Control Gap
Definition
A deficiency in the design or operation of a control that leaves a fraud scheme inadequately mitigated. Design gaps exist where no control addresses a scheme; operating gaps exist where a control is designed correctly but is not being performed as intended.
- Types
- Design gap and operating gap
- Design gap
- No control addresses the scheme
- Operating gap
- Control exists but isn't performed as intended
Common questions
How does an auditor distinguish a design gap from an operating gap?+
They first check whether any control addressing the fraud scheme exists on paper at all; if one does exist, they then sample its actual performance to see whether it is being carried out as designed.
Why does the distinction between design and operating gaps matter for remediation?+
A design gap requires creating a new control, while an operating gap usually requires enforcement, training, or resourcing fixes rather than designing something new that already exists on paper.
Related terms
- COSO Fraud Risk Management Guide
- A framework published by the Committee of Sponsoring Organizations of the Treadway Commission that provides a methodology for identifying, assessing, and responding...
- Inherent Fraud Risk
- The level of fraud risk present in a business process or transaction type before any controls are applied. Scored on likelihood and...
- Residual Fraud Risk
- The level of fraud risk that remains after existing controls are applied and operating. If residual risk exceeds the organisation's risk appetite...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Scheme Mapping
- The step in a fraud risk assessment that connects each identified fraud scheme to the specific business process, sub-process, and control environment...