Lesson

Map controls, audit evidence, and accountability

Translate a reporting risk into controls and evidence while preserving management, board, auditor, overseer, and regulator responsibilities.

Updated Aug 7, 2026 Review due Nov 7, 2026
On this page
  1. Start from the reporting assertion
  2. Design for management override and collusion
  3. Preserve the audit boundary
  4. Practice and exit check
About this lesson

Lesson details

Estimated study time
95 min
Learning objectives (5)

“Improve controls” is not a recommendation an owner can execute. A control has a risk, owner, procedure, timing, population, evidence, reviewer, exception rule, and escalation path. If any field is missing, the recommendation is not yet designed.

Start from the reporting assertion

Suppose the risk is that unsupported fixed assets are recorded through manual entries. The affected assertions can include existence, occurrence, classification, valuation, completeness of expense, and presentation. A direct control chain might be:

risk: unsupported manual capitalization
owner: controller independent of entry preparer
population: all manual debits to asset accounts and linked credits
procedure: inspect approval and qualifying source evidence; aggregate anomalies
timing: before close, with post-close follow-up
evidence: immutable entry log, approval, invoice, receipt, asset record, exception record
escalation: unresolved or management-override item to audit committee

A dollar threshold alone is weak because entries can be split. HealthSouth's history motivates population-level analytics by preparer, approver, time, account pair, facility, vendor, posting source, narrative, round amount, and later activity. An anomaly is a reason to gather evidence, not a fraud verdict.

Design for management override and collusion

Segregation of duties assumes different people act independently. Senior override or collusion can defeat ordinary approval. Responsive design includes protected reporting channels, monitored privileged access, immutable logs, independent external evidence, audit-committee access, retrospective analytics, and explicit escalation outside implicated management.

AIG's finite-reinsurance history adds transaction complexity. A reviewer must confirm all contractual terms and side understandings, model risk transfer, test sensitivity, reconcile reporting effects, and back-test actual performance. A contract title and an executive approval are not independent evidence.

Apply the same nine fields rather than switching to a looser checklist:

Field AIG-inspired transaction-review design
Risk a financing-like arrangement is reported as insurance without meaningful risk transfer
Owner technical accounting leader independent of the transaction sponsor
Procedure reconstruct all cash flows and model risk transfer under the applicable criteria
Timing before execution and reporting, then through post-transaction back-testing
Population all finite-risk and economically linked agreements, amendments, and side terms
Evidence direct confirmations, executed documents, actuarial model, sensitivity, and accounting memorandum
Reviewer independent accounting, actuarial, legal, and disclosure reviewers with defined roles
Exception rule missing side-term confirmation, unsupported assumption, or unexplained reporting benefit stops approval
Escalation unresolved exceptions and sponsor overrides go to the audit committee

Preserve the audit boundary

Management prepares statements and maintains internal control. The board oversees. An independent auditor plans and performs a bounded audit and reports an opinion. The PCAOB oversees covered audit firms. The SEC administers and enforces securities requirements. None of these roles transfers the others' responsibility.

Auditor independence includes both state of mind and external circumstances that could cause a reasonable observer to question objectivity. Financial, employment, business, family, advocacy, self-review, management-participation, and fee dependencies must be evaluated under the applicable framework. A safeguard must remove or reduce a specified threat; “be objective” is not a safeguard.

Practice and exit check

Complete Complete the control-evidence chain and Identify an auditor-independence response. Then redesign one generic control recommendation from a case so another person could execute it and a reviewer could verify that it operated.