Back to templates
    Template

    Control test workpaper

    A twenty-one-column record of one control test: the population, its completeness check, the sample, the procedure, the evidence and a conclusion two roles sign.

    Compliance5 Sept 20263 min read

    2017 Trust Services Criteria (With Revised Points of Focus – 2022)ISO/IEC 27001:2022
    On this page
    Download the template

    control-test-workpaper.xlsx · 11 kBLicensed CC BY 4.0

    What this is

    The record of running one control test, written so a second person can re-perform it. One row per test, across three sheets: the workpaper, the exceptions it raised, and the calendar. Sections 3.3 to 3.6 of Control testing and ITGC produce it.

    It is not a second test plan; that already exists, one row per control, in the control catalogue workbook.

    How to use it

    1. Delete the nine example rows before the first real entry, and copy each control ID from the catalogue so the two files stay joinable.
    2. Fill the Workpaper sheet left to right. That order is the method. See the playbook, sections 3.3 to 3.6.
    3. Settle the population before drawing a sample, then record a completeness check and its outcome either way.
    4. Record the selection method, not just the size. Random supports a statement about the population; judgemental does not.
    5. Give the test a procedure beyond inquiry. Compliance with the policy set, rules and standards is reviewed regularly, with results recorded 1.
    6. Name tester and reviewer as roles, and keep the tester off the control. Independent review is expected at planned intervals, by people independent of the area reviewed 2.
    7. Open an Exceptions row the moment a sampled item fails. CC4.2 covers evaluating and communicating deficiencies 3.
    8. Publish the Calendar before the period opens. Clause 9.2.2 is titled Internal audit programme 4.

    What good looks like

    Seven of the twenty-one Workpaper columns.

    Test IDControl IDProcedure typePopulation sizeSample sizeSelection methodResult
    TST-001CTL-0014. Re-performance334. Entire population1. No exception
    TST-002CTL-0023. Inspection309251. Random2. Exception
    TST-003CTL-0033. Inspection186202. Systematic2. Exception

    Fields

    FieldRequiredMeaningCommon mistake
    Control IDyesThe catalogue row this test runs againstA test with no control behind it
    Procedure typeyes1. Inquiry, 2. Observation, 3. Inspection or 4. Re-performanceInquiry standing alone
    Population, source, checkyesEvery occurrence in the period, its origin, and the reconciliationA list with no stated boundary
    Population and sample sizeyesThe count, and how much was examinedA sample larger than its population
    Selection methodyes1. Random, 2. Systematic, 3. Judgemental or 4. Entire population"The ones available"
    Evidence obtainedyesThe records, named so they can be found againA screenshot with no identifier
    Result, Conclusion, Tester, RevieweryesThe closed value, a sentence about the period, and two roles that exclude the ownerA conclusion about the test date

    Download

    • File: control-test-workpaper.xlsx (xlsx, 11 KB) — sheets Read first, Workpaper, Exceptions, Calendar.
    • Markdown variant: the same tables as _control-test-workpaper.md, beside the workbook.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data, no organisation names; example rows are invented.

    References

    1. ISO/IEC. Information security controls. ISO/IEC 27002:2022. Controls 5.35 and 5.36 read in a licensed copy; https://www.iso.org/standard/75652.html 5
    2. ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 6
    3. AICPA (AICPA & CIMA). 2017 Trust Services Criteria (With Revised Points of Focus – 2022). TSP Section 100. https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022 3

    Sample sizes and frequencies are organisational choices. The four procedure types and the term ITGC are GRCIDE's own working definitions.

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by AICPA, ISO, IEC or any other standards body.

    Sources

    1. 1ISO/IEC 27002:2022 control 5.36, licensed copy · verified 2026-09-05
    2. 2ISO/IEC 27002:2022 control 5.35, licensed copy · verified 2026-09-05
    3. 3AICPA, 2017 Trust Services Criteria (With Revised Points of Focus – 2022), CC4.2 · verified 2026-09-05
    4. 4ISO/IEC 27001:2022 clause 9.2.2, iso.org/obp · verified 2026-09-03
    5. 5ISO/IEC 27002:2022 controls 5.35 and 5.36, licensed copy · verified 2026-09-05
    6. 6ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03