About Me

So, I'm trapped in audit. At least for the time being. Whilst I'm here I may as well make constructive use of my time. So I'll share some of my thoughts and experiences

Saturday, June 11, 2011

Interrelationships between preventive, corrective, directive and detective controls

Both detective and corrective controls are preventive in the sense that they can enable the prevention further events or the continuation of the detected event. For example, a control that detects fraud by an employee will prevent further frauds by that employee and will reduce the likelihood of fraud by other employees through deterrence.

Directive controls (i.e. policy and procedures) support controls at all stages.

It may be helpful to visualise the action of different controls on a timeline:



[Definition of corrective controls: act to reduce the impact of a detected event]

No comments:

Post a Comment