Auditing Internal Controls: Preventive vs Detective Controls
Distinguish preventive and detective controls for AUD with timing rules, process examples, a worked scenario, and clear audit-procedure boundaries.
Quick answer
Preventive controls act before or during processing to stop an error or unauthorized action. Detective controls operate after processing to identify what slipped through so it can be investigated and corrected. "Preventative" is a common search spelling, but "preventive" is the usual control term. Classification depends on when and how the control operates, not whether it is manual or automated.
Preventative vs detective controls: decide by timing
Ask one question first: does the control block the problem before it affects the process, or identify the problem after it occurs? That timing test is more reliable than memorizing lists because the same technology can perform either role under different configurations.
This page owns the control-timing distinction. The full five-component framework remains with the COSO framework guide, while AUD audit procedures owns how an auditor tests a control and responds to risk.
Worked control chain: one payment, three control roles
- 1An employee enters a vendor payment without the required approval. The payment system refuses submission until an authorized approver acts. The block operates before posting, so it is preventive.
- 2Assume an emergency override instead permits the payment to post. A daily exception report identifies the override and routes it to a supervisor. The report and review are detective because they identify an event that already occurred.
- 3The supervisor inspects the support, reverses an improper payment, removes inappropriate access, and records the disposition. Those actions correct and respond to the detected issue; they do not change the earlier report into a preventive control.
- 4For an AUD question, name the risk, place each action on the transaction timeline, identify the evidence retained, and keep the client control classification separate from the auditor's test of controls.
- 1Unapproved payment enteredThe risk is an unauthorized payment entering the disbursement process.
- 2Approval block operatesThe system refuses submission before posting, so the action is preventive.
- 3Emergency override postsThe transaction occurs despite the normal preventive rule.
- 4Exception report is reviewedThe completed override is identified after posting, so the review is detective.
- 5Supervisor resolves the exceptionInvestigation, reversal, access change, and documented disposition respond to the finding.
Practice the CPA topics covered on this page
Practice CPA exam questions and use your results to find the topics that need more work.
Find My Weak AreasSeparate design, implementation, and operating effectiveness
A well-worded control description does not establish that the control works. Design asks whether the control, if operated as described, can prevent or detect the stated misstatement on a timely basis. Implementation asks whether the control was placed in operation. Operating effectiveness asks whether it operated as designed, consistently, and by people with the necessary authority and competence.
Suppose a policy requires independent approval before a vendor is activated. The control may be preventive by design. If the system allows activation without evidence of approval, implementation may not match the design. If approval exists for some vendors but not throughout the period, operating effectiveness may be deficient even though the policy and system configuration appear sound.
A detective control also needs a sufficiently precise review. A manager who signs a monthly variance report without thresholds, investigation criteria, or evidence of follow-up may not detect a material error. The signature proves that a mark exists, not that the review could identify the risk at the required level.
Keep these questions distinct on AUD. First classify the control by timing and objective. Then evaluate design and implementation. Finally decide what evidence would support a conclusion about operation during the relevant period.
| Question | What to establish | Illustrative evidence | Failure signal |
|---|---|---|---|
| Design | Could the control prevent or detect the stated misstatement on a timely basis? | Defined risk, rule, owner, precision, frequency, evidence, and exception response | The described action cannot address the risk at the required level |
| Implementation | Was the designed control actually placed in operation? | Configured approval rule, observed process, or completed control instance | Policy exists, but the system or people do not perform it as described |
| Operating effectiveness | Did the control operate consistently, as designed, by authorized and competent people? | Period evidence, retained review support, deviations, and resolved exceptions | Operation is inconsistent, imprecise, unsupported, or missing during the period |
Classify common control pairs by timing
| Process and risk | Control action | Timing and type | Evidence retained |
|---|---|---|---|
| Purchasing: unapproved order | System blocks the purchase order without approval | Before posting: preventive | Approval record and blocked-transaction log |
| Cash: unauthorized release | Dual authorization is required before payment release | Before release: preventive | Two authorized approvals linked to the payment |
| Access: inappropriate activity | Reviewer investigates completed access-log exceptions | After activity: detective | Dated review, investigated items, and disposition |
| Payroll: unusual payment | Reviewer investigates a variance report after the payroll run | After processing: detective | Report, threshold, reviewer sign-off, support, and follow-up |
Control type is different from audit procedure
Preventive and detective describe what the client control is designed to do. Inquiry, observation, inspection, and reperformance describe ways an auditor may obtain evidence about the control. Calling a client review "detective" does not tell you which audit procedure is sufficient.
Inquiry can explain who performs a control and what happens when an exception appears, but the auditor still evaluates other evidence appropriate to the objective. Inspection might show a dated review, observation might show the process at one point in time, and reperformance might test whether the control logic reaches the expected result.
When the evidence is captured in a schedule or workpaper, use audit documentation guidance to distinguish a PBC label, a workpaper mark, and the conclusion that the evidence actually supports.
Frequency, precision, and exception follow-up
Frequency affects both prevention and detection. An automated block may operate on every transaction, while a detective reconciliation may operate daily, monthly, or quarterly. The relevant question is whether the frequency is timely enough for the risk and reporting objective, not whether one category is automatically stronger.
Precision describes how closely the control can identify a meaningful error. A high-level annual budget comparison may not detect a misstatement hidden within one account. A review using disaggregated data, defined thresholds, reliable inputs, and documented investigation can be more precise, but its design still must fit the stated risk.
Exception follow-up is part of understanding whether a detective control achieves its objective. An exception report that nobody reviews is only information. A review that identifies an exception but has no investigation or escalation path may leave the underlying risk unresolved.
When evaluating evidence, trace one exception through the entire process: generation, review, investigation, supporting evidence, correction or accepted disposition, and approval. This prevents the common mistake of treating the presence of a report as proof that the control operated effectively.
Integrated audits and ICFR: identify the authority
An integrated audit combines an audit of financial statements with a separate audit of internal control over financial reporting, or ICFR. The internal-control conclusion does not replace the financial statement opinion, and a control deficiency does not automatically mean the financial statements are materially misstated.
For a nonissuer integrated audit performed under AICPA standards, AU-C Section 940 supplies the ICFR reporting framework. It applies when the auditor is engaged to audit nonissuer ICFR together with the financial statements; it does not make an integrated audit mandatory for every private company. PCAOB AS 2201 governs the corresponding issuer integrated-audit context.
In either context, connect the control objective, design and implementation, operating-effectiveness evidence, identified deficiencies, and separate reporting conclusion. Do not transfer issuer report wording to a nonissuer question or assume that evidence supporting the financial statement audit alone is enough for an ICFR opinion.
Exceptions that change the classification
A system edit that blocks an invalid transaction is preventive. If the same edit only flags the transaction after posting, it is detective.
A reconciliation is generally detective because it compares recorded activity after processing. A separate approval required before a reconciling adjustment posts is preventive for that adjustment.
Segregation of duties usually prevents one person from completing incompatible steps. A manager's later review of a combined-role report detects a conflict that already occurred.
A dashboard is not automatically a control. Someone must use sufficiently precise information, investigate exceptions, and take the designed action for the review to operate as intended.
A repeatable internal-control question sequence
- Name the risk and the financial statement assertion or engagement objective affected.
- Describe the control as an action with an owner, timing, input, threshold or rule, evidence, and response to exceptions.
- Classify it as preventive, detective, or a combination based on when each action operates.
- Separate whether the control is suitably designed and implemented from whether it operated effectively during the relevant period.
- Choose an audit procedure that tests the feature in question instead of assuming the control label dictates the procedure.
- Connect deviations and compensating controls to the revised risk assessment, additional work, communication, and reporting consequence.
Source boundary and AUD practice sequence
The 2026 AICPA Blueprint owns current exam scope. The AICPA standards toolkit is the source path for AU-C Section 940 and nonissuer integrated-audit guidance. PCAOB AS 2201 supplies issuer integrated-audit context, and the AICPA-CIMA COSO resource supplies the broader internal-control framework. The process examples here are CPAPass illustrative study scenarios, not official Blueprint tasks and not a substitute for engagement-specific standards.
Use the AUD section guide for the full risk-to-evidence-to-conclusion sequence. Then try free AUD practice and explain why each control is preventive or detective before choosing how the auditor should test it.
Frequently asked questions
What is the difference between preventative and detective controls?
A preventive control blocks or reduces the chance of an error before or during processing. A detective control identifies an error after it occurs so it can be investigated and corrected. "Preventative" and "preventive" refer to the same category in this context.
Is a bank reconciliation preventive or detective?
A bank reconciliation is generally detective because it identifies differences after transactions have been recorded. A separate approval that blocks an unsupported reconciling adjustment can be preventive for that later step.
Is an automated control always preventive?
No. An automated rule that blocks an invalid entry is preventive, while an automated report that flags the entry after posting is detective. Timing and designed operation control the classification.
How do preventive and detective controls fit into COSO?
They are useful ways to describe control activities by timing and purpose. Use the COSO framework guide for the five components and broader framework instead of treating this two-category distinction as the entire COSO model.
Sources
- 2026 Uniform CPA Examination Blueprints (retrieved 2026-08-11)
- AICPA accounting and auditing standards toolkit (retrieved 2026-08-11)
- PCAOB AS 2201: An Audit of Internal Control Over Financial Reporting (retrieved 2026-08-11)
- AICPA-CIMA: COSO Internal Control - Integrated Framework (retrieved 2026-08-11)
- PCAOB AS 1105: Audit Evidence (retrieved 2026-08-11)