Test of Controls
A test of controls is an audit procedure used to evaluate whether an organization's internal controls are effective. Auditors examine the relevant policies, procedures, and evidence to determine whether a control is properly designed and, where applicable, operating as intended. The results help the auditor form conclusions about how well controls address the risks they are meant to mitigate.
A test of controls is an audit procedure performed to obtain evidence about the effectiveness of internal controls, specifically whether a control is suitably designed and, in most engagements assessing operating effectiveness, whether it operated as intended over the relevant scope. In the context of internal control audits, the objective is to obtain evidence about the effectiveness of controls in preventing or detecting material misstatements. Tests of controls are typically distinguished from substantive testing, which addresses the accuracy of specific transactions or balances rather than the functioning of controls. The nature, timing, and extent of testing depend on the auditor's scoping decisions and the controls in scope. In a SOC 2 examination, this distinction maps to the difference between assessing suitability of design (as in a Type I) and assessing both design and operating effectiveness over a defined review period (as in a Type II), with the specific approach determined by the engagement scope.
Why it matters
Tests of controls sit at the center of any audit that relies on an organization's internal control environment. Rather than checking the accuracy of individual transactions, they evaluate whether the controls meant to prevent or detect problems are actually designed and functioning as intended. In an internal control audit, the objective is to obtain evidence about the effectiveness of controls in preventing or detecting material misstatements, so the credibility of the auditor's overall conclusion depends heavily on how rigorously these tests are performed.
For SOC 2 examinations specifically, the concept underpins the difference between a Type I and a Type II report. A Type I assesses only the suitability of design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period. When an auditor tests controls in a Type II, they are gathering the evidence that supports opinions about whether controls operated as intended across the period in scope. The length of that period and the specific approach are set by scoping decisions rather than a fixed rule.
It is important to understand the boundaries of this work. A test of controls, and any resulting SOC 2 report, attests only to the controls and the period covered by the engagement. It does not guarantee that an organization is free from breaches, nor does it address matters outside the defined scope. Because the nature, timing, and extent of testing depend on the auditor's scoping decisions, results should be read in light of what was actually in scope.
Who it's relevant to
Inside Test of Controls
Common questions
Answers to the questions practitioners most commonly ask about Test of Controls.