Skip to main content
Category: Audit Process

Test of Controls

Also known as: Control Testing, Tests of Controls
Simply put

A test of controls is an audit procedure used to evaluate whether an organization's internal controls are effective. Auditors examine the relevant policies, procedures, and evidence to determine whether a control is properly designed and, where applicable, operating as intended. The results help the auditor form conclusions about how well controls address the risks they are meant to mitigate.

Formal definition

A test of controls is an audit procedure performed to obtain evidence about the effectiveness of internal controls, specifically whether a control is suitably designed and, in most engagements assessing operating effectiveness, whether it operated as intended over the relevant scope. In the context of internal control audits, the objective is to obtain evidence about the effectiveness of controls in preventing or detecting material misstatements. Tests of controls are typically distinguished from substantive testing, which addresses the accuracy of specific transactions or balances rather than the functioning of controls. The nature, timing, and extent of testing depend on the auditor's scoping decisions and the controls in scope. In a SOC 2 examination, this distinction maps to the difference between assessing suitability of design (as in a Type I) and assessing both design and operating effectiveness over a defined review period (as in a Type II), with the specific approach determined by the engagement scope.

Why it matters

Tests of controls sit at the center of any audit that relies on an organization's internal control environment. Rather than checking the accuracy of individual transactions, they evaluate whether the controls meant to prevent or detect problems are actually designed and functioning as intended. In an internal control audit, the objective is to obtain evidence about the effectiveness of controls in preventing or detecting material misstatements, so the credibility of the auditor's overall conclusion depends heavily on how rigorously these tests are performed.

For SOC 2 examinations specifically, the concept underpins the difference between a Type I and a Type II report. A Type I assesses only the suitability of design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period. When an auditor tests controls in a Type II, they are gathering the evidence that supports opinions about whether controls operated as intended across the period in scope. The length of that period and the specific approach are set by scoping decisions rather than a fixed rule.

It is important to understand the boundaries of this work. A test of controls, and any resulting SOC 2 report, attests only to the controls and the period covered by the engagement. It does not guarantee that an organization is free from breaches, nor does it address matters outside the defined scope. Because the nature, timing, and extent of testing depend on the auditor's scoping decisions, results should be read in light of what was actually in scope.

Who it's relevant to

Compliance and GRC Managers
Those preparing for a SOC 2 examination need to understand that auditors will test whether controls are designed and, in a Type II, operating effectively across the review period. This shapes how they document controls, retain evidence, and scope the engagement, since the extent of testing depends on scoping decisions.
Auditors and CPA Firms
Practitioners performing tests of controls rely on this procedure to obtain evidence about control effectiveness and to distinguish it from substantive testing. The nature, timing, and extent of their testing is a professional judgment tied to the controls and period in scope.
Security Engineers and Control Owners
The people who operate day-to-day controls, including IT general controls, are the ones whose work is examined during testing. Understanding what evidence an auditor looks for helps them maintain records that demonstrate a control operated as intended over the relevant period.
Report and Certificate Users
Stakeholders relying on a SOC 2 report should recognize that tests of controls support opinions limited to the controls and period covered by the engagement, and do not guarantee freedom from breaches or address matters outside the defined scope.

Inside Test of Controls

Test of Design
An assessment of whether a control, as designed, is suitable to meet the stated control objective or criterion if it operates as intended. In a SOC 2 examination this corresponds to evaluating suitability of design, which is the primary focus of a Type I engagement performed at a point in time.
Test of Operating Effectiveness
An assessment of whether a control operated consistently and effectively throughout a defined review period. This is central to a SOC 2 Type II examination, where the period length varies and is set by scoping decisions rather than being fixed.
Testing Procedures
The methods an auditor uses to gather evidence, which typically include inquiry, observation, inspection of documentation, and reperformance. The specific mix and depth applied depend on the auditor's judgment, the nature of the control, and the scope of the engagement.
Sampling Approach
For controls that operate repeatedly over a period, testing often relies on selecting a sample of occurrences rather than examining every instance. Sample size and selection method depend on control frequency and the auditor's approach, and results inform conclusions about operating effectiveness over the review period.
Evidence and Exceptions
The documentary or observed proof that a control was performed, along with any deviations (exceptions) identified during testing. Identified exceptions are evaluated for their impact and may be reflected in the resulting SOC 2 report or, in an ISO 27001 context, raised as findings during a certification or surveillance audit.
Application Across Frameworks
Tests of controls appear in both a SOC 2 examination (conducted by a licensed CPA firm under SSAE 18, resulting in a report) and in an ISO 27001 audit (conducted by an accredited certification body against the ISMS requirements and Annex A controls selected via the Statement of Applicability). The purpose and reporting outcome differ between the two.

Common questions

Answers to the questions practitioners most commonly ask about Test of Controls.

Does a test of controls in a SOC 2 examination guarantee that no security breaches occurred during the review period?
No. A test of controls evaluates whether the controls in scope were suitably designed and, in a Type II examination, operating effectively over the defined review period. It attests only to the controls and period covered and does not guarantee freedom from breaches. Testing typically relies on sampling and evidence available to the auditor, so the resulting report expresses reasonable assurance about the controls examined rather than a guarantee about the overall security state of the organization.
Are tests of controls the same thing in a SOC 2 examination and an ISO 27001 certification audit?
Not exactly. In a SOC 2 examination, tests of controls are performed by a licensed CPA firm under the AICPA SSAE 18 standard to support an attestation report, evaluating controls against the applicable Trust Services Criteria. In an ISO 27001 certification audit, an accredited certification body assesses the ISMS against the requirements in clauses 4 through 10 and the reference controls selected in the Statement of Applicability. While both involve examining evidence that controls function, the objective, standard, and outcome differ, so the term should not be treated as interchangeable across the two frameworks.
What types of evidence are typically examined during a test of controls?
Depending on the control and the scope, auditors typically examine evidence such as system configurations, logs, policies and procedures, tickets, records of approvals, and other documentation demonstrating that a control operated as intended. In a Type II examination, evidence is usually gathered across the review period rather than at a single point in time. The specific evidence requested depends on the control being tested and the auditor's methodology.
How does testing differ between a SOC 2 Type I and a Type II?
In a Type I, testing focuses on the suitability of the design of controls at a point in time, so the auditor typically examines whether controls are appropriately designed and in place as of a specified date. In a Type II, testing addresses both design and operating effectiveness over a defined review period, so the auditor typically examines evidence that controls operated consistently throughout that period. The length of the review period varies and is set by scoping decisions.
What common testing methods do auditors use when performing a test of controls?
Auditors typically use a combination of methods such as inquiry, observation, inspection of documentation and configurations, and reperformance, depending on the control and the assurance sought. The mix of methods and the extent of sampling depend on the auditor's judgment, the nature of the control, and the scope of the engagement, so approaches vary across engagements rather than following a single fixed rule.
What happens if a control fails during testing?
If a control does not operate as intended, the auditor may identify it as a deviation or exception, and the handling depends on the auditor's evaluation of the nature and significance of the issue and the scope of the engagement. Exceptions may be noted in the report, and in some cases the organization may need to remediate or provide additional context. Because outcomes depend on the auditor, scope, and applicable criteria, the treatment of a failed control varies from engagement to engagement.

Common misconceptions

A test of controls guarantees that no security breach can occur.
Testing attests only to the controls and, where applicable, the period covered by the engagement. A SOC 2 report does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS. Testing provides assurance about design and, in some cases, operating effectiveness, not an absolute assurance of security.
Testing for a SOC 2 report and testing for ISO 27001 certification are interchangeable and satisfying one covers the other.
The two frameworks are distinct: SOC 2 is an attestation examination resulting in a report, while ISO 27001 is a certification against a management system standard. Mapping between them is possible but partial, and testing performed for one does not automatically satisfy the requirements of the other.
A test of operating effectiveness is performed at a single point in time, like a test of design.
A test of design evaluates suitability at a point in time (the focus of a SOC 2 Type I), whereas a test of operating effectiveness evaluates whether controls operated consistently over a defined review period (the focus of a SOC 2 Type II). The period length varies based on scoping decisions.

Best practices

Clarify at the outset whether the engagement requires testing of design only or also operating effectiveness, since this distinguishes a SOC 2 Type I from a Type II and shapes the evidence you must retain.
Maintain contemporaneous evidence of control performance throughout the review period so that operating effectiveness can be demonstrated for sampled occurrences rather than reconstructed after the fact.
Align controls with the applicable criteria before testing begins; for SOC 2 confirm which Trust Services Criteria categories are in scope, and for ISO 27001 confirm which Annex A controls were selected via the Statement of Applicability.
Understand the auditor's sampling approach and control frequency expectations early, so populations are complete and samples can be supported with adequate evidence.
Track and remediate identified exceptions promptly, documenting root cause and corrective action, since exceptions may be reflected in the resulting report or raised as audit findings.
Define and document the scope precisely, recognizing that a SOC 2 report attests only to the controls and period covered and an ISO 27001 certificate covers only the defined ISMS scope.