CPA AUD · Assessing Risk and Developing a Planned Response · Free Lesson

Control Environment and IT General Controls

Free CPA AUD (Auditing & Attestation) lesson in Assessing Risk and Developing a Planned Response. 15 min read, ~2,295 words.

Process controls (three-way match, bank reconciliation, SOD) fail when leadership rewards hitting numbers over reporting them honestly. AS 2201 and AU-C 315 treat the control environment as the most pervasive of the five COSO components: a CFO who tells staff to "find a way" to hit targets poisons every downstream control.

KEY: A weak control environment is itself a material weakness, even if every transaction-level control is designed effectively. "Tone at the top" beats "perfect SOD" when grading internal control as a whole.

COSO Principles 1 through 5 define the control environment.

Read the full lesson, free →
Worked examples and practice. Free with a free account, no card.

Common mistakes

Bottom line

Exam shortcut

When a question describes a specific control, ask which COSO component it belongs to. Anything about culture, ethics, oversight, structure, competence, or accountability is control environment. Then ask whether it is direct (prevents misstatement on its own) or indirect (only supports other controls). For ITGCs, remember: ITGC weakness invalidates automated application controls.

The full lesson (about 2,295 words, 15 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.

Learning objectives

Browse all free CPA AUD lessons or jump into free CPA AUD practice questions.