Preventive Control
Definition
A control designed to stop an error or fraudulent act before it occurs. Examples include segregation of duties, mandatory authorisation limits, access restrictions, and pre-numbered documents. Preventive controls reduce fraud frequency but cannot guarantee zero occurrence.
- Purpose
- Stop an error or fraud before it happens
- Examples
- Segregation of duties, authorisation limits, access restrictions
- Contrast
- Detective controls catch it after the fact
- Limitation
- Reduces frequency, does not guarantee zero occurrence
Common questions
How does a preventive control differ from a detective control in an investigation?+
A preventive control, such as dual sign-off on payments, is evaluated by whether it was actually operating at the time of the fraud; a detective control, such as a bank reconciliation, is evaluated by whether it should have caught the loss afterward. A fraud examiner tests both separately when assessing control failure.
Why do auditors still test transactions when preventive controls are in place?+
Preventive controls can be overridden by management, bypassed through collusion between staff who are supposed to be segregated, or simply not applied consistently, so their presence in policy is not treated as proof they worked in every instance.
Related terms
- COBIT
- Control Objectives for Information and Related Technologies, published by ISACA. A governance and management framework for enterprise IT that defines IT-specific control...
- Control Environment
- The first and foundational component of the COSO framework. It encompasses the board's oversight, management's philosophy and operating style, organisational structure, commitment...
- COSO Integrated Framework
- A framework for internal control published by the Committee of Sponsoring Organizations of the Treadway Commission, defining five interrelated components: control environment,...
- Detective Control
- A control designed to identify an error or irregularity after it has occurred. Examples include bank reconciliations, exception reports, variance analysis, and...
- IT General Controls (ITGCs)
- Controls over the IT environment that support the reliable operation of application controls. Key categories include access management, change management, computer operations,...