Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Internal Controls & Audit

Test of Operating Effectiveness

Also known as: Operating Effectiveness Testing, Test of Controls (Operating Effectiveness)
Simply put

A test of operating effectiveness checks whether a control that an organization says is in place is actually working as intended in day-to-day practice. Rather than just confirming a control was designed correctly, this testing looks at whether people are consistently following it and whether it functions the way it is supposed to over a period of time. It is commonly used in internal and external audits to gather evidence about how well controls perform.

Formal definition

A test of operating effectiveness is an audit procedure that evaluates whether a control selected for testing is operating as designed and whether it functioned consistently over the relevant period. It is typically distinguished from a test of design effectiveness, which assesses whether a control, if operated as prescribed, is capable of preventing or detecting the risk it addresses; operating effectiveness testing instead confirms that a control stated to be in place is actually functioning in practice, including whether responsible personnel are applying it as intended. Under PCAOB Auditing Standard No. 13, the auditor tests operating effectiveness by determining whether the control is operating as designed. The nature, timing, and extent of such testing (which may or may not involve audit sampling) commonly depend on factors including the type of control, the frequency of its operation, and the level of assurance sought; specific methodologies vary by engagement type, framework, and applicable professional standards, and readers should consult the governing standard for their context.

Why it matters

Testing operating effectiveness closes a critical gap in assurance: knowing that a control was designed well does not tell you whether it is actually being performed. An organization may have a well-crafted policy requiring dual authorization of payments, but if staff routinely bypass the second approver under time pressure, the control exists on paper only. Operating effectiveness testing gathers evidence about what happens in day-to-day practice over a period of time, giving audit committees, management, and external auditors a defensible basis for relying on a control rather than assuming it works.

Because this testing evaluates whether responsible personnel are consistently applying a control, it is central to how auditors form conclusions about the reliability of financial reporting and compliance processes. Under PCAOB Auditing Standard No. 13, for example, the auditor tests operating effectiveness by determining whether the control is operating as designed. Where testing reveals that a control is not functioning consistently, that finding may point to a deficiency, prompt additional substantive procedures, or lead the auditor to reassess the level of assurance the control can provide. This makes operating effectiveness testing a mechanism through which stated controls are held to account against actual behavior.

It is worth noting that operating effectiveness testing evaluates whether a control functions as intended; it does not, on its own, guarantee that a risk has been eliminated or that an organization is fully compliant. The nature, timing, and extent of testing vary by engagement type, framework, and applicable professional standards, and conclusions are shaped by the period examined and the sampling approach used. Readers should treat findings as evidence bearing on control reliability rather than as an absolute assurance of outcomes.

Who it's relevant to

External auditors
External auditors rely on tests of operating effectiveness to determine whether a control selected for testing is operating as designed over the relevant period, which informs the extent of additional substantive procedures and the overall level of assurance they can place on an organization's controls. Under standards such as PCAOB Auditing Standard No. 13, this testing is a defined step in evaluating control reliability.
Internal auditors
Internal audit functions use operating effectiveness testing to confirm that controls management asserts are in place are actually functioning day to day, including whether responsible personnel are applying them consistently. This helps distinguish controls that exist only on paper from those that operate reliably.
Compliance officers
Compliance professionals are concerned with whether controls supporting adherence to laws, regulations, and internal policies are functioning as intended in practice, not merely designed correctly. Operating effectiveness findings can highlight where behavior diverges from stated procedure and where remediation may be needed.
Control owners and process management
Those responsible for operating specific controls are directly evaluated by this testing, since it examines whether the control is being applied as designed and functioning consistently over time. Understanding how operating effectiveness is assessed helps control owners maintain evidence and perform controls in a way that can withstand scrutiny.

Inside Test of Operating Effectiveness

Operating Effectiveness
The degree to which a control operated as designed throughout a specified period, addressing whether the control was applied consistently, by appropriately authorized and competent persons, and produced the intended outcome. This is distinct from design effectiveness, which concerns whether a control is capable of preventing or detecting a material issue if it operates as intended.
Test Period Coverage
The interval over which the control's operation is evaluated. Because operating effectiveness concerns consistency over time, testing typically considers the control's application across the relevant period rather than at a single point, though the specific period varies by engagement scope and the assurance objective.
Nature of Testing Procedures
The type of evidence-gathering procedure applied, which often includes inquiry, observation, inspection of documentation, and reperformance. In many audit frameworks, inquiry alone is generally considered insufficient to conclude on operating effectiveness and is typically combined with more corroborative procedures.
Timing of Testing
When procedures are performed relative to the period under review, which may involve interim testing with roll-forward considerations or testing at or after period end. Timing choices can affect the extent of additional work needed to cover the remaining period.
Extent (Sample Size)
The number of instances or items examined, often influenced by the frequency of the control's operation, the assessed level of risk, and the desired level of assurance. Frequently operating controls typically warrant larger samples than infrequently operating ones.
Control Frequency
How often the control operates (for example, per transaction, daily, monthly, quarterly, or annually), which commonly informs both the extent of testing and the interpretation of results.
Exceptions and Deviations
Instances where the control did not operate as intended. Identified deviations are typically evaluated for their nature, cause, and potential effect on the conclusion, and may indicate a control is not operating effectively even where design is sound.
Documentation of Results
The evidence and working papers supporting the tester's conclusion, including what was tested, how, over what period, and the basis for the conclusion reached. Adequate documentation supports the defensibility and reperformability of the assessment.

Common questions

Answers to the questions practitioners most commonly ask about Test of Operating Effectiveness.

Is a test of operating effectiveness the same as a test of design?
No, though the two are related and often performed in sequence. A test of design evaluates whether a control, as it is structured, is capable of preventing or detecting the risk it is intended to address if it operates as intended. A test of operating effectiveness goes further, examining whether the control actually operated as designed over a defined period. A control can be well designed yet fail to operate effectively, and conversely, evidence of operation is of limited value if the underlying design is not capable of addressing the risk. Many frameworks treat design assessment as a prerequisite to, rather than a substitute for, operating effectiveness testing.
Does passing a test of operating effectiveness mean a control eliminates the associated risk?
No. A successful test typically provides evidence that a control operated as intended over the period examined, which may support a conclusion that the control reduces the likelihood or impact of the associated risk. It does not eliminate risk. Residual risk can remain even where controls operate effectively, and testing itself is generally performed on a sample or over a limited period rather than exhaustively. The conclusion is one of reasonable assurance about past operation, not a guarantee of future performance or of a risk-free state.
How do you determine an appropriate sample size when testing operating effectiveness?
Sample size commonly depends on factors such as the frequency with which the control operates, the nature of the control (for example, manual versus automated), the assessed level of risk, and the degree of assurance sought. Controls that operate more frequently are often tested with larger samples, while some automated controls may be assessed differently because consistent configuration can, in principle, be evaluated through a smaller number of items or through testing of the underlying system. Specific sampling conventions vary by framework, methodology, and professional judgment, so the applicable audit or assurance standards and internal methodology should be consulted rather than applying a fixed number.
What period should a test of operating effectiveness cover?
The testing period is typically aligned with the period for which a conclusion is being drawn, such as a reporting or reliance period. Because operating effectiveness concerns how a control performed over time rather than at a single moment, testing generally spans a defined interval rather than a point in time. Where a conclusion is needed as of a particular date but testing was performed earlier, additional procedures may be needed to address the remaining interval. The appropriate period depends on the objective, the framework, and the relevant assurance requirements.
What types of evidence are commonly used to test operating effectiveness?
Evidence often includes a combination of inquiry, observation, inspection of documents or records, and reperformance of the control. Inquiry alone is generally considered insufficient to conclude on operating effectiveness in many frameworks and is typically corroborated by other procedures. The nature and strength of evidence sought may vary with the assessed risk and the type of control, and the persuasiveness of evidence is usually a matter of professional judgment against the applicable standards.
How should exceptions or deviations found during testing be handled?
When testing identifies instances where a control did not operate as intended, these are commonly evaluated to understand their nature, cause, and potential effect rather than treated as automatically determinative. Considerations often include whether an exception is isolated or systematic, whether it indicates a control deficiency, and what its implications are for the overall conclusion and for any related residual risk. The evaluation and any resulting conclusions, including whether a deficiency is significant, generally involve professional judgment and should be assessed against the relevant framework and assurance standards; matters carrying legal or regulatory consequences may warrant professional advice.

Common misconceptions

A test of operating effectiveness is the same as a test of design.
These address different questions. A test of design evaluates whether a control, if operated as intended, is capable of achieving its objective; a test of operating effectiveness evaluates whether the control actually operated as designed over the relevant period. A control can be well designed yet fail to operate effectively, and testing one does not substitute for the other.
Confirming that a control exists or asking staff whether it is performed is enough to conclude it operates effectively.
In many audit and assurance frameworks, inquiry alone is generally not considered sufficient to support a conclusion on operating effectiveness. Corroborative procedures such as inspection, observation, or reperformance are typically needed, and the mere existence of a control does not demonstrate consistent operation over time.
A control that passes testing eliminates the associated risk and guarantees compliance.
Testing provides a level of assurance about operation over a period; it does not eliminate risk or guarantee an outcome. Residual risk typically remains even where controls are found effective, and conclusions are inherently limited by sampling, the test period, and the possibility of undetected deviations.

Best practices

Test design effectiveness before, or alongside, operating effectiveness, since concluding on operation is generally only meaningful for a control that is capable of achieving its objective by design.
Match the nature, timing, and extent of procedures to the control's frequency and the assessed level of risk, and avoid relying on inquiry alone by combining it with inspection, observation, or reperformance where appropriate.
Define and document the test period clearly, and where interim testing is performed, consider what additional roll-forward work is needed to cover the remaining period.
Evaluate every identified exception for its nature, cause, and effect rather than treating deviations solely as a numeric pass/fail, since a small number of deviations can still indicate the control is not operating effectively.
Maintain documentation sufficient for an independent reviewer to understand what was tested, how, over what period, and the basis for the conclusion, so the assessment is reperformable and defensible.
State the scope and limitations of the conclusion, recognizing that testing provides assurance rather than a guarantee and that residual risk typically remains.
Promotional banner for the Pentest Readiness checklist download