Control test workpaper
A twenty-one-column record of one control test: the population, its completeness check, the sample, the procedure, the evidence and a conclusion two roles sign.
Compliance5 Sept 20263 min read
On this page
control-test-workpaper.xlsx · 11 kBLicensed CC BY 4.0
What this is
The record of running one control test, written so a second person can re-perform it. One row per test, across three sheets: the workpaper, the exceptions it raised, and the calendar. Sections 3.3 to 3.6 of Control testing and ITGC produce it.
It is not a second test plan; that already exists, one row per control, in the control catalogue workbook.
How to use it
- Delete the nine example rows before the first real entry, and copy each control ID from the catalogue so the two files stay joinable.
- Fill the Workpaper sheet left to right. That order is the method. See the playbook, sections 3.3 to 3.6.
- Settle the population before drawing a sample, then record a completeness check and its outcome either way.
- Record the selection method, not just the size. Random supports a statement about the population; judgemental does not.
- Give the test a procedure beyond inquiry. Compliance with the policy set, rules and standards is reviewed regularly, with results recorded 1.
- Name tester and reviewer as roles, and keep the tester off the control. Independent review is expected at planned intervals, by people independent of the area reviewed 2.
- Open an Exceptions row the moment a sampled item fails. CC4.2 covers evaluating and communicating deficiencies 3.
- Publish the Calendar before the period opens. Clause 9.2.2 is titled Internal audit programme 4.
What good looks like
Seven of the twenty-one Workpaper columns.
| Test ID | Control ID | Procedure type | Population size | Sample size | Selection method | Result |
|---|---|---|---|---|---|---|
| TST-001 | CTL-001 | 4. Re-performance | 3 | 3 | 4. Entire population | 1. No exception |
| TST-002 | CTL-002 | 3. Inspection | 309 | 25 | 1. Random | 2. Exception |
| TST-003 | CTL-003 | 3. Inspection | 186 | 20 | 2. Systematic | 2. Exception |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Control ID | yes | The catalogue row this test runs against | A test with no control behind it |
| Procedure type | yes | 1. Inquiry, 2. Observation, 3. Inspection or 4. Re-performance | Inquiry standing alone |
| Population, source, check | yes | Every occurrence in the period, its origin, and the reconciliation | A list with no stated boundary |
| Population and sample size | yes | The count, and how much was examined | A sample larger than its population |
| Selection method | yes | 1. Random, 2. Systematic, 3. Judgemental or 4. Entire population | "The ones available" |
| Evidence obtained | yes | The records, named so they can be found again | A screenshot with no identifier |
| Result, Conclusion, Tester, Reviewer | yes | The closed value, a sentence about the period, and two roles that exclude the owner | A conclusion about the test date |
Download
- File:
control-test-workpaper.xlsx(xlsx, 11 KB) — sheets Read first, Workpaper, Exceptions, Calendar. - Markdown variant: the same tables as
_control-test-workpaper.md, beside the workbook. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data, no organisation names; example rows are invented.
Related
- Playbook: Control testing and ITGC.
- Playbook: Running the external audit, which re-performs it.
- Templates: Control catalogue, holding the test plan · Findings-to-closure tracker, for exceptions that become findings.
References
- ISO/IEC. Information security controls. ISO/IEC 27002:2022. Controls 5.35 and 5.36 read in a licensed copy; https://www.iso.org/standard/75652.html 5
- ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 6
- AICPA (AICPA & CIMA). 2017 Trust Services Criteria (With Revised Points of Focus – 2022). TSP Section 100. https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 3
Sample sizes and frequencies are organisational choices. The four procedure types and the term ITGC are GRCIDE's own working definitions.
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by AICPA, ISO, IEC or any other standards body.
Sources
- 1ISO/IEC 27002:2022 control 5.36, licensed copy · verified 2026-09-05
- 2ISO/IEC 27002:2022 control 5.35, licensed copy · verified 2026-09-05
- 3AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), CC4.2 · verified 2026-09-05
- 4ISO/IEC 27001:2022 clause 9.2.2, iso.org/obp · verified 2026-09-03
- 5ISO/IEC 27002:2022 controls 5.35 and 5.36, licensed copy · verified 2026-09-05
- 6ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
Related
- AI use-case triage form
Template
- China–EU regulatory bridge
Reference
- Control testing and ITGC
Playbook