Instiq
Chapter 5 · Control evaluation·v1.0.0·Updated 7/11/2026·~15 min

What's changed: Initial version

5.1Evaluating planning and development controls

Key points

Covers how a systems auditor evaluates the design and operating effectiveness of preventive and detective controls in project management, requirements definition, testing, migration, and production release, and diagnoses design deficiencies such as a lack of segregation of duties between development and operations.

A systems auditor is not the party building the system, but the party that independently evaluates whether appropriate controls are designed into each phase of development and actually operating. In the planning and development process, each stage—project management, requirements definition, testing, migration, and production release—carries risk, and each is designed with preventive controls (which prevent errors or risks from arising at all) and detective controls (which detect errors that have arisen). This section covers how the auditor evaluates both the design (is the design sound?) and operating effectiveness (is it carried out as designed?) of these controls, and diagnoses a deficiency by distinguishing whether it is a design deficiency or an operating deficiency.

5.1.1Controls in each development phase and audit focus

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.