8 min read

Automated Controls vs. Manual Controls: Testing Approaches

A practical comparison of how IT auditors test automated and manual controls, including sample sizing, evidence, and reliance strategies.

CISAPractice|

One of the most fundamental distinctions a CISA candidate must internalize is the difference between automated and manual controls, and how that difference drives audit testing strategy. Automated controls are executed by an information system without human intervention, such as system-enforced field validations, automated three-way match in accounts payable, or a configuration that locks accounts after five failed login attempts. Manual controls depend on a person performing a task, such as a supervisor reviewing an exception report or a security administrator manually approving an access request.

Why the Distinction Matters

The nature of a control determines how much testing is required to gain assurance over its operating effectiveness. Automated controls, once proven to function correctly and once the underlying application is confirmed to be stable and subject to effective change management, are generally expected to operate consistently every single time a transaction is processed. This means that for automated controls, auditors typically test a single instance (or a very small number of instances) rather than a large sample, provided general IT controls, particularly change management and access controls over the application, are also assessed as effective.

Manual Controls Require Larger Samples

Manual controls are subject to human error, inconsistency, and fatigue. A reviewer might miss an exception on a Friday afternoon that they would have caught on a Monday morning. Because performance can vary from instance to instance, auditors must test a representative sample across the period under review, typically using attribute sampling techniques, to conclude on operating effectiveness. Sample sizes for manual controls are influenced by the frequency of control performance (daily, weekly, monthly), the population size, and the auditor's desired confidence level.

Hybrid or IT-Dependent Manual Controls

Many real-world controls are hybrids: a system generates an exception report (automated) and a person reviews and clears the exceptions (manual). These IT-dependent manual controls require the auditor to test both the completeness and accuracy of the automated report generation and the manual review and disposition of items. Auditors should verify report logic against source data to confirm the report captures all relevant exceptions before evaluating how the reviewer handled them.

Evidence Considerations

For automated controls, evidence typically includes system configuration screenshots, test scripts run through the application, and confirmation that the configuration has not changed since the last test date (often supported by change management records). For manual controls, evidence includes signed-off reports, email approvals, ticketing system records, and interview corroboration. Auditors should be alert to controls described as automated that actually contain manual override capabilities, as these overrides can undermine the reliability of the automated control entirely.

Practical Exam Tip

CISA exam questions frequently test whether a candidate understands that reliance on an automated control requires validating the general controls environment first. If change management or logical access controls around an application are weak, an auditor cannot place full reliance on the consistency of an automated control, because unauthorized changes could alter its behavior without detection.

Building an Effective Testing Approach

An effective audit program blends both approaches: walk through the process to identify each control point, classify each as automated, manual, or IT-dependent manual, then design testing procedures proportionate to the risk and the nature of the control. Auditors should also consider the frequency of the control, the potential impact of failure, and whether compensating controls exist. Combining configuration testing, re-performance, inquiry, and observation ensures a well-rounded conclusion on control design and operating effectiveness across the full population of transactions.

Related Tags

Technical Deep DiveIT ControlsAudit Testing

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free