Back to Explore
⚠️

Internal Controls

Key Control Failures

Failures of designated key controls, ranked by potential financial impact and root cause.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why ranking key control failures matters

Key controls are those the institution relies on to prevent or detect material misstatement, so their failure carries disproportionate financial and audit consequence under the COSO and ISSAI frameworks. Ranking failures by potential financial impact and root cause directs scarce remediation effort to where it protects the most value. AuditPro Core isolates designated key-control failures and orders them by exposure so the most consequential breakdowns get attention first.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Key controls

58

Failed key controls

9

16% of key

Potential impact

R31.4m

Compensating in place

5

of 9 failures

Failures by root cause

Failed key controls

Key controlRoot causeImpact (Rm)Compensating
Three-way matchManual override9.2Yes
Bank reconciliationSkills gap6.1No
User access reviewSegregation gap5.4Yes
Journal approvalSystem config4.7No
Vendor master changeSegregation gap3.8Yes

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Key controls

A key control is one whose failure would, on its own, allow a material risk to materialise. The designation matters because not all controls warrant equal scrutiny or remediation priority.

Potential financial impact

Ranking by the value at risk if the control stays broken focuses attention on consequence rather than count. Ten minor failures may matter less than one key failure over a material balance.

Root cause analysis

Identifying why a control failed, whether design, execution or override, determines whether a fix is durable. Treating the symptom without the root cause invites recurrence.

Compensating controls

Where a key control has failed, the existence of a compensating control affects the residual exposure. Absence of any compensating control elevates the failure to a serious deficiency.

How AuditPro Core Bridges the Gap

  • Impact ranking: key-control failures are ordered by potential financial impact so remediation follows value at risk.
  • Root-cause capture: each failure records its root cause category, supporting durable rather than cosmetic fixes.
  • Compensating-control linkage: failures show whether any compensating control mitigates residual exposure.
  • Traceability to source: each failure links to the test that detected it and the control definition it breached, ready for audit review.

Key Takeaways

  • Prioritise failures by value at risk, not by count.
  • Capture root cause to ensure fixes are durable, not cosmetic.
  • Check for compensating controls before judging residual exposure.
  • Key-control failures without mitigation are serious deficiencies.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.