Back to Explore
⚠️

Internal Controls

Preventive vs Detective Control Mix

Balance between preventive and detective controls across key financial and operational cycles.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why control balance shapes residual risk

A control environment weighted entirely toward detection catches errors only after they have happened, while one relying solely on prevention has no safety net when a control is bypassed. A healthy balance across financial and operational cycles is what keeps residual risk genuinely low, a balance the audit committee should be able to see. AuditPro Core shows the preventive-to-detective mix across key cycles so gaps in either layer are obvious.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Total controls

312

Preventive

58%

▲ 4%

Detective

42%

Automated

37%

▲ 6%

Control mix by cycle

Control mix detail

CyclePreventiveDetectivePrev %
Revenue281960
Expenditure412760
Payroll221461
Supply chain312654
Assets191851

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Preventive controls

Preventive controls stop an error or irregularity before it occurs, such as authorisation limits and segregation of duties. They reduce the chance of loss but can be circumvented.

Detective controls

Detective controls identify errors after the fact, such as reconciliations and exception reports. They limit how long a problem persists but do not prevent the initial event.

Layered defence

Prevention and detection are complementary, not interchangeable. The strongest cycles use prevention as the first line and detection as the backstop.

Cycle-level view

Mix should be assessed per cycle. A procurement cycle heavy on detection but light on prevention is exposed differently from a payroll cycle with the opposite imbalance.

How AuditPro Core Bridges the Gap

  • Control classification: each key control is tagged preventive or detective and grouped by cycle.
  • Balance analysis: the platform shows the mix per cycle so over-reliance on one type is visible.
  • Exception workflow: cycles missing a preventive or detective layer are flagged for control design review.
  • Traceability to source: each control links to the process and assertion it protects.

Key Takeaways

  • Detection alone catches errors only after the loss has occurred.
  • Prevention alone has no backstop when a control is bypassed.
  • Aim for prevention as first line and detection as backstop per cycle.
  • Assess the mix cycle by cycle, not across the whole environment at once.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.