Control Assurance: Independent Confirmation That Controls Work
Control assurance is an independent confirmation that a stated control was designed to meet a stated objective and operated as stated throughout a stated period. The confirmation is given by somebody who does not run the control, rests on evidence rather than opinion, and ends in a written conclusion with a name at the bottom. Assurance never makes a control work. Assurance tests whether the claim that a control works survives.
One distinction carries this whole guide, and it is worth reading twice. A controlSomething an institution does on purpose so that a specific thing does not go wrong. is a thing somebody does. A rating is somebody's opinion of whether that thing works. Control assurance is a test of the rating, not a second opinion about the control. Once assurance is seen to take a claim as its subject rather than the work itself, every other rule in this guide stops being a rule to be remembered and becomes something that could have been worked out: why the person giving it cannot be the person making the claim, why it needs evidence and a sample rather than a conversation, and why it can only ever speak about a stretch of time that has already ended.
What does control assurance actually take as its subject?
Start with a shop on a busy street. The shape is identical and the words are easier. The shutter has to be locked every night. The locking is the control. The owner says, when asked, that it is locked every night without fail, and that statement is a rating: an opinion about the control, offered by the person responsible for it. Now imagine the insurer asks a third person to go and look at the closing register and the camera recording for a stretch of nights chosen at random. The third person is not checking the shutter. The third person is checking the sentence the owner said about the shutter. Everything else follows from that one move.
The move is easy to miss because both things end up as words on paper. The owner's sentence and the third person's sentence read almost identically, and a reader who sees only the output cannot tell which is which. The confusion is not a failure of attention. The confusion is the structural problem the whole practice exists to solve, and it is why the discipline attaches so much weight to who wrote a sentence and on what basis, rather than to how confident the sentence sounds.
Inside Vindhya Commercial Bank Limited, an invented bank of Rs 96,000 crore whose figures are illustrative throughout, the same three objects are stacked in the same order across nine named processesA named sequence of work with a start, an end and an owner, here numbered PR1 to PR9.. Somebody in the business reconciles the collateral valuation feed before the loan book is marked. The reconciliation is the control. The business then records, in its own annual self assessmentThe exercise in which the people who run a set of controls rate those same controls themselves, on their own cycle., that the control operated effectively. The record is the rating. Somebody in a different reporting line then pulls the evidence for a set of days and tests whether that record survives. The test is the assurance work. All three exist at once, all three produce a sentence, and only the third one has been tested by anybody who could afford to say no.
The distinction rules out a great deal immediately. Assurance does not touch the control, so it cannot fix anything. Assurance cannot make a weak control strong, cannot shorten a queue, cannot stop a feed going stale. Expecting assurance to improve an institution directly means it has quietly been confused with the control itself. Assurance can change what the institution believes about itself. The change is a slower and stranger kind of usefulness, and it is the only kind on offer.
What four things does an assurance conclusion always name?
An assurance conclusion is a paragraph, not a score, and the paragraph has four fixed parts. The paragraph names the control exactly. The second part is the objective the control exists to meet. The third is the period over which the control is said to have operated. The fourth is the evidence the conclusion rests on. A statement missing any one of those four parts is a description of an intention rather than a confirmation of anything, and it cannot be relied on for a decision.
Each part earns its place by what goes wrong without it. Without the control named exactly, nobody can tell later which of the 214 things at this bank was tested, and two people reading the same conclusion can walk away believing different work was done. Without the objective, there is no judging whether the control was the right control at all: a signature collected reliably every day is worthless if the thing it was meant to prevent could happen anyway. Without the period, effective means nothing. A control can be flawless on the day somebody visits and absent for the eleven working days before it. Without the evidence, the sentence is an assertion by a second person rather than the first. A change of author is not a change of instrument.
The four parts are also what makes a conclusion checkable by somebody who was not involved. A person handed the left hand paragraph can go and ask for the working papers, count the days in the sample, notice that the sample never touched month 10, and form their own view of whether the conclusion is strong. A person handed the right hand paragraph has nothing to pull on. Assurance is only useful to the extent that a stranger can interrogate it, and the four parts are exactly the handles a stranger needs. Writing rather than speaking follows from the same requirement: a sentence that has to survive a stranger reading it in six months has to be fixed in place first.
A conclusion reads, in full: the collateral valuation control is operating effectively. What is missing?
Who are the three lines, and whose model is that?
Almost everybody organises this with the three linesThe Institute of Internal Auditors' 2020 description of who takes risk, who challenges it and who independently confirms it. model. The model belongs to the Institute of Internal Auditors, restated by them in 2020. A reader who does not know whose idea it is cannot go and read the original, so the attribution is part of the term and belongs in the sentence that uses it. The three lines model is a description of an arrangement rather than a rule imposed by anybody. No supervisor obliges an institution to draw itself in exactly three layers, and institutions that do not still have to answer the same question about who confirms what.
Inside Vindhya Commercial Bank Limited the three jobs sit like this. The first line is the business itself, taking the risk and running the 214 key controls day to day, and it is also the line that rates those controls in its own self assessment. The second line is the risk and compliance function under Sunanda Ravikumar. The function sets the nine policies PL1 to PL9 and challenges how the first line goes about its work. The third line is internal audit under Rustom Batliwala. Internal audit reports to committee G3, the audit committee, and confirms the first line and the second. The third line exists for one reason: neither of the first two can confirm itself, and the arrangement is built to make that impossibility visible rather than to imply that anybody is untrustworthy.
One warning about the picture. Three lines is a description of jobs, not of job titles, and an institution can have all three jobs done properly with two departments or badly with five. The model gives a question to ask of any arrangement: for a given stretch of work, who does it, who challenges it, and who confirms it from somewhere the first two cannot reach. If two of those three answers are the same name, that is the thing worth looking at, and no organisation chart will say so.
Whose description is the three lines model, and when was it restated?
Why is a team rating its own control not assurance?
The next sentence is easy to hear as an insult. Read it carefully. A team rating its own control produces a rating, and a rating is not a confirmation, and none of that is an accusation that anybody lied. Consider a person counting their own steps on a walk. There is no cheating, and the number is genuinely believed. The walker also chose when to start counting, decided what counts as a step, and would be the one who has to explain a number that came out badly. Nothing about that requires bad faith to produce a number that leans one way.
Each of the three structural reasons survives even when everybody involved is careful and honest, so each is worth naming separately. First, the rater chose the scope: normal days, one-off exceptions, gaps already fixed. Every one of those calls was theirs. Second, the rater carries the consequence: a rating of not effective becomes a findingA written record that a tested control did not do what was claimed for it. against their own work, and a person who has to live with an answer is not the ideal person to reach it. Third, the rater has no separate evidence trail: they know what usually happens. Knowing what usually happens is a different and weaker thing than a record of what did happen on named days.
The two percentages carry a trap under them that has caught careful readers before. The independent work at this invented bank tested design on all 214 controls and then tested operation only on the 198 that survived the design test, finding 172 of those 198 effective. Quoting that as 86.9 per cent and setting it beside the business's 91.6 per cent is tempting, and it would make the gap look like a rounding difference. The two figures sit on different denominators and putting them side by side is simply wrong. Stated like for like, both on the full population of 214 key controls, it is 91.6 per cent against 80.4 per cent, and the honest gap is 11.2 percentage points rather than the comfortable 4.7 the mismatched pair suggests.
A team rates its own control effective, writes down the evidence it looked at, and has its manager sign the rating. Is that assurance?
What does independent mean here, and how independent is enough?
IndependenceA property of the person giving assurance: they do not run the control, do not report to whoever does, and cannot have their conclusion edited by them. is a property of a person and their reporting arrangements, not a property of a method. Independence read this way is the most useful idea available for judging a real institution. The reading turns a vague word into three questions that can be asked out loud and answered. Do they run the control themselves? Do they report to whoever does? Can that person edit the conclusion before it goes anywhere? Any one yes turns the output back into a rating, however careful the testing that produced it was.
Watch how sharply the third question bites. Somebody can sit in a completely separate function, gather beautiful evidence, and reach a hard conclusion, and then hand a draft to the head of the business who then asks for the wording to be softened before it goes to a committee. The testing was independent. The conclusion is not: the person it was about edited it. The editing is why an internal audit function's reporting route to committee G3 matters more than the seating plan: the route is what makes the last question answerable with a no.
How independent is enough, then? Enough is when all three answers are no for the specific conclusion in question, and the honest answer is that this is a threshold rather than a scale. There is no such thing as slightly independent for the purpose of relying on a sentence. The weight a conclusion carries once it clears the threshold does vary, and vary a lot, and the weight depends on the evidence and the sample rather than on the person. Independence is what makes a conclusion admissible; the evidence is what makes it strong.
Is a control the whole of internal control?
No, and the reason is worth twenty seconds because it bounds what any amount of control assurance can be worth. The five component structure of internal control belongs to the Committee of Sponsoring Organizations of the Treadway Commission, published in 1992 and updated in 2013, and control activities are one of those five components. The others describe the environment people work in, how the institution decides what could go wrong, how information moves and how anybody keeps watch over the whole arrangement.
The practical consequence is a limit rather than a definition. When somebody at this invented bank tests the 214 key controls and reaches a conclusion, they have tested one component of five. Four fifths of what the structure describes was never on the test sheet, so an institution can pass every control activity test and still have a weak internal control system. None of that is a criticism of control testing. The limit is the reason a conclusion about controls is always narrower than the sentence people would like to read out of it, and why an audit committee that hears a control conclusion and relaxes about internal control generally has quietly widened the claim.
Attribution here is not decoration either. Anyone can go and read the original structure, and a reader who is only ever told about five components without being told whose five they are has been handed a piece of furniture instead of an idea they can check.
What is a key control, and who decided that 214 of them are key?
A key controlA control the institution has decided it would notice the absence of, so the one it tests. is not a special kind of control. A key control is an ordinary control that somebody put on a list. There was never going to be enough time, money or attention to test everything anybody does. Vindhya Commercial Bank Limited runs 214 of them across nine named processes, PR1 to PR9, from account opening at one end through to financial reporting and close at the other. The number 214 is a decision, not a measurement. Nobody discovered that 214 controls were key. Somebody, at some point before any evidence existed, drew a line.
Consider a household with one salary coming in. There are dozens of small habits keeping the month intact: checking the balance before a big purchase, keeping the rent transfer on a standing instruction, keeping a buffer nobody touches. Naming the three whose absence would be noticed within a week is easily done, and those three are the household's key controls. The other habits still matter. The remaining habits are simply not the ones to watch when only three can be watched. The word key does not mean important. The word means chosen, and chosen before anybody looked.
Read downward, the bars show the population shrinking twice, for two different reasons. Design was tested on all 214 controls and 198 passed, so 16 carried a design gap: they would not have met their objective even if somebody performed them perfectly every single day. Operation was then tested on the 198 that survived, and 172 passed, so 26 controls were well designed and did not happen reliably. End to end, 172 of the 214 key controls were effective, or 80.4 per cent, and the 42 that were not are exactly the 16 design gaps plus the 26 operating failures. The two shortfalls need completely different repairs: a design gap is fixed by changing the control, an operating failure by making the control actually happen.
Now look back at the top bar, the one with no number on it. The record at this invented bank does not say how many things people do in total, so nobody can state what share of the real population the 214 represents. The missing number is not sloppiness in the example, it is the ordinary condition. Every assurance conclusion is bounded by a choice of population that was made before any evidence existed, and the choice is almost never quoted alongside the result. When somebody states that 80.4 per cent of controls were effective, the useful follow up is not about the 80.4. The follow up is: effective out of what, and who picked it.
Why does an institution call 214 controls key rather than testing everything people do?
Independent testing at this invented bank raised 42 findings. The business had already said 18 controls were not working. Before the arithmetic: can the second number explain away the first?
What did the two readings of this bank's year actually produce?
Two readings of one year exist inside Vindhya Commercial Bank Limited, and both of them are honest. The first is the business's own. Its self assessment covered all 214 key controls and rated 196 of them effective, or 91.6 per cent, leaving 18 that the business itself said were not working. The second is independent. Testing produced 42 findings, being the 16 design gaps and the 26 operating failures already met above, one finding written per failed control.
| What was read | Who produced it | Result | On 214 controls |
|---|---|---|---|
| The self assessment | The first line, rating its own controls | 196 rated effective, 18 rated not effective | 91.6 per cent |
| Independent testing, design | Testers outside the first line | 198 designed effectively, 16 design gaps | 92.5 per cent |
| Independent testing, operation | Testers outside the first line, on the 198 that passed design | 172 operated effectively, 26 operating failures | 80.4 per cent |
| The 42 findings | Independent testing | 16 design gaps plus 26 operating failures | 19.6 per cent |
Held up together, the two readings leave something missing. The bank's record does not say how many of the 18 controls the business flagged are among the 42 findings that testing raised. Nobody measured the overlap. The record does not need to: the overlap is bounded by arithmetic rather than by evidence. 196 controls rated effective plus 42 findings is 238. There are only 214 controls in the population. So at least 238 less 214, being 24 findings, must sit on controls the business had rated effective, no matter how the unmeasured overlap turns out.
Look at the same number from the other direction and it lands in the same place. The business rated 196 controls effective and independent testing found 172 effective, and 196 less 172 is 24. The floor of 24 findings on controls rated effective and the like for like gap of 24 controls between the two readings are one fact reached by two routes, not two findings that happen to agree. As a share, those 24 findings are 11.2 per cent of the 214 key controls. The same 11.2 percentage points separate 91.6 per cent from 80.4 per cent. The arithmetic keeps closing on itself. Closing on itself is a good sign that nothing has been smuggled in.
State the result carefully. The careful version is stronger than the dramatic one. The floor is not a claim that the business was wrong about 24 controls in some blameworthy way, and it is not an estimate of how much the business did not know. The floor is measured: at least 24 findings, and possibly as many as all 42, fell on ground the business believed was solid. Unlike an estimate, a floor carries no assumption anybody can dispute it away with, so a floor is the most useful thing an argument can put in front of a committee.
The business rated 196 of 214 controls effective and independent testing raised 42 findings. Before moving the control below: what is the smallest number of findings that could possibly be news to the business?
Try to push the count of new findings below 24 by moving the unmeasured overlap
One variable moves: k, how many of the 18 controls the business itself rated not effective also carry one of the 42 findings. Everything else is held: 214 controls, 196 rated effective, 42 findings, one finding per failed control. The overlap k was never measured at this invented bank and appears nowhere in its record. The absence of k is the entire reason the control is here. Drag it as far as it will go and watch where the block stops.
Reading the self assessment result as the assurance result
Both numbers are a percentage of controls working. Both arrive in the same committee paper, in the same month, set in the same typeface. One of them is 91.6 per cent and the other is 80.4 per cent. The one that travels is 91.6 per cent: it is the biggest, it is ready earliest, and it is the most comfortable thing anybody in the room could say out loud. The travelling figure is also the only one of the two that nobody outside the work ever tested.
The cost is exact and it is the floor established above. At least 24 of the 42 findings sat on controls inside that 91.6 per cent, so the figure that reads as reassurance is precisely the figure concealing the findings. Committee G3, the audit committee, receives the findings and the year's assessment. The committee is not given a reason to ask which of two numbers in front of it was produced by the people being reported on.
Nobody falsified anything, and that matters for how the situation should be handled. The business rated what it believed, and belief is not the same instrument as evidence. The failure is not in the 91.6 per cent at all. The failure is in a committee receiving one number where two exist, with nothing in front of it to say which one was tested and which one was asserted.
The audit committee receives one figure: 91.6 per cent of controls effective. What should it ask first?
Where do the expectations on an Indian bank and an Indian board come from?
Everything so far is jurisdiction free. Nothing about testing a claim on evidence is Indian, and an institution anywhere would recognise the four parts of a conclusion and the three questions about independence. The duty is not jurisdiction free: who is obliged to report on internal control, to whom, in what form, and with what independent opinion attached. The duty comes from a statute and from professional standards.
A section number, a threshold, an applicability test or an effective date is exactly the kind of thing that changes, and a statement carrying one becomes wrong quietly, without anybody noticing that it has. Naming a body and a duty stays true. Knowing where to look is also a skill that survives the next amendment. A remembered fact does not.
Where the borrowed models come from, and where an Indian institution's duties sit
The three lines used in this guide are the model of the Institute of Internal Auditors, restated by them in 2020, and the attribution belongs in the sentence that uses it rather than in a footnote at the bottom. The five component structure of internal control belongs to the Committee of Sponsoring Organizations of the Treadway Commission, published in 1992 and updated in 2013, and the same rule applies to it. Neither is a rule anywhere. Both are descriptions that institutions and their supervisors found useful enough to keep using.
The set of duties an Indian company and an Indian bank carry is not jurisdiction free. The Companies Act places a reporting duty on the board and on the auditor in respect of internal financial controls, and the text of it, who it applies to, who is exempt and the form the report takes all sit with the Ministry of Corporate Affairs at mca.gov.in. The assurance standard and the guidance note that govern how work of this kind is performed and reported sit with the Institute of Chartered Accountants of India at icai.org. The additional rules binding a bank, including its risk management arrangements and the standing of its internal audit function, sit with the Reserve Bank of India at rbi.org.in.
Section numbers, rule numbers, thresholds, applicability tests, exemptions, ratios, sampling minimums and effective dates all change by amendment, and none of them should be carried away from a worked illustration. The current text sits with the bodies named above and has to be read there.
Which body holds the text of the Indian reporting duty on internal financial controls?
What can control assurance never tell?
Three limits sit inside every assurance conclusion ever written, and none of them is a defect. The three limits are the instrument itself. An assurance conclusion is a statement about a stretch of time that has already closed, reached from a sample rather than from everything, by somebody who was not standing there while the work happened. Read that sentence slowly. Each of its three clauses removes a different thing people want the conclusion to give them.
Take the period first. A conclusion that 172 of the 214 key controls at this invented bank operated effectively describes a year that has ended. The conclusion is in the past tense on purpose. Nothing in it is a statement about this morning, and a control that was effective through twelve months can stop working on the first day of the thirteenth without making the conclusion wrong. The collateral valuation control in process PR3 sits inside that same population of 214 and then failed for 11 working days in month 10, with no monitoring control noticing. The two facts are exactly the shape of the problem: the conclusion and the failure are not in contradiction, they are answers to different questions.
Take the sample next. Testing looks at named days and named items, not at every occurrence. Looking at every occurrence would cost more than the control is worth. The trade is sensible and it has a price: a clean sample is consistent with a control that fails sometimes, and the rarer the failure the larger the sample would have to be before a clean result meant much. The third limit is the one people forget. The tester was not there. The tester is reading records made by other people, and a record is a claim too. Assurance reduces how much is taken on trust, and it never gets that quantity to zero.
There is one more thing assurance cannot tell, and it is the quietest of the four. Assurance cannot speak to anything outside the population somebody chose. Nothing beyond the 214 key controls was on the sheet, so nothing beyond them was ever going to appear in a finding, however badly it was working. A conclusion is bounded above by the evidence and bounded below by a decision taken before any evidence existed, and only one of those two bounds is ever printed alongside the result.
Internal audit concludes that 172 of 214 key controls operated effectively last year. What does that establish about this morning?
How does somebody outside an institution ever use this?
Most readers will never test a control. Readers will read conclusions that other people reached, and that is where the habit below pays for itself. Somebody lending to a business, analysing one, sitting on a board of a small company or simply choosing where to put a deposit is constantly handed sentences of the form the control is working. The single most useful habit available is to ask two things of any such sentence: which of the four parts it actually names, then which of the three independence questions its author would have to answer no to.
The habit is easiest to practise on small claims, where the shape is identical and the stakes are low. A landlord says the building's fire equipment is checked. Which equipment, checked against what standard, over what period, and evidenced how, and is the person making the claim the person who does the checking? A supplier says its quality process is reliable. A school says its transport arrangements are safe. In every case, four parts and three questions. In most cases the sentence names one part and answers yes to at least one question, and that fixes exactly how much weight it can carry.
Now scale it up. Somebody reading Vindhya Commercial Bank Limited from outside, with its Rs 96,000 crore of assets, will see a statement that internal controls were effective and will be tempted to treat it as a summary of how well run the institution is. It is not. The statement is a past tense conclusion, on a sample, over a chosen population of 214 controls, about one of the five components of internal control. The right response to a control conclusion is not more confidence or less confidence, it is a sharper question: effective over what period, out of what population, tested by whom, and who could have edited the answer. Four questions, thirty seconds, and they work on a bank, a supplier and a landlord in exactly the same way.
One habit is worth taking away above all others. When two figures about the same thing arrive together, ask which one somebody tested before asking which one to believe. At this bank the two figures were 91.6 per cent and 80.4 per cent, and the difference between them was not accuracy. The difference was authorship.
Sources
| Source | Document | Site |
|---|---|---|
| Ministry of Corporate Affairs | The Companies Act duty on internal financial controls: the text, who it applies to, who is exempt, and the form the report takes | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance standard and the guidance note behind independent work on controls, including how sufficiency of evidence is framed | icai.org |
| Reserve Bank of India | What binds a bank in India on internal control, risk management arrangements and the standing of the internal audit function | rbi.org.in |
Vindhya Commercial Bank Limited, Sunanda Ravikumar and Rustom Batliwala are invented.
Educational material. Not advice on any investment, tax, budget or market position.
