# Internal Controls Design

> Internal controls design and evaluation using the COSO 2013 framework. USE THIS SKILL when the user asks about SOX compliance, COSO framework, control design, internal controls, control environment, risk-control matrices, control deficiencies, material weakness, ITGCs, segregation of duties, control testing, or any engagement involving the design, documentation, or assessment of internal controls over financial reporting. Produces COSO-aligned control frameworks, risk-control matrices, testing plans, and deficiency remediation roadmaps.

- Skill: `kaakati/internal-controls-design` (Agent Skill)
- Install (CLI): `npx skillmds@latest add kaakati/internal-controls-design`
- Raw SKILL.md: https://api.skillmd.com/api/skills/kaakati/internal-controls-design/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Docs & Writing
- Author: Kaakati (https://skillmd.com/u/kaakati)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/kaakati/internal-controls-design

---


# Internal Controls Design & Evaluation

## Required Inputs

- **Organization**: Company name, industry, size (revenue, headcount), and public/private status
- **Scope**: Full entity, specific process areas, or IT general controls
- **Regulatory Context**: SOX 302/404, SOC 1/2, regulatory exam, voluntary adoption
- **Reporting Framework**: US GAAP, IFRS, or other applicable standards
- **Material Accounts**: Key financial statement line items in scope
- **Known Issues** (optional): Prior deficiencies, auditor findings, management concerns
- **Systems Environment**: ERP, GL, and key financial applications in use

## Execution Steps

### 1. COSO 2013 Internal Control Framework Assessment

Evaluate the organization against all 5 components and 17 principles of the COSO 2013 Integrated Framework. Each principle is scored as Present & Functioning (P), Present with Exceptions (E), or Not Present (N).

**Component 1: Control Environment**

| # | Principle | Key Assessment Areas | Score |
|---|-----------|---------------------|-------|
| 1 | Commitment to integrity and ethical values | Code of conduct, ethics hotline, tone at the top, consequence management | P / E / N |
| 2 | Board exercises oversight responsibility | Audit committee charter, meeting frequency, financial expertise, independence | P / E / N |
| 3 | Management establishes structure, authority, and responsibility | Org structure, reporting lines, delegation of authority matrix | P / E / N |
| 4 | Commitment to competence | Job descriptions, hiring standards, training programs, performance evaluation | P / E / N |
| 5 | Enforces accountability | Performance metrics tied to controls, escalation procedures, corrective action | P / E / N |

**Component 2: Risk Assessment**

| # | Principle | Key Assessment Areas | Score |
|---|-----------|---------------------|-------|
| 6 | Specifies suitable objectives | Financial reporting objectives linked to assertions; clear and measurable | P / E / N |
| 7 | Identifies and analyzes risk | Risk identification process; considers internal and external factors | P / E / N |
| 8 | Assesses fraud risk | Fraud risk assessment covering incentive, opportunity, rationalization | P / E / N |
| 9 | Identifies and analyzes significant change | Change management triggers; M&A, new products, system changes, regulatory | P / E / N |

**Component 3: Control Activities**

| # | Principle | Key Assessment Areas | Score |
|---|-----------|---------------------|-------|
| 10 | Selects and develops control activities | Controls address identified risks; mix of preventive and detective | P / E / N |
| 11 | Selects and develops technology general controls | ITGCs over access, change management, operations, development | P / E / N |
| 12 | Deploys through policies and procedures | Written policies; procedures documented; controls embedded in process | P / E / N |

**Component 4: Information & Communication**

| # | Principle | Key Assessment Areas | Score |
|---|-----------|---------------------|-------|
| 13 | Uses relevant information | Information quality; data sources identified; relevant to control objectives | P / E / N |
| 14 | Communicates internally | Control responsibilities communicated; reporting channels established | P / E / N |
| 15 | Communicates externally | External reporting processes; regulatory communication; whistleblower channels | P / E / N |

**Component 5: Monitoring Activities**

| # | Principle | Key Assessment Areas | Score |
|---|-----------|---------------------|-------|
| 16 | Conducts ongoing and/or separate evaluations | Management testing program; continuous monitoring; self-assessments | P / E / N |
| 17 | Evaluates and communicates deficiencies | Deficiency identification; classification; escalation to audit committee | P / E / N |

**COSO Assessment Summary**: A component is effective only when ALL underlying principles are Present & Functioning. The system of internal control is effective only when ALL 5 components are effective.

### 2. Financial Statement Assertion Mapping

Map controls to the 5 financial statement assertions for each significant account:

| Assertion | Abbreviation | Definition | Example Controls |
|-----------|-------------|------------|-----------------|
| Existence / Occurrence | E/O | Assets/liabilities exist; transactions occurred | Physical inventory counts; bank confirmations; transaction matching |
| Completeness | C | All transactions and balances are recorded | Sequence checks; 3-way match (PO-receipt-invoice); reconciliation to third party |
| Valuation / Allocation | V/A | Amounts are recorded at appropriate values | Reserve calculations; impairment testing; fair value models; aging analysis |
| Rights & Obligations | R/O | Entity holds rights to assets; liabilities are obligations | Title documents; contract review; lien searches; confirmation of terms |
| Presentation & Disclosure | P/D | Properly classified, described, and disclosed | Disclosure checklists; financial statement review; classification mapping |

### 3. Control Activity Design Methodology

For each identified risk, design a control activity using the following classification framework:

**Control Classification Matrix:**

| Dimension | Options | Considerations |
|-----------|---------|---------------|
| **Nature** | Preventive / Detective | Preventive preferred; detective needed as backup layer |
| **Type** | Manual / Automated / IT-Dependent Manual | Automated controls preferred for consistency and efficiency |
| **Frequency** | Transaction-level / Daily / Weekly / Monthly / Quarterly / Annual | Match to transaction volume and risk level |
| **Level** | Entity-Level / Process-Level / Transaction-Level | Entity-level are pervasive; process-level are targeted |

**Control Design Requirements (each control must specify):**
1. **Objective**: What risk does this control mitigate?
2. **Assertion(s)**: Which financial statement assertions does it address?
3. **Description**: What is performed, by whom, how, and when?
4. **Evidence**: What documentation is produced and retained?
5. **Precision**: How sensitive is the control to detecting a material error?
6. **IPE (Information Produced by the Entity)**: What reports or data does the control rely on?

### 4. Control Hierarchy: Entity-Level, Process-Level, and ITGCs

**Entity-Level Controls (ELCs):**

| Category | Examples | Mapping |
|----------|----------|---------|
| Control Environment | Code of conduct, audit committee oversight, delegation of authority | COSO Principles 1-5 |
| Risk Assessment | Enterprise risk management, fraud risk program | COSO Principles 6-9 |
| Monitoring | Internal audit function, management self-assessment program | COSO Principles 16-17 |
| Information & Communication | Reporting structure, whistleblower program, policy dissemination | COSO Principles 13-15 |

ELCs operate at the "indirect" level. They do not replace process-level controls but may influence the extent of testing required.

**Process-Level Controls (PLCs):**

Design process-level controls for each significant process. Standard significant processes include:

| Process | Key Risks | Typical Key Controls |
|---------|-----------|---------------------|
| Revenue / Receivables | Revenue recognized prematurely or fictitiously; uncollectible receivables | Contract review and approval; credit approval; shipping/delivery confirmation; AR aging review; reserve calculation |
| Procurement / Payables | Unauthorized purchases; duplicate payments; unrecorded liabilities | Purchase requisition approval; 3-way match; vendor master maintenance; AP aging review; cutoff procedures |
| Inventory | Incorrect valuation; obsolete inventory; existence | Physical inventory counts; standard cost updates; NRV analysis; cycle count program |
| Payroll | Ghost employees; incorrect compensation; unauthorized changes | New hire authorization; pay rate changes approval; payroll register review; bank reconciliation |
| Treasury / Cash | Unauthorized transactions; incorrect cash balance | Bank reconciliation; dual signatures; wire transfer approval; investment authorization |
| Financial Close | Misstatement in financial statements | Close calendar; JE approval; account reconciliations; variance analysis; management review |
| Equity / Stock Comp | Incorrect fair value; unauthorized issuance | Board approval of grants; valuation model review; vesting schedule tracking; expense calculation review |

**IT General Controls (ITGCs):**

| ITGC Domain | Control Objective | Key Controls |
|-------------|-------------------|-------------|
| **Access Security** | Only authorized users access systems and data | Access provisioning with approval; periodic access reviews (quarterly); privileged access monitoring; password policies; terminated user removal within 24 hours |
| **Change Management** | Changes are authorized, tested, and approved | Change request documentation; segregation of dev/test/prod; testing evidence; approval prior to migration; emergency change procedures |
| **Computer Operations** | Systems operate reliably and data is protected | Job scheduling and monitoring; backup procedures with offsite storage; backup restoration testing; incident management; disaster recovery planning |
| **Program Development** | New systems are properly designed and implemented | SDLC methodology; requirements documentation; user acceptance testing; data migration validation; post-implementation review |

### 5. SOX Scoping Methodology

**Step 1: Identify Material Accounts**

A financial statement line item is material if a misstatement could reasonably influence economic decisions. Apply quantitative and qualitative materiality:

- **Quantitative**: Typically 5% of pre-tax income (or alternative base: revenue, total assets)
- **Qualitative**: Items involving estimates, judgments, fraud risk, related parties, unusual transactions

**Step 2: Map Material Accounts to Significant Processes**

| Material Account | Significant Process(es) | Location(s) | System(s) |
|-----------------|------------------------|-------------|-----------|
| [Account] | [Process] | [Entity/Location] | [Application] |

**Step 3: Identify Key Controls**

For each significant process, identify key controls: the minimum set of controls that, if operating effectively, reduce the risk of material misstatement to an acceptably low level.

Key Control Criteria:
- Addresses a meaningful risk of material misstatement
- Operates at a sufficient level of precision
- Appropriate evidence of performance is retained
- IPE (information produced by the entity) used by the control is reliable

**Step 4: Determine Testing Approach**

| Control Frequency | Minimum Sample Size (Design) | Minimum Sample Size (Operating) |
|-------------------|------------------------------|-------------------------------|
| Annual | 1 | 1 |
| Quarterly | 1 | 2-4 |
| Monthly | 1 | 2-5 |
| Weekly | 1 | 5-15 |
| Daily | 1 | 20-25 |
| Per transaction | 1 | 25-60 (based on population size) |

**Operating Effectiveness Sample Sizes by Population:**

| Population Size | Sample Size (Low Risk) | Sample Size (High Risk) |
|----------------|----------------------|------------------------|
| < 50 | 5-10 | 10-20 |
| 50-250 | 15-20 | 25-40 |
| 250-1,000 | 20-25 | 40-60 |
| > 1,000 | 25 | 45-60 |

### 6. Risk-Control Matrix (RCM) Design

Each significant process requires an RCM with the following structure:

| Field | Description |
|-------|-------------|
| Process | Business process name |
| Sub-process | Specific activity within the process |
| Risk ID | Unique identifier |
| Risk Description | What could go wrong (specific to financial reporting) |
| Assertion(s) | E/O, C, V/A, R/O, P/D |
| Account(s) Affected | Financial statement line items |
| Control ID | Unique identifier |
| Control Description | Who does what, when, how, and what evidence |
| Control Type | Preventive / Detective |
| Control Nature | Manual / Automated / IT-Dependent Manual |
| Control Frequency | Transaction / Daily / Weekly / Monthly / Quarterly / Annual |
| Key Control? | Yes / No |
| IPE Used | Reports or data the control depends on |
| ITGC Dependencies | Related IT general controls |

### 7. Deficiency Classification

| Classification | Definition | Escalation |
|---------------|------------|------------|
| **Control Deficiency** | A control does not allow management or employees to prevent or detect misstatements on a timely basis in the normal course of performing their functions | Documented; tracked for remediation |
| **Significant Deficiency** | A deficiency, or combination of deficiencies, that is less severe than a material weakness yet important enough to merit attention by those charged with governance | Reported to audit committee; remediation plan required |
| **Material Weakness** | A deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis | Disclosed publicly (SOX); immediate remediation; auditor communication |

**Deficiency Evaluation Factors:**
- Likelihood of misstatement occurring
- Magnitude of potential misstatement (quantitative)
- Nature of financial statement accounts affected (qualitative)
- Whether compensating controls exist
- Whether the deficiency is systemic or isolated

### 8. Remediation Planning

**Remediation Priority Matrix:**

| Priority | Criteria | Timeline |
|----------|----------|----------|
| **Immediate** | Material weakness; regulatory deadline; active audit finding | 0-30 days |
| **High** | Significant deficiency; multiple related deficiencies; fraud risk | 30-90 days |
| **Medium** | Control deficiency with no compensating control; efficiency opportunity | 90-180 days |
| **Low** | Control deficiency with compensating control; best practice enhancement | 180-365 days |

### 9. Management Testing vs. External Auditor Reliance

| Factor | Management Testing | External Auditor Testing |
|--------|-------------------|------------------------|
| **Objective** | Assess control effectiveness for management assertion (SOX 302/404a) | Form opinion on ICFR effectiveness (SOX 404b) |
| **Scope** | All key controls across all significant processes | Risk-based selection; may rely on management testing |
| **Auditor Reliance Factors** | N/A | Competence and objectivity of testers; scope and results of testing; risk of the area; nature of controls |
| **Reliance Limits** | N/A | Auditor cannot rely solely on management testing for high-risk areas or entity-level controls |
| **Documentation** | Testing workpapers; sample selection; results; conclusions | Independent re-performance; documentation review; sample testing |

## Output Template

```markdown
# Internal Controls Design & Evaluation: [Organization Name]

**Prepared**: [Date]
**Regulatory Context**: [SOX 302/404 / SOC 1/2 / Voluntary]
**Reporting Framework**: [US GAAP / IFRS]
**Materiality Base**: [Amount] ([Basis: pre-tax income / revenue / total assets])

> **Advisory Disclaimer**: This analysis provides advisory guidance on audit
> readiness and controls design. It does not constitute an audit opinion or
> assurance engagement. Statutory audit opinions must be obtained from an
> independent auditor.

---

## 1. COSO 2013 Framework Assessment

### Component Summary

| Component | Principles Assessed | Present & Functioning | Exceptions | Not Present | Component Effective? |
|-----------|-------------------|----------------------|------------|-------------|---------------------|
| Control Environment | 1-5 | X | X | X | Yes / No |
| Risk Assessment | 6-9 | X | X | X | Yes / No |
| Control Activities | 10-12 | X | X | X | Yes / No |
| Information & Communication | 13-15 | X | X | X | Yes / No |
| Monitoring Activities | 16-17 | X | X | X | Yes / No |

**Overall ICFR Effectiveness**: [Effective / Not Effective - due to deficiencies in Components X, Y]

### Detailed Principle Assessment

| # | Principle | Score | Evidence | Gaps Identified |
|---|-----------|-------|----------|----------------|
| 1 | Integrity and ethical values | P / E / N | [Evidence] | [Gaps] |
| 2 | Board oversight | P / E / N | [Evidence] | [Gaps] |
| ... | ... | ... | ... | ... |
| 17 | Evaluates and communicates deficiencies | P / E / N | [Evidence] | [Gaps] |

---

## 2. SOX Scoping

### Material Accounts and Significant Processes

| Material Account | Balance / Activity | Significant Process | Location(s) | Key System(s) | Risk Level |
|-----------------|-------------------|--------------------|--------------|----|-----------|
| [Account] | $[Amount] | [Process] | [Location] | [System] | High / Med / Low |

### Key Controls Identified

| Control ID | Process | Control Description | Type | Nature | Frequency | Assertion(s) | Key Control? |
|-----------|---------|--------------------|----|--------|-----------|-------------|-------------|
| [ID] | [Process] | [Description] | Prev/Det | Man/Auto/ITDM | [Freq] | E/O, C, V/A, R/O, P/D | Yes / No |

---

## 3. Risk-Control Matrices

### [Process Name] RCM

| Risk ID | Risk Description | Assertion | Account | Control ID | Control Description | Type | Nature | Freq | Key? | IPE | ITGC Dep. |
|---------|-----------------|-----------|---------|-----------|--------------------|----|--------|-----|------|-----|-----------|
| [ID] | [Risk] | [Assert] | [Acct] | [ID] | [Control] | [Type] | [Nature] | [Freq] | Y/N | [IPE] | [ITGC] |

*(Repeat for each significant process)*

---

## 4. IT General Controls Assessment

| ITGC Domain | Application/System | Control Objective | Control Description | Status | Gaps |
|-------------|-------------------|-------------------|--------------------|----|------|
| Access Security | [System] | [Objective] | [Control] | Effective / Gap | [Details] |
| Change Management | [System] | [Objective] | [Control] | Effective / Gap | [Details] |
| Computer Operations | [System] | [Objective] | [Control] | Effective / Gap | [Details] |
| Program Development | [System] | [Objective] | [Control] | Effective / Gap | [Details] |

---

## 5. Control Testing Plan

| Control ID | Test Procedure | Sample Size | Population | Testing Period | Tester | Status |
|-----------|---------------|-------------|-----------|---------------|--------|--------|
| [ID] | [Procedure] | [Size] | [Population] | [Period] | [Role] | Planned / Complete |

---

## 6. Deficiency Register

| Deficiency ID | Process | Control ID | Description | Classification | Root Cause | Compensating Control? |
|--------------|---------|-----------|-------------|---------------|------------|----------------------|
| [ID] | [Process] | [Control] | [Description] | CD / SD / MW | [Cause] | Yes (describe) / No |

---

## 7. Remediation Plan

| Priority | Deficiency ID | Remediation Action | Owner | Start Date | Target Date | Validation Method | Status |
|----------|--------------|-------------------|-------|------------|------------|-------------------|--------|
| Immediate | [ID] | [Action] | [Role] | [Date] | [Date] | [Method] | [Status] |
| High | [ID] | [Action] | [Role] | [Date] | [Date] | [Method] | [Status] |
| Medium | [ID] | [Action] | [Role] | [Date] | [Date] | [Method] | [Status] |

---

## 8. Management Testing Program

| Quarter | Controls to Test | Sample Period | Testing Deadline | Results Due | Auditor Reliance Expected? |
|---------|-----------------|--------------|-----------------|------------|---------------------------|
| Q1 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |
| Q2 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |
| Q3 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |
| Q4 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |

---

*Advisory recommendation vs. audit requirement: Control design recommendations in this document reflect advisory best practices based on the COSO 2013 framework. The determination of control effectiveness for SOX compliance purposes is made by the external auditor during the integrated audit.*

*Engagement sequences: SOX Implementation (risk assessment -> control design -> testing -> remediation) | IPO Track (audit readiness -> internal controls -> financial reporting -> ESG).*
```

## Quality Checks

- [ ] All 5 COSO components assessed with all 17 principles individually scored
- [ ] Financial statement assertions (E/O, C, V/A, R/O, P/D) mapped to every key control
- [ ] Control activities classified by nature (preventive/detective), type (manual/automated), and frequency
- [ ] Entity-level controls, process-level controls, and ITGCs all addressed
- [ ] SOX scoping includes material accounts, significant processes, and key control identification
- [ ] Risk-control matrices provided for each significant process in scope
- [ ] ITGC assessment covers all 4 domains (access, change, operations, development)
- [ ] Sample sizes documented per control frequency and population size
- [ ] Deficiencies classified using 3-tier framework (deficiency / significant deficiency / material weakness)
- [ ] Remediation plan prioritized with timelines, owners, and validation methods
- [ ] Management testing program addresses auditor reliance considerations
- [ ] Advisory disclaimer is prominently displayed in the output
- [ ] Deliverable distinguishes advisory recommendations from audit requirements

