View/Export Results
Manage Existing Surveys
Create/Copy Multiple Surveys
Collaborate with Team Members
Sign inSign in with Facebook
Sign inSign in with Google

Internal control questionnaire: 16 checks a process owner answers

A self-assessment the named owner of one process fills in, such as purchasing, payroll or cash receipts. Sixteen questions under the five components of internal control, answered Yes, Partly, No or Not applicable.

  • 16questions
  • about 8 minto answer
  • Yes, Partly, Noor not applicable
  • 1 processper response
Internal Control Questionnaire · answer to move through it
Use this template
Question 1 of 16 The process
Which process are you answering for?
Question 2 of 16 The process
How many people carry out the steps of this process in a normal month?
Only me
2 or 3
4 to 10
More than 10
Question 3 of 16 Control environment
A current written description of this process names who carries out each step.
Yes
Partly
No
Not applicable
Question 4 of 16 Control environment
Everyone who carries out a step knows what they are expected to check before passing it on.
Yes
Partly
No
Not applicable
Question 5 of 16 Risk assessment
In the last 12 months, somebody has listed what could go wrong in this process, including fraud.
Yes
Partly
No
Not applicable
Question 6 of 16 Control activities
No one person can take a transaction from start to finish without a second person checking it.
Yes
Partly
No
Not applicable
Question 7 of 16 Control activities
Every approval in this process is given within a written limit of authority.
Yes
Partly
No
Not applicable
Question 8 of 16 Control activities
Balances this process feeds are reconciled on a set schedule by somebody who did not post them.
Yes
Partly
No
Not applicable
Question 9 of 16 Control activities
Access to the systems and assets in this process was reviewed in the last 12 months.
Yes
Partly
No
Not applicable
Question 10 of 16 Control activities
When a step cannot be done as designed, the exception is logged and signed off.
Yes
Partly
No
Not applicable
Question 11 of 16 Information and communication
The reports used to check this process can be traced back to the source records.
Yes
Partly
No
Not applicable
Question 12 of 16 Information and communication
A problem found in this process reaches somebody with the authority to fix it.
Yes
Partly
No
Not applicable
Question 13 of 16 Monitoring
Somebody independent of this process has tested at least one of its controls in the last 12 months.
Yes
Partly
No
Not applicable
Question 14 of 16 Monitoring
Every weakness raised at the last review has a named owner and a due date.
Yes
Partly
No
Not applicable
Question 15 of 16 In your words
Which control in this process would you least want tested tomorrow, and why?
Question 16 of 16 Overall
Overall, how confident are you that this process would catch a material error before it reached the accounts?
Very confident
Confident
Somewhat confident
Not very confident
Not at all confident

What this internal control questionnaire checks

One process, one owner, and the checks built into it, grouped the way auditors group them.

One process per response. Most published questionnaires cover a whole organisation in 50 to 90 items, and nobody answers the last forty carefully. This one asks the owner of a single process, named in question 1. Send one per process.

Grouped by the five components. The checks sit under control environment, risk assessment, control activities, information and communication, and monitoring, the structure of the COSO framework[2] and of the US Green Book, which says nonprofit organisations may also adopt it.[1] Every question here is written for this page, and all sixteen are ready to edit in the questionnaire builder.

Yes, Partly, No. A control that runs most months gets a Partly, not a forced Yes.

An isometric conveyor carrying document trays through three checkpoint gates, a barrier, a magnifier over a stamped sheet and a shield with a tick, ending at a locked cabinet
A process with its checks built in: a stop, a review, a sign-off, then secure storage. The questionnaire asks whether each one really happens.

The 16 internal control questions

Every question, the answer it takes, and what a No or a Partly points at. Copy one group or the whole set.

Plain text, one question per line, with the answer scale.

The process

Two fields first. A questionnaire that does not name its process cannot be followed up.

  1. Which process are you answering for?Short textUse the name your finance team uses, so each response lines up with a process on the audit plan.
  2. How many people carry out the steps of this process in a normal month?Pick one of 4"Only me" or "2 or 3" changes how question 6 is read: a small team may need a manager or board member as the second person.

Control environment

Whether the process is defined well enough that a control inside it can be expected to run.

  1. A current written description of this process names who carries out each step.Yes, Partly, No, Not applicableA No here usually means the process lives in one person's head, which is also the first thing an auditor asks for.
  2. Everyone who carries out a step knows what they are expected to check before passing it on.Yes, Partly, No, Not applicablePartly is common: people know their own step but not what the next person relies on them to have checked.

Risk assessment

One question. A control only makes sense against a named way the process could go wrong.

  1. In the last 12 months, somebody has listed what could go wrong in this process, including fraud.Yes, Partly, No, Not applicableA No means the controls in place were chosen by habit. Fraud is named because it is the risk most often left off.

Control activities

What an auditor tests first: separation, authority, reconciliation, access and exceptions.

  1. No one person can take a transaction from start to finish without a second person checking it.Yes, Partly, No, Not applicableThe most important No in the set. One person able to start, approve and record a transaction is the classic opening for error and fraud alike.
  2. Every approval in this process is given within a written limit of authority.Yes, Partly, No, Not applicablePartly usually means the limits exist but nobody checks approvals against them.
  3. Balances this process feeds are reconciled on a set schedule by somebody who did not post them.Yes, Partly, No, Not applicableA reconciliation done by the person who posted the entries checks their arithmetic, not their judgement.
  4. Access to the systems and assets in this process was reviewed in the last 12 months.Yes, Partly, No, Not applicableLeavers and role changes are where access drifts. A No here is often quick to fix and worth doing first.
  5. When a step cannot be done as designed, the exception is logged and signed off.Yes, Partly, No, Not applicableIf nobody logs exceptions, an answer of Yes to the questions above describes the design, not what happens.

Information and communication

Whether the evidence can be trusted, and whether a problem goes anywhere.

  1. The reports used to check this process can be traced back to the source records.Yes, Partly, No, Not applicableA spreadsheet re-keyed from the system is the usual reason for a No. The check is only as good as the report it runs on.
  2. A problem found in this process reaches somebody with the authority to fix it.Yes, Partly, No, Not applicableA No means problems are found and then sit. That is a reporting line to fix, not a control.

Monitoring

Whether anybody outside the process checks that it still works, and whether past findings were closed.

  1. Somebody independent of this process has tested at least one of its controls in the last 12 months.Yes, Partly, No, Not applicableIn a small organisation the independent tester can be a trustee, a board treasurer or an external accountant.
  2. Every weakness raised at the last review has a named owner and a due date.Yes, Partly, No, Not applicableOpen weaknesses with no owner are the ones still open at the next review.

In your words, then the verdict

The open answer is the one an auditor would ask for first. Then one rating.

  1. Which control in this process would you least want tested tomorrow, and why?Long textOwners usually know where the weak control is. This question gives them a safe way to say so before a test does.
  2. Overall, how confident are you that this process would catch a material error before it reached the accounts?Pick one of 5Read it against the Nos above. High confidence with several Nos in control activities is the finding.

Twelve checks share one scale: Yes, Partly, No, Not applicable. Keep Not applicable honest: it means the step does not exist in this process, not that nobody knows.

For an audit file, add a text box after any check asking where the evidence is kept.

Reading the questionnaire by component

Count the Nos and Partlys by component, and start with control activities.

No single score. Leave out Not applicable, then count the Nos and Partlys in each group. One No in control activities matters more than two Partlys in monitoring, because it is a control that is missing rather than one nobody has checked lately.

Read the open answer next to the confidence rating. An owner who is very confident but names a control they would not want tested has told you where to look first.

There is no benchmark to compare against. Compare the same process with last year, or two processes with each other.

If the No sits inIt usually meansStart with
Control environment (Q3 to Q4)The process is not written down, or people do not know what the next step relies onA one-page description naming who does each step
Risk assessment (Q5)The controls were chosen by habit, not against a named riskListing what could go wrong, fraud included
Control activities (Q6 to Q10)A missing separation, approval, reconciliation or access checkThe separation of duties gap first
Information and communication (Q11 to Q12)Evidence that cannot be traced, or problems with nowhere to goWho a problem is reported to, in writing
Monitoring (Q13 to Q14)Nobody outside the process looks, or old findings stay openAn owner and a date for every open finding

Sending the questionnaire

Who answers, when, and what it is not.

The owner answers, under their own name. A gap found here needs somebody to close it, so this is not anonymous. For every employee's anonymous view of the rules, the employee compliance survey is the right instrument.

Send it before the year-end audit, and after any big change. A new finance system, a merged team or a key leaver is when controls quietly stop running.

Neighbouring problems. If the process is controlled but slow, the operational efficiency survey asks where the time goes. If a control has already failed and caused an incident, review it with a crisis management survey.

Two more hand-offs. Access problems often trace back to staff habits, which the cyber security questionnaire for employees covers. And if the people doing the work have ideas for redesigning the steps, ask them with a process improvement survey.

Internal control questionnaire FAQ

What is an internal control questionnaire?

A set of questions about whether the checks built into a process exist and run: who approves, who reconciles, who has access, and what happens when a step is skipped. Auditors use them to plan testing; managers use them to review their own processes.

Who should fill in an internal control questionnaire?

The person who owns the process: the finance manager for payments, the payroll lead for payroll, the treasurer in a small nonprofit. They answer under their own name, because a gap found here needs an owner.

What are the five components of internal control?

Control environment, risk assessment, control activities, information and communication, and monitoring. They come from the COSO Internal Control - Integrated Framework, and the US Green Book uses the same five. The questions here are grouped under them; the wording is our own.

Does it work for a nonprofit or a small business?

Yes, and the smaller the team the more question 6 matters. With two or three people somebody will do several steps, so the usual fix is a trustee or board treasurer who reviews bank statements and approvals.

Is a questionnaire the same as testing the controls?

No. It records what the owner believes happens; a test checks samples against the evidence. Use the answers to decide where testing starts, and treat a Partly or No as a place to look.

Michael Hodge, survey methodology and questionnaire design · Updated 22 September 2026 · How templates are reviewed

Sources (2)
  1. US Government Accountability Office. Standards for Internal Control in the Federal Government (the Green Book), GAO-25-107721, 2025 revision. gao.gov
  2. Committee of Sponsoring Organizations of the Treadway Commission. Internal Control - Integrated Framework, 2013. Named and attributed only; no text reproduced. coso.org

Sixteen questions written for this page and grouped under the five components of internal control, the structure shared by the COSO framework and the US Green Book.[1] Twelve checks share one Yes, Partly, No, Not applicable scale, the format self-assessment questionnaires in this field use, with Partly added so a control that runs some of the time is not forced into a Yes. No item comes from a licensed or proprietary questionnaire. The COSO framework is commercially licensed and is named and attributed only.[2] The Green Book is a US federal publication; the component names are used as group labels and no principle text is reproduced.[1]

Send it to the owner of your riskiest process

Sixteen questions, about eight minutes, and a list of the Nos to start with. Put your own process names in and send it.

Use this template