Evidence from Systems with Effective Controls
In CIA Part 2, evidence from systems with effective controls is one of the factors internal auditors use to judge the reliability of information during an engagement. The IIA's Global Internal Audit Standards require auditors to gather information that is relevant, reliable, and sufficient to suppo… In CIA Part 2, evidence from systems with effective controls is one of the factors internal auditors use to judge the reliability of information during an engagement. The IIA's Global Internal Audit Standards require auditors to gather information that is relevant, reliable, and sufficient to support their findings and conclusions. Reliability depends partly on the strength of the controls over the system that produced the information. When a system has well-designed controls that operate effectively, the data it generates is more likely to be accurate, complete, and valid. Evidence from such a system is therefore considered more reliable than evidence from a system with weak or missing controls. Examples of relevant controls include IT general controls, such as access security, change management, and backup and recovery. Application controls also matter, such as input validation, processing edits, reconciliations, and output reviews. Segregation of duties, authorization requirements, and management oversight further strengthen confidence in system-generated reports, transaction logs, and records. Auditors should not simply assume that controls are effective. They should first evaluate the design of the controls and then test whether the controls operate effectively. They can use walkthroughs, inquiry, observation, inspection, reperformance, or data analytics. When testing confirms that controls are effective, auditors may rely more on system-generated evidence. This can allow them to reduce the nature, timing, or extent of detailed substantive testing, which improves engagement efficiency. When controls are weak, auditors should be more skeptical. In that case, they should seek corroborating evidence, such as external confirmations, direct observation, or recalculation, and expand their sample sizes. This principle fits into the general hierarchy of evidence reliability. Evidence obtained directly by the auditor is generally more reliable than evidence obtained indirectly. Independent external sources are generally more reliable than internal sources, and original documents are more reliable than copies. Internally generated evidence becomes more persuasive when effective controls support it. Auditors must document their assessment of controls and explain how that assessment affected their reliance on the evidence. This documentation helps ensure that conclusions are well supported and defensible.
Evidence from Systems with Effective Controls (CIA Part 2: Information Gathering, Analysis and Evaluation)
Overview
In CIA Part 2 (Practice of Internal Auditing), one key part of gathering and evaluating information is judging how reliable audit evidence is. A core principle in both the IIA standards and the CIA exam is this: information produced by a system with effective internal controls is more reliable than information produced by a system with weak or untested controls. This guide explains why the principle matters, what it means, how it works in practice and how to answer exam questions on it.
Why It Is Important
Internal auditors must base their conclusions and engagement results on sufficient, reliable, relevant and useful information. This requirement appears in IIA Standard 2310 (Identifying Information) and, under the Global Internal Audit Standards (2024), in Standard 14.1 (Gathering Information for Analyses and Evaluation).
Much of the evidence auditors rely on comes from the organization's own systems, such as reports, ledgers, transaction logs and system-generated listings. If the controls over those systems are weak, the evidence may be:
- incomplete
- inaccurate
- manipulated
- unauthorized
Knowing the link between control effectiveness and evidence reliability lets auditors:
- decide how much they can rely on client-generated data;
- set the nature, timing and extent of substantive testing;
- use audit resources efficiently, doing less testing where controls are strong and more where they are weak;
- avoid reaching wrong conclusions from flawed data;
- support engagement conclusions that will stand up to scrutiny by management, the board and quality reviewers.
What It Is
The principle is one of the classic hierarchy of evidence reliability rules. The IIA and the auditing literature generally rank evidence reliability as follows:
1. Evidence obtained from independent sources outside the organization is more reliable than evidence obtained from inside it.
2. Evidence obtained directly by the auditor (observation, physical examination, recalculation, reperformance) is more reliable than evidence obtained indirectly or by inference.
3. Documentary evidence is more reliable than oral evidence.
4. Original documents are more reliable than photocopies or facsimiles.
5. Internally generated evidence is more reliable when the related controls are effective.
Rule 5 is the subject of this topic. Even evidence produced inside the organization can be highly reliable if it is generated, processed and stored under effective controls. Examples of such controls include:
- segregation of duties
- authorization and approval controls
- input, processing and output controls
- access controls
- reconciliations
- change management
- IT general controls (ITGCs)
For example, a sales report from an ERP system with strong access controls, validated inputs and regular reconciliations to the general ledger is far more trustworthy than a spreadsheet anyone in the department can edit.
How It Works
1. Understand and evaluate the control environment. Before relying on system-generated information, the auditor gains an understanding of the system and its controls. This is done through:
- walkthroughs
- flowcharts
- narratives
- internal control questionnaires
- reviews of prior audit results
2. Test the controls. Understanding is not enough. If the auditor plans to rely on the controls, they must test whether the controls are operating effectively. Tests of controls include:
- Inquiry: asking about the controls (the weakest test on its own).
- Observation: watching the control being performed.
- Inspection: examining documents for evidence of the control, such as approval signatures or reconciliation sign-offs.
- Reperformance: independently executing the control (often the strongest test).
- Computer-assisted audit techniques (CAATs), test data, parallel simulation and data analytics for automated controls.
3. Evaluate ITGCs for automated systems. Reliance on application controls and system reports depends on effective IT general controls:
- logical access security
- program change management
- computer operations
- system development controls
If ITGCs are weak, automated controls and system outputs may not be dependable, even if they appear to work.
4. Adjust substantive testing to the level of control reliance.
- Effective controls: higher reliance on system data, lower control risk, and reduced substantive testing (smaller samples, testing at interim dates, more analytical procedures).
- Ineffective or untested controls: lower reliance, higher control risk, and expanded substantive testing (larger samples, testing at or near period-end, more direct and external evidence such as confirmations).
5. Validate key reports. Even with effective controls, auditors often verify the completeness and accuracy of key system-generated reports (sometimes called Information Produced by the Entity, or IPE). They do this by tracing items to source documents and from source documents to the report, and by reconciling report totals to the ledger.
6. Document the evaluation. Under IIA Standard 2330 (Documenting Information), or Standard 14.6 under the 2024 standards, auditors document the basis for relying on system evidence, including the results of control testing.
Illustrative Example
An auditor reviewing accounts payable wants to use a system-generated aged payables listing.
- Scenario A: The auditor tests the controls and finds that the three-way match is automated, vendor master file changes require dual approval, access is role-based and restricted, and monthly reconciliations to the GL are reviewed and signed off. The listing can be relied on with limited additional verification.
- Scenario B: Finance staff can edit invoices after posting, and no reconciliation is performed. The listing is unreliable. The auditor should expand substantive procedures, for example by confirming balances with vendors, examining subsequent disbursements and reconciling independently.
Relationship to Other Evidence Attributes
Under the IIA framework, evidence must be:
- Sufficient: factual, adequate and convincing, so that a prudent, informed person would reach the same conclusion.
- Reliable: the best attainable information through appropriate engagement techniques.
- Relevant: supports engagement observations and recommendations and is consistent with the engagement objectives.
- Useful: helps the organization meet its goals.
Effective controls mainly improve reliability. They do not by themselves make evidence relevant or sufficient. Reliable evidence that does not address the audit objective is still inadequate.
Common Pitfalls
- Assuming controls are effective because they are documented in a policy manual. Design does not prove operation.
- Relying on inquiry alone to conclude that controls work.
- Ignoring ITGC weaknesses when relying on automated application controls.
- Forgetting that management override can defeat even well-designed controls.
- Treating internal evidence from a well-controlled system as automatically superior to independent external evidence. External evidence generally ranks higher.
Exam Tips: Answering Questions on Evidence from Systems with Effective Controls
1. Memorize the reliability hierarchy. Many questions ask which evidence is most or least reliable. Remember these rankings:
- External sources beat internal sources.
- Direct auditor evidence beats indirect evidence.
- Documentary evidence beats oral evidence.
- Originals beat copies.
- Internal evidence from a system with effective controls beats internal evidence from a system with weak controls.
2. Watch for the key phrase. When an option says internal evidence is more reliable "when the related internal controls are effective" or "when produced under satisfactory conditions of internal control," that is usually a correct statement.
3. Compare carefully. If a question pits an external confirmation against an internal report from a well-controlled system, the external confirmation is usually still more reliable. If both items are internal, choose the one produced under effective controls.
4. Link control effectiveness to substantive testing. Expect questions such as "If controls are found to be effective, the auditor would most likely...". The correct answer typically involves:
- reducing the extent of substantive testing;
- relying more on analytical procedures;
- testing at interim dates.
Weak controls lead to the opposite: expanded testing, larger samples and more external or direct evidence.
5. Distinguish design from operating effectiveness. A walkthrough or questionnaire shows how a control is designed. Reliance requires evidence that it operates effectively, through observation, inspection or reperformance. An option suggesting reliance based only on inquiry or a policy review is likely wrong.
6. Remember ITGCs. In IT-related questions, reliable system-generated evidence depends on effective general controls (access, change management, operations). If an option mentions weak change management or unrestricted access, the system output should not be relied on without further testing.
7. Identify the best action when controls fail. When a scenario shows that controls are not effective, the best answer usually involves:
- obtaining corroborating evidence from independent sources;
- increasing sample sizes;
- performing more direct testing;
- reporting the control deficiency.
It is not simply to accept management's data.
8. Use elimination. Discard options that:
- treat oral evidence as more reliable than documentation;
- rank copies above originals;
- claim effective controls eliminate the need for any substantive work.
Effective controls reduce substantive testing but rarely eliminate it, because of inherent limitations such as collusion and management override.
9. Read for qualifiers. Words like most, least, best, primarily and initially matter. "Most reliable" asks about the hierarchy. "First step" usually asks about gaining an understanding of controls before testing them.
10. Tie answers to the standards. When in doubt, choose the answer that ensures information is sufficient, reliable, relevant and useful (Standard 2310, or Standard 14.1 under the 2024 standards) and properly documented. These concepts are often the deciding factor between two plausible options.
Quick Practice Question
Which of the following would an internal auditor consider the most reliable evidence?
A. An oral explanation from the accounts payable supervisor.
B. A photocopy of a vendor invoice in the AP file.
C. A system-generated report from a payroll system with tested and effective controls.
D. A spreadsheet prepared by a clerk with unrestricted edit access.
Answer: C. The payroll report is documentary evidence produced under effective, tested controls. A is oral evidence, B is a copy, and D comes from an uncontrolled environment.
Summary
Evidence from systems with effective controls is more reliable because the controls reduce the risk of errors, omissions and manipulation in the data. Internal auditors must:
- understand the controls;
- test their operating effectiveness, including ITGCs;
- adjust the nature, timing and extent of substantive procedures to match;
- document their basis for reliance.
On the exam, know the reliability hierarchy, link control effectiveness to how much testing is needed, and remember that effective controls strengthen internal evidence but do not make it superior to independent external evidence.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!