A controller learns that one clerk approves vendor payments, reconciles the bank account, and holds custody of the company checks. That single role spans authorization, recording, custody, and reconciliation. The exam will reward you for naming the broken control (segregation of duties) and the framework that demanded it (COSO).
Internal control risk is the chance that controls fail to prevent or detect a material misstatement, asset loss, or compliance breach. Management owns the risk and must design, implement, and monitor controls in proportion to the exposure. Acceptable residual risk is set by the board against the organization's risk appetite.
Internal control objectives fall in three buckets: effective and efficient operations, reliable financial reporting, and compliance with applicable laws and regulations. The same control can serve more than one objective; a journal-entry approval rule supports reporting reliability and fraud prevention at the same time.
KEY: Controls provide reasonable assurance, not absolute. Cost-benefit ceilings, human error, collusion, and management override mean no system catches every issue.
Common mistakes
- Treating "reasonable assurance" as a loophole. Reasonable assurance is a cost-benefit ceiling, not permission to skip controls. A material weakness still requires remediation, even if the company argues that absolute assurance is impossible.
- Combining authorization with custody. A manager who can both approve a wire and release it holds two of the four functions. The wire-approval workflow must route release to a separate person. One person should never hold authority and custody for the same asset class.
- Confusing significant deficiency with material weakness. A material weakness triggers an adverse 404(b) opinion on ICFR; a significant deficiency does not. The trap is calling a finding "significant" when the likelihood-and-magnitude analysis actually reaches material.
Bottom line
- Internal controls give reasonable, not absolute, assurance over three objectives: operations, financial reporting, and compliance.
- COSO's Internal Control framework has five components: Control Environment, Risk Assessment, Control Activities, Information and Communication, Monitoring Activities.
- Segregation of duties splits four functions across different people: authority, recording, custody, and periodic reconciliation.
- SOX 302 (CEO/CFO certify filings), 404 (ICFR assessment plus auditor attestation for accelerated filers), 906 (criminal penalties); PCAOB oversees auditors and requires the top-down risk-based approach under AS 2201.
Exam shortcut
When a SoD question lists who does what, count functions per person before reading the answer choices. The violation is whichever individual touches two or more of authority, recording, custody, and reconciliation. The trap answer cites a different (real but lesser) deficiency to draw you off the SoD finding. When the question mentions ICFR auditing and approaches, anchor to top-down risk-based as the PCAOB-required answer.
The full lesson (about 3,045 words, 20 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1E1
Browse all free CMA Part 1 lessons or jump into free CMA Part 1 practice questions.