Platformed

What is an automated control and how does it affect audit planning?

Audit planning and risk assessment · last updated 2026-09-02

An automated control is a control performed by a system without the same recurring human intervention as a manual control. Examples include system-enforced approval limits, automated three-way matching, edit checks and calculations performed by configured application logic.

Automated controls can be highly consistent, but the auditor needs to understand what they depend on. A control may rely on the configuration of the application, the completeness of source data, access restrictions and effective change management. If people can alter the program, parameters or data without appropriate control, the automated result may not be reliable.

This affects audit planning because the team may need to assess the relevant IT general controls before relying on the automated application control. Where the automated control and supporting ITGCs are effective, the audit approach may be more efficient than repeatedly testing a manual control. Where the environment is weak or poorly understood, the team may need a different response.

AI can help document the relationship between the application control, its dependencies and the relevant ITGCs. It does not remove the need to test the controls on which reliance is based.

References: PCAOB AS 2201 · PCAOB AS 2110

← All 60 questions