A
AcadiFi
WA
WalkthroughNolan2026-05-20
ciaCIA Part 2RCMWalkthroughsControl Testing

What is the right sequence for RCMs, walkthroughs, design testing, and operating effectiveness testing?

41 upvotes
AcadiFi TeamVerified Expert
AcadiFi Certified Professional

Start with a draft process map and risk-control matrix, then validate it through walkthroughs. The walkthrough confirms how the process actually works, what evidence exists, who performs the control, and whether the control is performed as described.

After the walkthrough, assess design effectiveness. Ask whether the control, if performed as described, would mitigate the risk. Only then should the auditor test operating effectiveness for a defined period. Operating testing asks whether the control was performed consistently and evidenced properly.

If the design is missing or weak, do not force an operating test just to fill a template. Report the design issue and have management define or improve the control before later operating testing.

🔍

Master CIA Part 2 with our CIA Course

45 lessons · 90+ hours· Expert instruction

#rcm#walkthroughs#design-effectiveness#operating-effectiveness