Back to Glossary

Entry · Accounting

Control Self-Assessment

Control self-assessment is a structured review in which process owners and staff examine the risks and controls in their own work. It may use a workshop, questionnaire or evidence checklist to identify gaps and assign improvements. It builds ownership but does not replace an independent audit or prove a control operates effectively just because someone rates it 'effective'.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

Managers own day-to-day controls such as payment approval, stock counts and user access reviews, and a self-assessment asks them to describe the control, show evidence and judge whether it addresses the risk. Internal audit can advise on method, while management remains responsible for the process.

Begin with a defined scope, as a company might review supplier setup for one country and one quarter rather than asking whether 'all finance controls' work. List key risks, expected controls and the people who operate them, because broad, undefined questions invite reassuring but unusable answers.

Describe each control in observable terms: 'Finance checks bank details with a previously verified contact before adding a supplier' can be tested, whereas 'Fraud is prevented' is an outcome claim, not a control description. Note frequency, owner, evidence and what happens when the check fails.

Ask for evidence before a rating, such as sampled approval logs, exception reports and the action taken on failures. A policy document proves a control was designed, not that employees followed it, so if records are missing, describe the gap rather than guessing that the work probably occurred.

A workshop can expose handoffs that a single questionnaire misses, such as procurement believing finance verifies bank details while finance believes procurement does, so bring both teams together to map where responsibility transfers and keep the discussion constructive so staff will disclose real exceptions. Self-ratings carry bias, because an owner may overstate a familiar process or focus on a recent failure and underrate a sound one, so define what 'effective', 'partly effective' and 'not effective' mean, review a sample and invite challenge where the outcome affects risk decisions.

COSO's guidance on monitoring internal controls concerns the quality of a control system over time, so a one-off self-assessment can feed monitoring but is not a permanent substitute for it. The Institute of Internal Auditors describes assurance as an objective examination of evidence against criteria, which is a different level of independence.

Distinguish design from operation: a control might require two approvers while the system permits one, which is a design gap, whereas another might be well designed but skipped during staff absences, which is an operating gap. The fix differs, since the first calls for a workflow change and the second for coverage or supervision.

Record residual risk after considering controls, because if a weak review exposes high-value transfers the issue may need immediate temporary safeguards while a system change is built, whereas a low-risk documentation gap may be handled through a planned process update, and a consistent severity method should stop serious items being buried inside an average. Assign actions with owners and dates, because 'Retrain staff' is often too broad, and a better action might require a weekly exception report reviewed by a named manager and a second approver for bank-detail changes, with a statement of how completion will be checked and which evidence will be retained.

Report unresolved disagreement: if the process owner says a control works but no log exists, state both the claim and the evidence limit. A reviewer can then decide whether further testing is warranted, and an unverified assertion should never be turned into a green dashboard box.

In practice

Real-world examples.

1

Example

Accounts payable staff find that supplier bank-detail callbacks are performed but not logged, so they add an evidence field and test it.

2

Example

Procurement and finance discover each expected the other to approve new vendors; they assign one owner and a separate reviewer.

3

Example

A store rates 42 of 50 reviewed controls effective, while separately escalating two weak high-risk cash controls.

Formula

Calculation

Illustrative self-rated effectiveness share = controls rated effective / controls assessed x 100. If 42 of 50 are rated effective, the share is 84%. This describes ratings, not independently verified effectiveness; report high-risk failures separately. Risk split. Suppose the 50 controls include 10 high-risk controls, of which 6 are rated effective, and 40 lower-risk controls, of which 36 are rated effective. - High-risk share = 6 / 10 x 100 = 60%. - Lower-risk share = 36 / 40 x 100 = 90%. - Overall share = (6 + 36) / 50 x 100 = 84%. The 84% headline hides a 60% result where the stakes are highest, so the two groups should be reported separately.

Case study

Seen in the real world.

This illustrative and entirely fictional case follows Delta Supplies, an invented wholesaler. In a quarterly self-assessment, finance staff marked supplier changes as controlled. A workshop showed that callbacks happened informally but were not recorded, and two sample changes had no proof of verification.

The finance head added a mandatory verified-contact field and a weekly exception review. Risk staff checked a later sample before closing the action. The dashboard reported the initial control as partly effective rather than silently changing its rating to green.

Watch out

Common mistakes.

  • Treating a manager's untested green rating as the same thing as independent assurance.
  • Counting the percentage of effective controls while ignoring whether the weak ones carry the highest risk.
  • Writing generic actions without an owner, due date, interim protection or evidence of later operation.

Questions

People also ask.

What is control self-assessment?

It is a structured review by process owners and staff of their own risks and controls. Evidence and assigned fixes make the result useful.

Does it replace audit?

No. Internal audit provides an independent assessment, while management self-assessment builds ownership and can identify where independent testing is needed.

How often is it done?

The cycle depends on the risk, how often the process changes and management policy, such as quarterly for key processes. Whatever the cycle, define criteria, inspect a sample of evidence and separate design from operation, because a rating without evidence is a claim, not proof.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.