After a control test, a reviewer confirms that an automated reconciliation ran on schedule and matched every transaction for the period. The residual risk, however, still sits above the level the risk owner has accepted. What should the practitioner conclude when judging control effectiveness?
- AThe control is fully effective because the automated reconciliation ran on schedule and produced no exceptions during the entire period under examination.
- BThe control is fully effective, and the remaining gap should be reported as an unavoidable inherent risk that no further control activity could realistically reduce.
- CThe control is ineffective and must be replaced entirely, because any residual risk above appetite proves the existing reconciliation logic was the wrong control to choose.
- DThe control is operating as designed yet not effective overall, because residual risk remains above the accepted level and additional treatment is still required. Correct
Why A is wrong: Tempting because clean operation looks like success, but effectiveness is measured against reducing risk to the accepted level, which has not been achieved here.
Why B is wrong: Tempting since some risk is inherent, but labelling the gap unavoidable ignores that residual risk above appetite still signals the control is not yet sufficient.
Why C is wrong: Tempting as a strong response, but a working control that leaves a gap may need supplementing rather than wholesale replacement, so this overstates the failure.
Why D is correct: Correct because effectiveness is judged by whether risk is reduced to the accepted level, so a control that runs cleanly but leaves excess residual risk is not yet effective.