Back to Explore
🛡️

COSO Framework

COSO Control Activities Design Adequacy

Scoring design adequacy before operating-effectiveness testing.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Confirming controls are well designed before testing if they work

Testing operating effectiveness on a poorly designed control wastes audit effort, because a control that cannot prevent or detect the risk will fail regardless of how diligently it is performed. COSO Principle 10 expects the entity to select and develop control activities that genuinely mitigate risks to acceptable levels, and AGSA methodology assesses design adequacy as a distinct step. AuditPro Core scores design adequacy before operating-effectiveness testing begins, so the engagement spends its testing budget only where design holds up.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Controls assessed

96

Adequately designed

71

74%

Design deficiencies

18

No control (gap)

7

uncovered risks

Design verdict by control type

Design deficiencies by type

Control typeAssessedDeficientDefect %
Authorisation23522
Reconciliation21524
Verification20630
Physical17529
Supervisory15427

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Design versus operating effectiveness

Design adequacy asks whether a control, if performed as intended, would address the risk; operating effectiveness asks whether it was actually performed that way. The two are sequential, and design must pass first.

Mapping control to risk

A well-designed control names the specific risk and assertion it addresses. Controls that cannot articulate what they mitigate are usually design failures dressed up as activity.

Preventive and detective balance

Strong design typically combines preventive controls that stop errors with detective controls that catch what slips through. Over-reliance on detection alone is a recognisable design weakness.

Testing economy

Filtering out design failures early protects scarce testing capacity. There is no value in sampling transactions through a control that was never capable of working.

How AuditPro Core Bridges the Gap

  • Design scoring: each control activity carries a documented design-adequacy rating distinct from any test result.
  • Risk-control mapping: controls link to the specific risks and assertions they are meant to address, exposing orphans.
  • Workflow gating: controls failing design are routed to remediation before testing effort is committed.
  • Traceability to source: design conclusions link to the walkthrough or documentation that supports them.

Key Takeaways

  • Establish design adequacy before spending effort on operating tests.
  • A control that cannot name its risk is probably badly designed.
  • Balance preventive and detective controls in the design.
  • Filtering design failures early protects testing capacity.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.