Internal Controls
Key Control Failures
Failures of designated key controls, ranked by potential financial impact and root cause.
Why ranking key control failures matters
Key controls are those the institution relies on to prevent or detect material misstatement, so their failure carries disproportionate financial and audit consequence under the COSO and ISSAI frameworks. Ranking failures by potential financial impact and root cause directs scarce remediation effort to where it protects the most value. AuditPro Core isolates designated key-control failures and orders them by exposure so the most consequential breakdowns get attention first.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Key controls
58
Failed key controls
9
16% of key
Potential impact
R31.4m
Compensating in place
5
of 9 failures
Failures by root cause
Failed key controls
| Key control | Root cause | Impact (Rm) | Compensating |
|---|---|---|---|
| Three-way match | Manual override | 9.2 | Yes |
| Bank reconciliation | Skills gap | 6.1 | No |
| User access review | Segregation gap | 5.4 | Yes |
| Journal approval | System config | 4.7 | No |
| Vendor master change | Segregation gap | 3.8 | Yes |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Key controls
A key control is one whose failure would, on its own, allow a material risk to materialise. The designation matters because not all controls warrant equal scrutiny or remediation priority.
Potential financial impact
Ranking by the value at risk if the control stays broken focuses attention on consequence rather than count. Ten minor failures may matter less than one key failure over a material balance.
Root cause analysis
Identifying why a control failed, whether design, execution or override, determines whether a fix is durable. Treating the symptom without the root cause invites recurrence.
Compensating controls
Where a key control has failed, the existence of a compensating control affects the residual exposure. Absence of any compensating control elevates the failure to a serious deficiency.
How AuditPro Core Bridges the Gap
- Impact ranking: key-control failures are ordered by potential financial impact so remediation follows value at risk.
- Root-cause capture: each failure records its root cause category, supporting durable rather than cosmetic fixes.
- Compensating-control linkage: failures show whether any compensating control mitigates residual exposure.
- Traceability to source: each failure links to the test that detected it and the control definition it breached, ready for audit review.
Key Takeaways
- Prioritise failures by value at risk, not by count.
- Capture root cause to ensure fixes are durable, not cosmetic.
- Check for compensating controls before judging residual exposure.
- Key-control failures without mitigation are serious deficiencies.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
