Why a Control Can Be Performed Perfectly and Still Fail: Evaluating Control Design
- John C. Blackshire, Jr.

- 1 day ago
- 7 min read
An employee performs a control exactly as instructed. The required form is completed, the appropriate boxes are checked, and the documentation is signed and filed on time.
Everything appears to be working.
There is only one problem: the control was never capable of preventing or detecting the risk it was supposed to address.
This is a control-design failure. It demonstrates why auditors and management must evaluate more than whether a control was performed. Before testing whether a control operated effectively, they must determine whether the control was properly designed.
A poorly designed control does not become effective simply because employees perform it consistently.
What Is Control Design Effectiveness?
A control is designed effectively when, if performed as intended by a person with the appropriate authority and competence, it can reasonably prevent or detect and correct a material error, fraud, compliance failure, or other identified risk.
Evaluating design effectiveness requires answering several fundamental questions:
What specific risk is the control intended to address?
What could go wrong within the process?
How does the control prevent or detect that problem?
Who performs the control?
Does that person possess the necessary authority, knowledge, and independence?
How frequently must the control operate?
What information does the control owner use?
Is that information complete, accurate, and sufficiently detailed?
What evidence demonstrates that the control was performed?
What happens when the control identifies an exception?
If these questions cannot be answered, the organization may not have a control. It may only have an activity.
Control Design and Operating Effectiveness Are Different
Control design and operating effectiveness are related, but they are not the same.
Design effectiveness asks whether the control is capable of addressing the identified risk.
Operating effectiveness asks whether the properly designed control was performed consistently, by the right people, at the right time, and with sufficient evidence.
Auditors should evaluate design before testing operation. Testing months of evidence for a control that could never address the underlying risk wastes time and produces a false sense of assurance.
Consider a manager who signs a monthly account reconciliation without examining the reconciling items. The signature may prove that the document reached the manager. It does not prove that the manager performed a meaningful review.
The control can be completed every month and still fail.
Common Examples of Poorly Designed Controls
1. Approval Without Defined Review Criteria
A manager approves every purchase over $25,000, but the procedure does not define what the manager must examine.
Is the manager verifying the business purpose, available budget, vendor selection, contract terms, conflicts of interest, or all these matters? A signature without established review criteria may document approval without demonstrating control.
2. Review by Someone Without Authority
An employee reviews system-access reports but lacks the authority to remove inappropriate access or require corrective action.
The review may identify a problem, but the control does not ensure that anyone resolves it.
3. Information That Is Incomplete or Inaccurate
A department head reviews a report of terminated employees to verify that system access was removed. However, the report excludes contractors and temporary workers.
The review might be performed flawlessly, but the incomplete population prevents the control from addressing the entire risk.
4. Control Frequency That Does Not Match the Risk
Management reviews high-risk transactions once each quarter, even though thousands of transactions occur every week.
By the time the control detects an error or fraudulent transaction, the organization may have already experienced a significant loss.
5. No Investigation of Exceptions
A supervisor reviews an exception report every month, but the control procedure does not establish:
Which exceptions require investigation
Who must investigate them
How quickly they must be resolved
What evidence must be retained
When unresolved issues must be escalated
Identifying an exception without requiring action is not an effective control response.
6. Excessive Reliance on Inquiry
Management asks employees whether they followed the procedure and accepts their verbal confirmation.
Inquiry may help auditors understand a process, but it rarely provides sufficient evidence that a control is operating effectively. People may misunderstand the question, forget what occurred, or describe what should happen instead of what actually happened.
7. Incompatible Responsibilities
The employee who creates a vendor can also approve invoices and modify payment information.
Management might review selected transactions afterward, but the preventive control structure remains weak. A single person retains too much authority over the transaction.
Start With the Risk
Effective control design begins with a clear statement of the risk.
A vague risk such as “payments may be incorrect” does not provide enough precision. A more useful risk statement would be:
Unauthorized or fictitious vendors could be added to the accounts payable system, resulting in fraudulent payments.
That statement allows management and the auditor to evaluate whether the control specifically addresses vendor authorization, vendor legitimacy, system access, and approval responsibilities.
A control that merely compares invoice totals with payment totals would not address the risk of a fictitious vendor. The control might be useful, but it addresses a different risk.
Every key control should have a defensible connection to a specific risk.
The Importance of Walkthroughs
A walkthrough follows a transaction from initiation through processing, recording, reporting, and—when applicable—financial statement presentation.
Effective walkthroughs help auditors:
Confirm how the process actually operates
Identify points where errors or fraud could occur
Determine which controls address those risks
Understand the systems and reports used
Identify manual workarounds
Evaluate segregation of duties
Confirm who performs and reviews each control
Examine the evidence retained
Determine what happens when exceptions occur
A walkthrough should not become a guided tour in which the auditor simply listens to management describe the official procedure. The auditor should ask questions, inspect documents, observe activities, and follow at least one transaction through the process.
The goal is to understand actual practice—not merely documented policy.
Information Used in the Control
Many management-review controls depend on spreadsheets, system reports, dashboards, or other company-produced information.
The control cannot be effective unless the information is reliable.
Auditors and management should determine:
Where the information originated
Whether the report includes the complete population
Whether the data is accurate
Which parameters were used
Whether users can alter the information
Whether formulas and calculations are correct
Whether report logic has changed
How management verifies the report’s reliability
A reviewer can perform an excellent analysis and still reach the wrong conclusion when the underlying information is incomplete or inaccurate.
Precision Matters
Some controls are too general to detect a significant problem.
For example, a senior executive may review monthly financial results. That review alone does not necessarily constitute an effective control over every account.
The design assessment should consider the precision of the review:
What level of detail does the executive examine?
What thresholds trigger investigation?
How are unexpected relationships identified?
How does the reviewer determine whether an explanation is reasonable?
Is supporting documentation examined?
Are unresolved matters tracked?
Is the review documented?
A high-level review may detect a major anomaly while completely missing smaller errors that could collectively become material.
Fraud Risk Requires More Than Routine Controls
Controls designed only for accidental errors may not address intentional misconduct.
Fraud can involve:
Management override
Collusion
Concealed related-party transactions
Fictitious vendors
Manipulated estimates
Altered supporting documents
Unauthorized journal entries
Suppressed exception reports
When evaluating control design, management and auditors should ask how an individual might deliberately bypass or manipulate the control.
A control performed by the same person who benefits from the transaction provides little protection. A review based entirely on information prepared by the person being reviewed may also be ineffective.
Fraud-resistant controls require appropriate independence, reliable information, clear escalation requirements, and evidence that can be independently verified.
Warning Signs of a Design Deficiency
Management, internal auditors, and external auditors should be concerned when:
The control owner cannot explain the risk being addressed.
The procedure consists only of obtaining a signature.
Review criteria are not defined.
Investigation thresholds do not exist.
Exceptions are identified but not tracked to resolution.
The control relies on an unverified spreadsheet or system report.
The reviewer lacks sufficient authority or competence.
One person controls multiple incompatible stages of a transaction.
The control operates too infrequently for the level of risk.
Documentation shows that the control occurred but not what was reviewed.
The process depends on verbal explanations or institutional knowledge.
The control does not address management override or fraud risk.
These conditions do not automatically prove that a material weakness exists. They do indicate that additional analysis and corrective action may be necessary.
What Audit Committees Should Ask
Audit committees do not need to test individual controls, but they should challenge whether management has established a credible control-assessment process.
Useful questions include:
How does management identify and document significant risks?
Which controls are considered key controls, and why?
How does management evaluate control design before testing operation?
How are system-generated reports validated?
What design deficiencies have been identified?
How quickly are those deficiencies corrected?
Which controls depend heavily on management judgment?
How does management address fraud and override risks?
Are internal audit and the external auditor finding the same control problems repeatedly?
Does management address root causes, or does it merely add another review and signature?
Repeated control failures often indicate that management has treated symptoms instead of correcting the underlying design.
Better Controls Are Not Necessarily More Controls
Organizations frequently respond to a control failure by adding another approval, checklist, certification, or review.
That can increase administrative work without reducing risk.
A better response is to determine:
Why the original control failed
Whether the control addressed the correct risk
Whether responsibility was assigned appropriately
Whether the control could be automated
Whether incompatible access should be removed
Whether better information is needed
Whether the control should prevent the problem instead of detecting it later
The goal is not to build the largest control environment. The goal is to establish controls that address significant risks efficiently and produce reliable evidence.
The Bottom Line
A completed control is not necessarily an effective control.
An organization can accumulate signatures, approvals, reconciliations, certifications, and checklists while remaining exposed to serious financial, operational, compliance, and fraud risks.
Management must first design controls that are capable of preventing or detecting the identified problem. Only then does it make sense to test whether those controls operated consistently.
Internal auditors should challenge the connection between risks and controls. External auditors should avoid relying on activities that lack sufficient precision. Audit committees should question repeated deficiencies and controls that create paperwork without producing assurance.
A control performed perfectly can still fail when it was designed to do the wrong thing—or was never capable of doing the right thing.
Strengthen Your Control-Testing Skills
Professionals who want a deeper understanding of risk-based walkthroughs, control objectives, entity-level controls, transaction-level controls, IT general controls, fraud-risk considerations, and control deficiencies can review the Corporate Compliance Seminars live webinar:
Testing the Design Effectiveness of Internal Controls — 4 CPE Credits
This program examines how auditors and control professionals can determine whether controls are properly designed before investing time in operating-effectiveness testing.
Comments