Asset Management Risks and Controls
In CIA Part 2, engagement planning requires the internal auditor to understand the area under review, identify significant risks, and evaluate whether controls are adequately designed before setting objectives, scope, and the work program. Asset management covers the acquisition, use, safeguarding,… In CIA Part 2, engagement planning requires the internal auditor to understand the area under review, identify significant risks, and evaluate whether controls are adequately designed before setting objectives, scope, and the work program. Asset management covers the acquisition, use, safeguarding, maintenance, recording, and disposal of tangible assets such as property, plant, equipment, inventory, and IT hardware, as well as intangible assets such as software licenses and data. Key risks include theft or misappropriation; physical damage or loss from fire, weather, or poor maintenance; unauthorized acquisitions or disposals; inaccurate or incomplete asset registers; improper capitalization versus expensing; incorrect depreciation, impairment, or valuation; obsolescence and underutilization; inadequate insurance coverage; noncompliance with lease, tax, or regulatory requirements; and, for IT assets, unlicensed software, untracked devices, and data breaches from improperly disposed equipment. Preventive controls include capital budgeting and documented authorization for purchases and disposals, segregation of duties among custody, authorization, and recordkeeping, physical safeguards such as locks, restricted access, and surveillance, asset tagging, and clear capitalization policies. Detective controls include periodic physical counts reconciled to the fixed asset register and general ledger, independent review of depreciation calculations, impairment assessments, exception reports, and monitoring of utilization. Corrective controls include investigating discrepancies, adjusting records, updating insurance, and enforcing disciplinary action for misuse. IT asset management tools and secure data-wiping procedures address technology-specific risks. During planning, the auditor reviews prior audit results, asset policies, organizational charts, and key performance indicators, interviews management, and performs analytical procedures, such as comparing depreciation trends or maintenance costs, to target high-risk areas. Engagement objectives typically address existence, completeness, accuracy, valuation, ownership rights, and safeguarding. Planned tests may include vouching from the register to physical assets to confirm existence, tracing from physical assets to the register to confirm completeness, examining invoices and titles for ownership, and inspecting disposal approvals. A risk-based approach ensures resources focus on high-value, portable, or easily misappropriated assets, giving management assurance that assets are protected and properly reported.
Asset Management Risks and Controls: A Complete CIA Part 2 Guide to Engagement Planning
Asset Management Risks and Controls: A Complete CIA Part 2 Guide
Introduction
Asset management is one of the most frequently tested operational areas in CIA Part 2 (Practice of Internal Auditing), particularly within the Engagement Planning domain. When internal auditors plan an engagement, they must understand the risks to the organization's assets and the controls designed to reduce those risks. This guide explains what asset management risks and controls are, why they matter, how they work in practice, and how to approach exam questions on the topic.
1. Why Asset Management Risks and Controls Are Important
Assets are the resources an organization uses to create value. They include:
• Cash
• Inventory
• Fixed assets such as property, plant and equipment (PP&E)
• IT hardware and software
• Intellectual property
• Data
When assets are poorly managed, the organization faces several types of harm:
• Financial loss: theft, fraud, damage or obsolescence directly reduce value.
• Misstated financial statements: assets may be overstated or understated, which leads to unreliable reporting and regulatory exposure.
• Operational disruption: unavailable or poorly maintained equipment halts production and service delivery.
• Inefficient use of capital: idle, duplicate or underused assets tie up resources that could be invested elsewhere.
• Compliance and legal issues: failures in insurance, environmental disposal rules, licensing or data protection rules create legal exposure.
• Reputational damage: data breaches or publicized fraud harm stakeholder trust.
The IIA's Global Internal Audit Standards expect internal auditors to evaluate whether governance, risk management and control processes are adequate to achieve objectives. One core control objective is the safeguarding of assets. Understanding asset management risks therefore sits at the heart of planning a risk-based engagement.
2. What Asset Management Is
Asset management is the systematic process of acquiring, recording, using, maintaining, protecting and disposing of assets in a cost-effective way that supports organizational objectives. It covers the full asset life cycle:
1. Planning and requisition: identifying needs and justifying acquisitions through capital budgeting.
2. Acquisition: purchasing, leasing or constructing assets.
3. Recording: capitalization, tagging and entry into the fixed asset register.
4. Use and maintenance: deployment, preventive maintenance, custody and transfers.
5. Valuation: depreciation, impairment testing and revaluation.
6. Disposal: sale, scrapping, donation or retirement, followed by removal from records.
Key asset categories tested on the CIA exam
• Cash: highly liquid and highly vulnerable to theft.
• Inventory: raw materials, work in progress and finished goods, which are exposed to shrinkage, obsolescence and valuation errors.
• Fixed assets (PP&E): long-lived assets, which are exposed to unrecorded additions, unauthorized disposals and incorrect depreciation.
• IT assets: hardware, software licenses and data, which are exposed to loss, license noncompliance and security breaches.
• Intangible assets: patents, trademarks and goodwill, which are exposed to infringement and impairment.
3. How It Works: Key Risks Across the Asset Life Cycle
Acquisition risks
• Unauthorized or unnecessary purchases
• Overpayment, kickbacks or conflicts of interest with vendors
• Incorrect capitalization versus expensing (for example, repairs capitalized to inflate profit)
• Purchases that bypass capital budgeting approval
Recording and accounting risks
• Assets not recorded, or recorded twice
• Incorrect cost, useful life or depreciation method
• Failure to recognize impairment
• Fictitious assets in the register
Custody and use risks
• Theft or misappropriation, including personal use of company assets
• Physical damage, often due to poor maintenance
• Unrecorded transfers between departments or locations
• Underuse or idle assets
Inventory-specific risks
• Shrinkage from theft, spoilage or recording errors
• Obsolescence and slow-moving stock
• Excess inventory, which carries high holding costs
• Stockouts that cause lost sales
• Cut-off errors at period end
• Incorrect valuation (FIFO, weighted average, lower of cost and net realizable value)
Disposal risks
• Unauthorized disposals, or sales to related parties below fair value
• Assets disposed of but not removed from the register (ghost assets)
• Data left on disposed IT equipment
• Environmental noncompliance in disposal
IT asset risks
• Software license noncompliance, either too few licenses (legal penalties) or too many (wasted cost)
• Lost laptops or mobile devices containing sensitive data
• Shadow IT, meaning unregistered devices or applications
4. How It Works: Key Controls
Controls are commonly classified as preventive, detective, corrective and directive. The exam often asks you to identify the best control or the type of control.
Preventive controls (stop problems before they occur)
• Segregation of duties: separate authorization, custody, recordkeeping and reconciliation. This is the single most tested concept. For example, the person who has custody of inventory should not maintain the inventory records.
• Authorization and approval: capital expenditure approval limits, purchase requisitions and disposal authorization forms.
• Physical safeguards: locked warehouses, safes, restricted access, security guards, CCTV and badge access.
• Asset tagging: barcodes, RFID tags and serial number tracking.
• Capitalization policy: clear thresholds and rules for capitalizing versus expensing.
• Insurance: transfers the financial risk of loss. Strictly, this is a risk-transfer and corrective mechanism rather than a pure control.
• Logical access controls: restrict who can change the asset register or inventory system.
Detective controls (find problems after they occur)
• Physical counts and inspections: periodic counts of fixed assets, and cycle counts or annual counts of inventory, compared to records.
• Reconciliations: the fixed asset subsidiary ledger reconciled to the general ledger, and perpetual inventory reconciled to physical counts.
• Variance and exception reports: unusual inventory adjustments, negative balances and idle asset reports.
• Analytical review: inventory turnover, shrinkage percentages, and depreciation trends compared to prior periods.
• Software license audits: comparing installed copies to purchased licenses.
Corrective controls (fix problems)
• Adjusting records after count differences
• Disciplinary actions
• Insurance claims
• Updating procedures after control failures
Directive controls
• Asset management policies and procedures
• Training on asset handling
• Codes of conduct addressing personal use of company assets
Inventory management techniques worth knowing
• Economic Order Quantity (EOQ): the order size that minimizes the combined cost of ordering and holding inventory.
• Just-in-Time (JIT): reduces holding costs but increases dependence on suppliers and the risk of stockouts.
• ABC analysis: focuses control effort on high-value (A) items.
• Reorder points and safety stock: help prevent stockouts.
• Perpetual versus periodic inventory systems: perpetual systems allow continuous monitoring and better detection of shrinkage.
5. Asset Management in Engagement Planning
When planning an asset management engagement, the internal auditor follows these steps:
1. Understand the area under review: its objectives, processes, systems, asset values and locations.
2. Conduct a preliminary risk assessment: identify inherent risks such as high-value portable items, multiple locations or recent system changes, and assess their likelihood and impact.
3. Identify key controls: use walkthroughs, flowcharts, narratives and internal control questionnaires.
4. Set engagement objectives and scope: for example, "Determine whether controls provide reasonable assurance that fixed assets are safeguarded and accurately recorded."
5. Develop the work program: specify tests linked to the risks.
6. Allocate resources: consider specialists such as IT auditors or valuation experts where needed.
Typical audit procedures and the assertion each tests
• Existence: trace from the register to the physical asset (vouching).
• Completeness: trace from the physical asset to the register.
• Valuation: recalculate depreciation and review impairment indicators and the lower of cost and NRV.
• Rights and ownership: examine titles, invoices and lease agreements.
• Authorization: inspect approvals for additions and disposals.
• Cut-off: examine receiving and shipping documents around period end.
• Observation: observe inventory counts to evaluate count procedures.
Key directional rule: To test existence, start from the records and go to the asset. To test completeness, start from the asset (or source documents) and go to the records. This distinction is heavily tested.
6. Common Fraud Schemes Involving Assets
• Theft of inventory concealed by false write-offs or adjustments
• Fictitious fixed asset additions used to hide embezzlement
• Selling assets and pocketing the proceeds while the asset remains on the books
• Personal use of company vehicles or equipment
• Lapping, cash skimming and kiting
• Inflating inventory to overstate profit (financial reporting fraud)
Red flags include large unexplained inventory adjustments, missing tags, frequent "lost" items, a custodian who refuses to take vacation, and growth in inventory that does not match sales.
7. Worked Examples
Example 1: A warehouse supervisor receives goods, maintains inventory records and approves inventory write-offs. What is the primary risk?
Answer: Inadequate segregation of duties. This allows theft to be concealed through write-offs. The best control is to separate custody from recordkeeping and to require independent approval of adjustments.
Example 2: An auditor selects items from the fixed asset register and locates them physically. Which assertion is tested?
Answer: Existence.
Example 3: Which control would best detect unrecorded disposals of equipment?
Answer: A periodic physical inspection of assets compared to the fixed asset register. This is a detective control.
Example 4: A company has recently adopted JIT. Which risk increases most?
Answer: Production stoppages caused by supplier delays, meaning stockout risk and supplier dependency.
Exam Tips: Answering Questions on Asset Management Risks and Controls
1. Think segregation of duties first. When a question describes one person doing several tasks, the answer usually involves separating authorization, custody, recording and reconciliation. Custody versus recordkeeping is the classic conflict.
2. Match the control type to the wording. "Prevent" points to authorization, physical security or SoD. "Detect" points to counts, reconciliations or exception reports. Read carefully: a reconciliation never prevents an error.
3. Master the direction of testing. Records to the physical item tests existence. The physical item or source document to the records tests completeness. Many distractors simply reverse this direction.
4. Choose the most effective, not just a valid, answer. Several options may be reasonable. Select the one that directly addresses the stated risk at its root cause. Independent verification generally beats self-review.
5. Identify the risk before the control. Ask what could go wrong (theft, misstatement, obsolescence, inefficiency) and which life-cycle stage is involved. Then select the matching control.
6. Remember that insurance does not safeguard the asset itself. It transfers financial loss. If the question asks how to protect assets from theft, physical controls are the better answer.
7. Watch for valuation questions. Obsolete or slow-moving inventory signals valuation risk (lower of cost and NRV). Asset impairment indicators signal overstatement.
8. Link the answer to engagement planning. In planning questions, the first step is usually understanding the process and its risks (preliminary survey, risk assessment) before testing controls. Do not jump straight to substantive testing.
9. Look for keywords. Words such as "best," "most likely," "primary" and "first" change the answer. "First" usually points to planning or understanding activities.
10. Apply the cost-benefit principle. Controls should be proportional to risk. ABC analysis and focusing on high-value or high-risk assets reflect risk-based thinking, which the IIA favors.
11. Use IT-related logic. For IT assets, consider license compliance, data wiping before disposal, encryption of portable devices, and access restriction to the asset register.
12. Eliminate extreme answers. Options that eliminate all risk, or that place management duties on internal audit (such as performing the counts or approving disposals), are usually wrong. They impair objectivity.
Quick Revision Summary
• Asset management covers the full life cycle: acquire, record, use, maintain, value and dispose.
• Key risks are theft, misstatement, obsolescence, unauthorized transactions, inefficiency and noncompliance.
• Key controls are SoD, authorization, physical security, tagging, counts, reconciliations and exception reporting.
• Existence is tested from records to the asset. Completeness is tested from the asset to the records.
• In planning, understand the process, assess risks, identify controls, set objectives and scope, then build the work program.
Master these principles and you will be well prepared to handle CIA Part 2 questions on asset management risks and controls with confidence.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!