Detective Control
Definition
A control designed to identify an error or irregularity after it has occurred. Examples include bank reconciliations, exception reports, variance analysis, and internal audit reviews. Detective controls limit the duration and scale of losses rather than preventing them.
- Field
- Internal control frameworks / fraud examination
- Examples
- Bank reconciliations, exception reports, variance analysis, internal audit
- Timing
- Identifies an error after it has occurred
- Contrast
- Distinct from preventive controls, which stop the error beforehand
Common questions
Why do organisations rely on detective controls when preventive controls already exist?+
No preventive control catches everything, particularly collusion or a novel scheme that was not anticipated when the preventive control was designed, so detective controls act as a second layer that limits how long an undetected error or fraud can continue and how large the loss grows.
What is a practical sign that a detective control is weak in a fraud investigation?+
A long gap between when a scheme began and when it was caught, especially through an external tip rather than the organisation's own reconciliation or exception review, usually points to a detective control that either was not performed regularly or was not designed to catch that type of anomaly.
Related terms
- COBIT
- Control Objectives for Information and Related Technologies, published by ISACA. A governance and management framework for enterprise IT that defines IT-specific control...
- Control Environment
- The first and foundational component of the COSO framework. It encompasses the board's oversight, management's philosophy and operating style, organisational structure, commitment...
- COSO Integrated Framework
- A framework for internal control published by the Committee of Sponsoring Organizations of the Treadway Commission, defining five interrelated components: control environment,...
- IT General Controls (ITGCs)
- Controls over the IT environment that support the reliable operation of application controls. Key categories include access management, change management, computer operations,...
- Preventive Control
- A control designed to stop an error or fraudulent act before it occurs. Examples include segregation of duties, mandatory authorisation limits, access...