What it means
Internal controls are the routine checks a business builds into its processes: a second signature on payments, a monthly bank reconciliation, a system rule that blocks a purchase order above a limit. A test of controls asks a narrow question about them, which is whether the control operated as designed, consistently, for the whole period under review.
This matters to management as much as to auditors. If controls are shown to be working, the external audit can lean on them and reduce the volume of transaction testing, which usually means a shorter, cheaper audit and less disruption to the finance team.
If controls fail, the auditor has to expand substantive testing, and the cost lands on the client. The mechanics are usually attribute sampling.
The auditor decides on a tolerable deviation rate, the maximum failure rate at which the control can still be relied on, then selects a sample sized according to how often the control runs and how much reliance is planned. Each item is inspected for evidence that the control happened, and the deviations are counted.
Testing is done through inspection of documents, re-performance of the control, observation of it happening, and enquiry of the people who run it. Enquiry alone is never enough, because asking someone whether they check something is not evidence that they did.
Auditors also test general information technology controls, since an automated control is only as reliable as the access and change management around the system. The important nuance is that a single deviation is not automatically a failure of the whole control, but it does require investigation into why it happened and whether it is isolated.
Equally, a control that operated perfectly for eleven months but was abandoned in December cannot be relied on for the year, which is why coverage across the full period matters as much as the sample size.
In practice
Real-world examples.
Example
An external auditor tests a manufacturer's payroll control by selecting 30 new starters from the year and checking that each had an authorised contract on file before the first payment ran. Two files are missing the authorisation, so the auditor traces both to the human resources system, confirms they were genuine hires, and reports the documentation weakness without expanding payroll testing.
Example
An internal audit team re-performs a retailer's daily cash reconciliation for 25 selected store days, recalculating each one from till reports and bank statements. Three days do not reconcile, and the pattern points to one store, so the team escalates to a targeted investigation rather than a general finding.
Example
A software company preparing for its first financial audit is asked to demonstrate that only authorised staff can post journal entries. The auditor inspects system access logs and change tickets for a sample of 20 entries, finds the control operating throughout, and confirms reliance for the year.
Think of it
“Test of controls checks if your controls actually work-verifying control operation.
Formula
Calculation
Sample deviation rate = (number of deviations found / sample size) x 100
An auditor is testing the control requiring every purchase invoice above $5,000 to carry documented approval from a budget holder before payment. The control operates several hundred times a year, the planned reliance is high, and the audit programme sets a sample of 40 invoices with a tolerable deviation rate of 5%.
The auditor inspects all 40 invoices and finds one that was paid with no evidence of approval. The deviation rate is (1 / 40) x 100 = 2.5%, which is below the 5% tolerable rate, so the control can be relied on and substantive testing of purchases is reduced.
Now suppose the auditor had found three unapproved invoices instead. The deviation rate would be (3 / 40) x 100 = 7.5%, above the 5% threshold. The control could not be relied on, the auditor would extend substantive testing of the purchases balance, and the deficiency would be reported to management.Case study
Seen in the real world.
Verith Components is an illustrative fictional electronics distributor whose audit fee had climbed for three years running. The finance director assumed the increase was market pricing until the audit partner explained that the firm was doing almost no controls reliance and testing transactions directly instead.
The auditors had tested the approval control over purchase invoices and found 4 deviations in a sample of 40, a rate of 10% against a tolerable 5%. All four had happened in the same two-week period when the usual approver was on leave and no delegate had been configured in the system. The control was well designed and simply had a hole in it.
Verith fixed the gap by configuring standing delegates and a system block on unapproved payments. In this fictional example the following year's test found no deviations in a sample of 40, the auditors relied on the control, substantive purchase testing fell sharply and the audit fee dropped for the first time in four years.
Watch out
Common mistakes.
- Confusing tests of controls with substantive testing, when one asks whether the process worked and the other asks whether the reported number is right.
- Relying on enquiry alone as evidence, because a person saying they perform a check is not proof that the check was performed.
- Testing only year-end transactions, which cannot support reliance on a control that has to operate for the whole period.
Questions
People also ask.
What is a tolerable deviation rate?
It is the highest failure rate at which the auditor is still willing to rely on the control, commonly set in the region of 5% to 10% depending on how much reliance is planned.
Does one deviation mean the control has failed?
Not necessarily, but it must be investigated to establish the cause and whether it is isolated, because an unexplained deviation can point to a wider breakdown.
Why should management care about controls testing?
Because reliable controls reduce audit effort and fees, catch errors and fraud earlier, and give the board evidence that the business is being run properly.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%