top of page
Search

How Mature Are Your Control Activities? Measuring Whether Controls Really Manage Risk


Organizations frequently spend enormous amounts of time documenting internal controls.


They build:

  • Risk and control matrices

  • Policies and procedures

  • Approval requirements

  • Reconciliations

  • Segregation-of-duties controls

  • System access controls

  • Management reviews

  • Automated controls

  • Exception reports

  • Supervisory reviews


Then Internal Audit, external audit, compliance, or management tests those controls and asks:

“Is the control operating effectively?”

That is an important question.


But there is another question that can tell management and the Audit Committee considerably more:

“How mature are our Control Activities?”

A control can operate successfully today while remaining highly dependent upon one employee, one spreadsheet, institutional knowledge, manual intervention, or a supervisor remembering to perform it.


Another organization may have the same control supported by documented procedures, assigned ownership, automated workflows, measurable performance indicators, exception monitoring, technology controls, and continuous improvement.


Both organizations technically have a control.


They clearly do not have the same level of control maturity.


Moving Beyond Effective or Ineffective

Traditional control testing frequently produces a binary conclusion:

Effective

or

Ineffective


A maturity assessment asks a different question:

How capable is this control of operating consistently, reliably, and sustainably over time?

For many organizations, a practical five-level maturity model can provide that answer:

Level 1 — Initial / Ad Hoc

Level 2 — Developing / Repeatable

Level 3 — Defined

Level 4 — Managed and Measured

Level 5 — Optimized


The objective is not automatically to move every control to the Level desired by the Organization's Governance. You have to know their risk appetite.


The required maturity should depend upon the significance of the risk.


A low-risk administrative control may operate adequately at Level 2 or Level 3.


A key financial reporting, cybersecurity, regulatory compliance, fraud-prevention, or safety control may need to operate at Level 4 or Level 5.


The principle should be straightforward:

Control maturity should be commensurate with risk.

COSO's Control Activities Component

COSO's Internal Control—Integrated Framework identifies three principles within the Control Activities component.


Principle 10 — Select and Develop Control Activities

The organization selects and develops control activities that help mitigate risks to achieving objectives to acceptable levels.


Principle 11 — General Controls Over Technology

The organization selects and develops general control activities over technology that support achievement of objectives.


Principle 12 — Deploy Through Policies and Procedures

The organization deploys control activities through policies establishing expectations and procedures putting those policies into action.


Those three principles provide an excellent architecture for a Control Activities Maturity Assessment.


Principle 10: Selecting and Developing Control Activities

The first maturity question is not:

“Do we have controls?”

Most organizations have hundreds or thousands of them.


The better question is:

“Can management demonstrate that the right controls have been deliberately designed to reduce identified risks to acceptable levels?”

Level 1 — Initial / Ad Hoc

Controls primarily develop in reaction to problems.

  • Controls depend heavily upon individual employees.

  • Control responsibilities may be unclear.

  • Controls may not be linked to identified risks.

  • Segregation of duties may be weak.

  • Significant processes may contain control gaps.

  • Management intervention frequently compensates for weak processes.

  • Controls may exist because “we have always done it that way.”


The organization has controls, but there is limited evidence that it has systematically designed a system of controls.


Level 2 — Developing / Repeatable

Basic controls have become repeatable.

  • Approvals and authorizations exist.

  • Reconciliations are regularly performed.

  • Supervisory reviews occur.

  • Some segregation of duties has been established.

  • Major processes have identifiable control owners.

  • Similar transactions generally receive similar control treatment.


However, controls may still have only a weak connection to formal risk assessment.


Management knows what controls are performed, but may have difficulty explaining precisely which risks each control mitigates.


Level 3 — Defined

Controls are formally designed and documented.


Management can identify:


Risk → Control Objective → Control Activity → Control Owner → Evidence


Risk and control matrices may document:

  • Significant risks

  • Control objectives

  • Key controls

  • Preventive versus detective controls

  • Manual versus automated controls

  • Control frequency

  • Control ownership

  • Evidence retained

  • Segregation-of-duties requirements


At Level 3, the organization has moved from having controls to having a defined control architecture.


Level 4 — Managed and Measured

Management begins measuring whether the control architecture actually works.


Management monitors such indicators as:

  • Control exceptions

  • Reconciliation differences

  • Approval overrides

  • Processing errors

  • Duplicate transactions

  • Segregation-of-duties conflicts

  • Control failures

  • Repeat audit findings

  • Corrective-action aging

  • Management overrides

  • Control-performance trends


Controls are no longer merely documented.


Their performance is measured.


Level 5 — Optimized

Control design becomes dynamic.


Changes in:

  • Risk

  • Technology

  • Business processes

  • Regulation

  • Fraud threats

  • Organizational structure

  • Transaction volume

  • Data analytics

can trigger reconsideration of the control design.


Management continually asks:

“Is there a better control?”

Unnecessary controls may be eliminated.


Manual controls may be automated.


Detective controls may be replaced or supplemented with preventive controls.


Data analytics may identify exceptions across entire populations rather than relying upon limited samples.


The organization is continually improving the relationship between risk and control.


Principle 11: General Controls Over Technology

Modern organizations cannot have mature business-process controls while maintaining immature technology controls.


Consider how many critical controls now depend upon:

  • ERP systems

  • Accounting applications

  • Cloud platforms

  • Automated workflows

  • Databases

  • Interfaces

  • Artificial intelligence

  • User-access permissions

  • System configurations

  • Automated calculations


A beautifully designed automated control becomes questionable if unauthorized users can change the program or underlying data.


Technology maturity therefore matters.


Level 1 — Initial / Ad Hoc

  • Access may be granted informally.

  • Privileged access is poorly controlled.

  • Changes may occur without formal approval.

  • Terminated employees may retain access.

  • System configurations may not be documented.

  • Technology controls depend heavily upon particular IT personnel.


Level 2 — Developing / Repeatable

Basic IT general controls exist.


These may include:

  • Password requirements

  • User provisioning

  • Backup processes

  • Change approvals

  • Security administration

  • Basic system monitoring


Processes are repeatable but may not be consistently documented or independently reviewed.


Level 3 — Defined

Formal IT general-control processes cover areas such as:

  • Logical access

  • Privileged access

  • User provisioning and termination

  • Change management

  • System development

  • Computer operations

  • Backup and recovery

  • Cybersecurity

  • Application interfaces

  • Technology acquisition and maintenance


Responsibilities and evidence requirements are documented.


Level 4 — Managed and Measured

Technology controls generate measurable information.


Management monitors:

  • Access violations

  • Privileged accounts

  • Failed login activity

  • Emergency changes

  • Unauthorized changes

  • Security incidents

  • Patch status

  • Backup failures

  • System availability

  • User-access-review exceptions


IT control performance becomes part of enterprise control reporting.


Level 5 — Optimized

Technology increasingly strengthens the control system itself.


Organizations use:

  • Automated access governance

  • Continuous monitoring

  • Exception analytics

  • Automated segregation-of-duties analysis

  • Continuous configuration monitoring

  • Workflow controls

  • Automated alerts

  • Data analytics

  • AI-assisted anomaly identification


Technology is no longer simply something that must be controlled.


It becomes an important mechanism for improving control maturity.


Principle 12: Policies and Procedures

Organizations often confuse documentation with control maturity.


They point to a 300-page policy manual and conclude:

“Our controls are well documented.”

Perhaps.


But a policy sitting on a SharePoint site does not control anything by itself.


The maturity question is:

“Are policies translated into procedures that people understand, consistently perform, evidence, supervise, and update?”

Level 1 — Initial / Ad Hoc

  • Policies may be incomplete or outdated.

  • Procedures depend upon institutional knowledge.

  • Employees learn processes primarily from coworkers.

  • Responsibilities are unclear.

  • Documentation of control performance is inconsistent.


Level 2 — Developing / Repeatable

Basic policies and procedures exist.


Employees generally know what is expected.


However:

  • Documentation varies among departments.

  • Procedures may lag behind actual practices.

  • Control evidence may be inconsistent.

  • Responsibilities may depend upon particular individuals.


Level 3 — Defined

Policies and procedures formally establish:

  • What must be performed

  • Who performs it

  • When it is performed

  • Who reviews it

  • What evidence must be retained

  • How exceptions are handled

  • Who receives escalation


Employees responsible for significant controls receive appropriate training.


Level 4 — Managed and Measured

Management measures compliance with established procedures.


It can identify:

  • Controls not performed

  • Controls performed late

  • Missing evidence

  • Unresolved exceptions

  • Policy violations

  • Repeat failures

  • Overdue corrective actions


Control owners become accountable for measurable performance.


Level 5 — Optimized

Policies and procedures evolve with risk.


Management periodically asks:

  • Is this policy still necessary?

  • Does the procedure still address the risk?

  • Can the control be simplified?

  • Can it be automated?

  • Are employees bypassing it?

  • Has technology changed the process?

  • Are new risks emerging?


The policy and procedure system becomes a living component of risk management rather than a static compliance library.


A Control Activities Maturity Scorecard

Management and Internal Audit can combine the three COSO principles into a practical assessment.

COSO Principle

Current Maturity

Target Maturity

Gap

Principle 10 — Control Selection and Design

2.8

4.0

1.2

Principle 11 — Technology Controls

2.4

4.0

1.6

Principle 12 — Policies and Procedures

3.2

4.0

0.8

Control Activities Component

2.8

4.0

1.2


That tells management considerably more than:

“Control Activities are effective.”

It shows where the weakness exists and how significant the capability gap may be.


Take the Assessment Down to the Individual Control Level

The methodology becomes even more useful when applied to significant controls.


Consider an accounts-payable vendor-change control.


Level 1

An employee receives an email requesting a bank-account change and updates the vendor master file.


Level 2

A second employee approves the change.


Level 3

A documented procedure requires independent verification, approval, segregation of duties, and retention of evidence.


Level 4

Management measures vendor changes, exceptions, overrides, failed verifications, and unusual activity.


Level 5

Automated workflow, access controls, analytics, independent verification, continuous monitoring, and exception reporting work together to identify suspicious changes before payments occur.


is technically the same control objective:

Prevent unauthorized changes to vendor payment information.

But the organization's capability to achieve that objective is dramatically different.


Control Design and Control Maturity Are Not the Same Thing

This distinction is particularly important for auditors.


A control can be properly designed but immature.


It may depend upon:

  • One experienced employee

  • A manually maintained spreadsheet

  • Institutional knowledge

  • An undocumented review

  • Management intervention

  • An informal exception process


The control may work today.


The question is whether it will continue working when:

  • The employee leaves

  • Transaction volume doubles

  • The organization implements a new system

  • Management changes

  • A sophisticated fraudster attacks the process

  • Operations are decentralized

  • The organization acquires another company


Maturity therefore provides another dimension for evaluating control sustainability.


Don't Average Away a Critical Weakness

There is also a danger in maturity scoring.


Suppose an organization scores:

Principle 10 — 4.2

Principle 11 — 1.8

Principle 12 — 4.0


The mathematical average is: 3.3


That number can be misleading.


If critical automated controls depend upon an IT environment operating at Level 1.8, the organization may have a significant control problem regardless of the average.


Maturity assessment should therefore identify critical dependencies and minimum acceptable maturity levels, not simply calculate averages.


Management Owns Control Maturity

Internal Audit should not decide how mature management's controls must become.


Management owns the system of internal control.


Management should therefore determine:

  • Significant risks

  • Risk appetite and tolerance

  • Required controls

  • Required maturity

  • Resources necessary to achieve that maturity


Internal Audit can independently assess whether:

  • Management's maturity assessment is reasonable.

  • Controls actually operate at the claimed level.

  • Evidence supports the rating.

  • Significant maturity gaps have been identified.

  • Remediation plans are reasonable.

  • Reported improvements actually occurred.


That preserves Internal Audit's independence while providing management and the Audit Committee with considerably better assurance information.


Give the Audit Committee Better Information

Consider two ways of reporting the same problem.


Traditional Reporting

  • Finding: Vendor master-file controls need improvement.

  • Risk: High.

  • Management Response: Corrective action underway.


Now consider:


Maturity Reporting

  • Risk: Vendor payment fraud — High

  • Current Maturity: Level 2 — Developing

  • Required Maturity: Level 4 — Managed and Measured

  • Gap: 2 Levels

  • Primary Weaknesses: Manual verification, excessive access, inadequate monitoring and insufficient exception reporting.

  • Target: Level 3 within six months; Level 4 within twelve months.


That tells the Audit Committee considerably more about the organization's actual control capability.


The Bigger Question

Organizations spend substantial resources creating and testing internal controls.


But the existence of controls should not be confused with a mature system of internal control.


The better questions are:

Are our controls deliberately linked to our risks?
Are technology controls strong enough to support them?
Are policies actually translated into consistently performed procedures?
Can management measure control performance?
Do controls improve as risks and operations change?

Ultimately, maturity assessment moves the discussion from:

“Do we have controls?”

to:

“How reliably can our controls manage risk today—and how confident are we that they will continue doing so tomorrow?”

That is a considerably more useful question for management, Internal Audit, external auditors, risk professionals, and the Audit Committee.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page