Control Design Evaluation & Testing

The Heart of ICFR Assurance

7/22/2026
Control Design Evaluation and Testing
What is Control Design Evaluation?

Control design evaluation determines whether a control is suitably designed to prevent or detect a financial misstatement.

Key questions to ask:
  • Is the control clearly defined and properly documented?
  • Does it directly address the identified risk?
  • Is the control owner specified?
  • Is it preventive or detective?
  • Is there a trail of documentation or system log?
Examples of Well - vs. Poorly Designed Controls
Risk Poor Control Strong Control
Unauthorized Journal Entries CFO randomly reviews some entries All journal entries > AED 50K require CFO approval with timestamp
Inaccurate Vendor Payments Manual review “when possible” ERP blocks payments without 3-way PO match and DoA approval
Unauthorized Journal Entries
Poor Control CFO randomly reviews some entries
Strong Control All journal entries > AED 50K require CFO approval with timestamp
Inaccurate Vendor Payments
Poor Control Manual review “when possible”
Strong Control ERP blocks payments without 3-way PO match and DoA approval
What is Control Testing?

Control testing confirms that controls:

  1. Exist
  2. Are operating consistently as intended
  3. Are effective in real-world execution
Types of testing:
  • Design Effectiveness Testing (DET) – Is the control well-structured?
  • Operating Effectiveness Testing (OET) – Is the control being performed as expected?
Sample Testing Scenario

Test Example
DET Review if the Delegation of Authority (DoA) matrix exists, and aligns with approval thresholds
OET Select 25 journal entries > AED 50K and verify that each was approved as per DoA
DET
Example Review if the Delegation of Authority (DoA) matrix exists, and aligns with approval thresholds
OET
Example Select 25 journal entries > AED 50K and verify that each was approved as per DoA

UAE ICFR Relevance
  • For SCA-regulated PJSCs: Control testing results support FY2026 management evaluation and auditor ICFR/ICOFR opinion, without public disclosure; from FY2027, they support public ICFR reporting
  • For Insurers: Control operating effectiveness should be evidenced in line with CBUAE Risk Management and Internal Controls requirements
  • For Private Companies: Testing supports audit readiness, Corporate Tax positions, transfer pricing support and seven-year record retention
How to Approach Testing
  • Identify and tag key controls during risk mapping
  • Use sampling based on control frequency and risk level
  • Maintain evidence: screenshots, logs, emails, signed checklists
  • Document test results, exceptions, and remediation steps
  • Rate controls as: Effective, Ineffective, or Not Applicable
Common Pitfalls to Avoid
  • Relying on undocumented controls or verbal confirmations
  • Assuming system controls work without ERP access testing
  • Treating walkthroughs as full control testing
  • Skipping re-testing after control remediation

How Crowe Adds Value to ICFR Testing

We support organizations with:

Designing and reviewing control test scripts

Conducting DET and OET with audit-grade documentation

Identifying gaps and planning remediation

Aligning testing with COSO, SCA phased ICFR/ICOFR requirements and applicable CBUAE standards

Preparing FY2026 non-public assessment packs, FY2027 public reporting evidence and working papers for external auditors and regulators


Coming Next Week:

Next week, we’ll focus on ICFR Deficiency Evaluation and Remediation, how to classify control failures, communicate findings, and track corrective actions to ensure full closure before year-end audit.

Echoes of truth

Wednesday Deep Dive – Echoes of Truth is a weekly thought-leadership series by Crowe’s Risk Advisory – Forensic & Process Excellence Division. It delivers practical insights on forensic investigations, fraud risk, governance, internal controls and process excellence.

Each edition draws from real-world engagements and global best practices to help organizations identify red flags, strengthen controls, optimize processes, and build resilient, transparent and high-performing operations.

Rakesh Kumar
Rakesh Kumar Dhoot
Associate Partner- Risk Advisory, Forensic & Process Excellence Division