Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Internal Controls & Audit

Manual Controls

Also known as: Manual Control
Simply put

Manual controls are internal control activities that people carry out by hand, rather than being performed automatically by a system. Examples typically include approving transactions, reviewing them, and reconciling records and following up on any discrepancies. They are commonly used to help verify financial transactions, operational processes, and compliance requirements.

Formal definition

In a GRC context, manual controls are internal control activities performed by individuals rather than executed automatically by information systems. In a manual system, such controls often include procedures such as approvals and reviews of transactions, and reconciliations together with the follow-up of reconciling items (per PCAOB Auditing Standard No. 12). Manual controls may serve to verify financial transactions, operational processes, and compliance requirements, and are typically distinguished from automated (system-enforced) controls. Note that the effectiveness of manual controls depends on human performance and is therefore often subject to considerations such as consistency, competence, and susceptibility to override; no control fully eliminates the underlying risk. The precise design, frequency, and evidencing of manual controls vary by organization, framework, and regulatory context.

Why it matters

Manual controls remain a foundational part of many organizations' internal control environments, particularly where processes are not fully automated or where human judgment is required to interpret exceptions. Activities such as approving transactions, reviewing them, and performing reconciliations with follow-up of reconciling items help organizations verify financial transactions, operational processes, and compliance requirements. Because these controls depend on people rather than system enforcement, they can be adapted to nuanced or evolving situations that automated rules may not anticipate.

That flexibility, however, comes with a trade-off. The effectiveness of a manual control depends on human performance, which introduces considerations such as consistency, competence, and susceptibility to override. A control performed reliably by one individual may be executed inconsistently under time pressure, staff turnover, or unclear procedures. For this reason, manual controls are often a focus area for auditors and risk managers assessing whether a control is not only well designed but also operating effectively over time.

It is important to note that no control, manual or automated, fully eliminates the underlying risk it addresses. Manual controls reduce or modify risk rather than remove it, and their design, frequency, and evidencing vary by organization, framework, and regulatory context. Organizations typically weigh manual controls against automated alternatives based on factors such as transaction volume, cost, and the level of assurance required.

Who it's relevant to

Internal Auditors
Internal auditors assess whether manual controls are both well designed and operating effectively over time. Because these controls depend on human performance, auditors typically examine consistency of execution, competence of those performing them, and the potential for override, alongside the documentation that evidences each control's operation.
Compliance Officers
Compliance officers rely on manual controls, such as approvals, reviews, and reconciliations, to help verify that transactions and processes meet applicable compliance requirements. They are often responsible for ensuring procedures are clear and that manual controls are performed as intended, recognizing that effectiveness varies by framework and regulatory context.
Risk Managers
Risk managers consider manual controls as measures that modify risk rather than eliminate it. They typically weigh manual controls against automated alternatives, factoring in susceptibility to human error and override when evaluating residual risk relative to the organization's objectives.
Finance and Accounting Teams
Finance and accounting personnel frequently perform manual controls in the course of processing and verifying financial transactions, for example, reviewing and approving transactions and reconciling records with follow-up of reconciling items. The consistency and competence with which they execute these procedures directly affect control reliability.

Inside Manual Controls

Human-Performed Control Activities
Manual controls are control activities executed by people rather than by automated system logic. Examples typically include reviews, approvals, reconciliations, physical counts, and sign-offs performed by an individual exercising judgment or following a defined procedure.
Preventive and Detective Orientations
Manual controls may be designed to prevent an error or irregularity before it occurs (for example, an authorization before a payment is released) or to detect one after the fact (for example, a periodic reconciliation identifying discrepancies). The same control category can span both orientations depending on design.
Evidence and Documentation
Because a person performs the activity, manual controls typically rely on tangible evidence of performance, such as initials, dates, checklists, annotations, or reviewer notes, to demonstrate that the control operated. This evidence often forms the basis for testing operating effectiveness.
Judgment and Discretion
Many manual controls involve human assessment, such as evaluating the reasonableness of an estimate or the appropriateness of an exception. This judgment can add value in ambiguous situations but also introduces variability that automated controls do not typically exhibit.
Relationship to the Broader Control Environment
Manual controls sit within an organization's system of internal control and risk treatment. In many frameworks, such as the COSO Internal Control Integrated Framework, control activities are one component supported by the control environment, risk assessment, information and communication, and monitoring. Manual controls are one form control activities can take.

Common questions

Answers to the questions practitioners most commonly ask about Manual Controls.

Are manual controls inherently less reliable than automated controls?
Not inherently, though the comparison is more nuanced than it is often presented. Manual controls depend on human performance and are therefore typically more susceptible to variability, fatigue, oversight, and override than automated controls, which tend to operate consistently once configured correctly. However, reliability depends on context. A well-designed manual control performed by a competent, appropriately supervised individual can be highly effective, and manual controls often provide judgment, interpretation, and contextual awareness that automated controls cannot. Conversely, an automated control can fail systematically and silently if its logic or configuration is flawed. The appropriate choice generally reflects the nature of the risk, the volume and complexity of transactions, and cost considerations, rather than a blanket assumption of superiority.
Does performing a manual control mean the associated risk has been eliminated?
No. No control, manual or automated, eliminates risk; controls are measures that modify risk. A manual control is intended to reduce the likelihood or impact of a risk event, moving inherent risk toward a level of residual risk. Residual risk typically remains even where a control operates as designed, and manual controls carry their own execution risk arising from human error or omission. It is also worth distinguishing the risk itself, meaning a potential event and its effect on objectives, from the control, meaning the measure applied to that risk. Characterizing any control as guaranteeing an outcome or removing risk entirely would overstate what controls can achieve.
How should the design of a manual control be documented so it can be evidenced and tested?
Documentation commonly captures who performs the control, what is being checked or reconciled, how frequently it operates, the source information relied upon, the criteria or threshold for identifying an exception, and how exceptions are escalated and resolved. Many organizations also record evidence of performance, such as sign-offs, annotated reports, or reviewer notes, so that operation can be substantiated after the fact. Clear documentation supports both internal monitoring and independent testing, since a control that cannot be evidenced is often difficult to rely upon regardless of how effectively it was performed. The specific format and retention expectations vary by framework, sector, and organizational policy.
What factors influence how often a manual control should be performed?
Frequency is typically calibrated to the nature and velocity of the underlying risk and the process it addresses. Controls over high-volume or time-sensitive activity may operate daily or per-transaction, while controls over periodic reporting or reconciliation may operate monthly, quarterly, or at defined cycle points. Considerations often include how quickly an error could accumulate or cause harm, the point at which detection remains useful, and the resources required to perform the control. There is no universal standard, and frequency decisions generally reflect a documented rationale tied to the risk rather than convention alone.
How can an organization reduce the risk of human error within a manual control?
Common approaches include clear procedures and defined criteria so performers apply consistent judgment, training and demonstrated competence for those executing the control, and supervisory review or a second-person check for higher-risk activities. Segregation of duties, meaning separating incompatible responsibilities across individuals, is frequently used to limit the effect of a single person's error or override. Some organizations also monitor for patterns in exceptions to identify where a control is under strain. These measures reduce, but do not remove, the residual execution risk associated with human performance.
When might it be appropriate to consider automating a manual control?
Automation is often considered where a manual control operates over high transaction volumes, where consistency and completeness are difficult to sustain manually, where the logic is rule-based and stable, or where the cost of human performance is disproportionate to the benefit. Where a control requires judgment, interpretation of unusual circumstances, or contextual awareness, a manual element may remain preferable, and some controls are implemented as a hybrid combining automated processing with human review. Any automation typically introduces its own considerations, such as configuration accuracy, change management, and monitoring of the automated logic, so the decision generally weighs the risk profile, cost, and control objectives rather than defaulting to automation as an improvement.

Common misconceptions

Manual controls are inherently weaker or less reliable than automated controls.
Manual and automated controls each carry different characteristics rather than a fixed hierarchy of strength. Automated controls typically operate more consistently once configured, while manual controls can apply judgment to non-routine situations. Reliability depends on design, competence of the performer, and consistent operation, so the appropriate choice varies by context.
A manual control eliminates the risk it addresses.
No control, manual or automated, eliminates risk. A control is a measure that modifies risk, typically reducing likelihood or impact and thereby lowering inherent risk toward residual risk. Manual controls are also subject to human error, override, and inconsistent application, which is why residual risk generally remains.
If a manual control is documented in a policy, it is operating effectively.
Documentation describes control design, not whether the control actually operates as intended over a period. Operating effectiveness typically must be demonstrated through evidence of consistent performance, and a well-designed control can still fail if it is not performed, is performed incompletely, or is overridden.

Best practices

Define each manual control clearly, specifying who performs it, what activity is performed, how often, and what evidence of performance is retained, so the control can be tested and relied upon.
Retain contemporaneous evidence of performance, such as dated sign-offs, checklists, or reviewer annotations, to support later assessment of operating effectiveness.
Assess the competence and independence of the individuals performing manual controls, and consider segregation of duties so that no single person can both execute and conceal an error or irregularity.
Distinguish whether each manual control is preventive or detective and confirm it aligns with the specific risk it is intended to modify, rather than assuming coverage from documentation alone.
Periodically evaluate whether a manual control could be automated or supported by automation where consistency is a concern, while recognizing that some judgment-based activities may be better retained as manual.
Include manual controls within ongoing monitoring so that failures, exceptions, and instances of override are identified and remediated, consistent with the monitoring component of common internal control frameworks.
Promotional banner for the Pentest Readiness checklist download