testing, along with annual scheduling of quality-assurance reviews. NASA NPR 9010.3A is agency-specific, not a schedule for every organization; the procedure lists an effective date of February 3, 2020, and an expiration date of June 29, 2031 (NASA NPR 9010.3A).
What should happen when a review finds a deficiency?
Document what failed or is missing, the risk it creates, the evidence supporting the finding, and any limits on the assessment. Assign an owner and a corrective action, then set a follow-up point to check implementation and effectiveness. NASA’s procedures describe documenting and monitoring deficiencies through Corrective Action Plans in its own financial-management context (NASA NPR 9010.3A).
Rank #3
A review provides information for risk management; it cannot guarantee that fraud, error, or control failure will never occur. OMB Circular A-123 frames internal control in terms of reasonable assurance and management responsibility. The linked circular is an archived revision effective in fiscal year 2006, not a stand-alone statement of current requirements. Federal agencies should verify the current circular and agency instructions, and organizations elsewhere should apply their own governing framework (OMB Circular A-123, archived revision).
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to choose a review process or tool
A small, straightforward control set may be managed with documented procedures and records; a complex, recurring program may benefit from specialized audit-management or governance, risk, and compliance (GRC) software. The choice should support the actual review work rather than substitute for it. Compare options on:
Rank #4
- Coverage of the organization’s risks and fit with its control framework.
- Evidence quality, traceability, retention, and access.
- Assignment of control owners, reviewers, and corrective actions.
- Reporting and audit-trail requirements.
- Integration with existing systems and review processes.
- Setup and ongoing effort relative to the program’s size and complexity.
- For outside support, independence, expertise, and competence in the relevant jurisdiction and framework.
These criteria follow from the practical needs to assign ownership, test and retain evidence, report results, and track corrective actions. No one format or tool is prescribed across all organizations.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →



