COSO Framework
COSO Control Activities Design Adequacy
Scoring design adequacy before operating-effectiveness testing.
Confirming controls are well designed before testing if they work
Testing operating effectiveness on a poorly designed control wastes audit effort, because a control that cannot prevent or detect the risk will fail regardless of how diligently it is performed. COSO Principle 10 expects the entity to select and develop control activities that genuinely mitigate risks to acceptable levels, and AGSA methodology assesses design adequacy as a distinct step. AuditPro Core scores design adequacy before operating-effectiveness testing begins, so the engagement spends its testing budget only where design holds up.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Controls assessed
96
Adequately designed
71
74%
Design deficiencies
18
No control (gap)
7
uncovered risks
Design verdict by control type
Design deficiencies by type
| Control type | Assessed | Deficient | Defect % |
|---|---|---|---|
| Authorisation | 23 | 5 | 22 |
| Reconciliation | 21 | 5 | 24 |
| Verification | 20 | 6 | 30 |
| Physical | 17 | 5 | 29 |
| Supervisory | 15 | 4 | 27 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Design versus operating effectiveness
Design adequacy asks whether a control, if performed as intended, would address the risk; operating effectiveness asks whether it was actually performed that way. The two are sequential, and design must pass first.
Mapping control to risk
A well-designed control names the specific risk and assertion it addresses. Controls that cannot articulate what they mitigate are usually design failures dressed up as activity.
Preventive and detective balance
Strong design typically combines preventive controls that stop errors with detective controls that catch what slips through. Over-reliance on detection alone is a recognisable design weakness.
Testing economy
Filtering out design failures early protects scarce testing capacity. There is no value in sampling transactions through a control that was never capable of working.
How AuditPro Core Bridges the Gap
- Design scoring: each control activity carries a documented design-adequacy rating distinct from any test result.
- Risk-control mapping: controls link to the specific risks and assertions they are meant to address, exposing orphans.
- Workflow gating: controls failing design are routed to remediation before testing effort is committed.
- Traceability to source: design conclusions link to the walkthrough or documentation that supports them.
Key Takeaways
- Establish design adequacy before spending effort on operating tests.
- A control that cannot name its risk is probably badly designed.
- Balance preventive and detective controls in the design.
- Filtering design failures early protects testing capacity.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
