Management review controls are the controls most often relied on in a SOX programme and most often found deficient in a PCAOB inspection, for the same reason: a manager reviewing a report looks like a control whether or not it would catch anything.
The PCAOB’s Staff Audit Practice Alert No. 11 of October 2013 said so directly — “verifying that a review was signed off provides little or no evidence by itself about the control’s effectiveness” — and set out the factors that decide whether a review has the precision to prevent or detect a material misstatement: the objective of the review, the level of aggregation, the consistency of performance, the correlation to the relevant assertion, the predictability of the expectation, and the criteria for investigation.
Those factors became the tests auditors apply and the standard management has to design to. This guide explains what a management review control is and where it sits in a top-down approach, the six precision factors as the Alert states them, the four questions an auditor needs answered to test one, the evidence a review has to leave behind, and how to redesign a review that fails.

What management review controls are
The Alert describes them by example: monthly comparisons of actual results to forecast revenues or budgeted expenses; comparisons of metrics such as gross margin and expenses as a percentage of sales; quarterly balance sheet reviews. They “typically involve comparing recorded financial statement amounts to expected amounts and investigating significant differences from expectations”. Most are entity-level or detective controls, which is why they are attractive: a single review can, in principle, cover many transactions, many accounts and many assertions, and AS 2201 permits an auditor who finds an entity-level control precise enough to reduce testing of the controls beneath it.
The same standard notes that some entity-level controls monitor other controls “but not at a level of precision that would, by themselves, sufficiently address the assessed risk” — and that is the distinction every management review control is tested against. Our guide to entity-level controls covers the top-down approach the reviews sit inside.
The six precision factors
| Factor (Practice Alert 11) | What the Alert says | Design implication |
|---|---|---|
| Objective of the review | A procedure that functions to prevent or detect misstatements generally is more precise than one that merely identifies and explains differences | The review’s purpose is stated as catching misstatement, not explaining variance |
| Level of aggregation | A control performed at a more granular level generally is more precise — revenue by location or product line rather than total company revenue | Disaggregate to the level at which a material error would be visible |
| Consistency of performance | A control performed routinely and consistently generally is more precise than one performed sporadically | A fixed calendar and a defined performer |
| Correlation to relevant assertions | A control indirectly related to an assertion is less likely to catch misstatement in it — a review of recorded receivables may not detect errors in the valuation of delinquent receivables | Each review mapped to the assertions it actually addresses |
| Predictability of expectations | Detective controls that use KPIs or other information to develop expectations depend on the ability to develop sufficiently precise expectations to highlight potentially material misstatements | The expectation built from independent data, not from the number being reviewed |
| Criteria for investigation | The threshold for investigating differences relative to materiality indicates precision; a threshold near financial-statement materiality has less precision than a lower one | A documented threshold well below materiality, and a record of what was investigated |
Management review controls: the four questions an auditor tests
The Alert lists what evaluating a review control’s design “generally involves”: whether it satisfies the control objective for the relevant assertion; the precision factors, including the appropriateness of the expectations, level of aggregation and criteria for investigation; the steps involved in identifying, investigating and resolving significant differences; the competence and authority of the person performing it; the frequency; and the information used, including whether it is system-generated. Operating effectiveness testing then looks, for selected operations, at “the steps performed to identify and investigate significant differences” and “the conclusions reached in the reviewer’s investigation, including whether potential misstatements were appropriately investigated and whether corrective actions were taken as needed”. Condensed, an auditor needs four answers.
| Question | What answers it | What does not |
|---|---|---|
| 1. What would this review catch? | The assertion, the account, the size of error the aggregation and threshold would expose | ‘The CFO reviews the financials’ |
| 2. What did the reviewer compare the numbers to? | An expectation from budget, prior period, operational data, external benchmarks — documented, and independent of the figures reviewed | A review of the numbers against themselves |
| 3. What differences were found, and what happened to them? | The items over the threshold, the inquiry made, the explanation obtained and corroborated, the adjustment or the conclusion | A sign-off; a variance commentary with no follow-up |
| 4. Is the information reviewed complete and accurate? | Evidence over the system-generated reports and spreadsheets used — ITGCs, report logic testing, reconciliation to source | Reliance on the report because it came from the system |
The fourth question is the one the Alert pairs with management review controls throughout: “if the control uses system-generated information or reports, the auditor also should obtain evidence about the completeness and accuracy of those reports”. A precise review of an incomplete report is not a control. Our guide to SOX 404 covers where information produced by the entity fits in the assessment.
Evidence a management review control must leave behind
| Evidence | Why | Practical form |
|---|---|---|
| The expectation | Shows what the recorded amount was compared to and that it was formed independently | Budget or forecast file, prior-period data, operational driver calculation, saved with the review |
| The threshold | Shows the criteria for investigation and their relation to materiality | Stated in the control description; applied visibly in the review file |
| The items investigated | Shows the review was performed at the stated aggregation and that differences were pursued | A list of items over threshold with the question asked and of whom |
| The resolution | Shows conclusions were reached and corrective action taken where needed | Explanation, corroborating support (a contract, a sub-ledger extract), the adjusting entry or the documented decision not to adjust |
| The reviewer’s competence and authority | Shows the person could reach the conclusion and act on it | Role in the control description; access to correct; evidence of challenge, not only acceptance |
| The information source | Shows the reports reviewed were complete and accurate | Report parameters, ITGC evidence, reconciliation of the report to the ledger |
A sign-off with a date is the least of it. What auditors and inspectors look for is a review file in which a reader who was not there can see what was expected, what was different, what was asked and what was concluded.
Redesigning a management review control that fails
- Name the assertion and the error size. “Revenue, existence and cut-off, errors above $X” — if the review cannot be described that way, it is monitoring, not a control.
- Lower the aggregation until the error would show. If a material misstatement in one product line would be invisible in a consolidated total, review by product line.
- Build the expectation from outside the number. Units shipped × price, headcount × average cost, prior period adjusted for known changes.
- Set the threshold at a fraction of materiality and write it into the control; every item over it gets an inquiry and a documented answer.
- Corroborate, do not accept. An explanation from the person who owns the number is a hypothesis; the control ends when it is supported.
- Fix the report before the review. Put the system-generated report and the spreadsheet under ITGCs and prove completeness and accuracy once, then rely on it.
- Retain the file. Expectation, items, inquiries, support, conclusion, sign-off — in that order, for every period.
Frequently asked questions
What are management review controls?
Controls in which a manager compares recorded financial amounts to an expectation — budget, forecast, prior period, operational metrics — and investigates significant differences. Monthly actual-to-budget reviews and quarterly balance sheet reviews are the PCAOB’s own examples. They are usually detective, often entity-level, and their value depends entirely on precision.
Why do auditors challenge them?
Because a sign-off proves a review happened, not that it would catch a material misstatement. PCAOB Practice Alert 11 states that verifying sign-off provides little or no evidence of effectiveness, and sets out the precision factors auditors test: objective, aggregation, consistency, correlation to the assertion, predictability of expectations and criteria for investigation.
What threshold should a review use?
One well below financial-statement materiality. The Alert says a control that investigates items near materiality has less precision and a greater risk of failing to detect a material misstatement than one with a lower threshold. The threshold is documented in the control and visible in the review file.
What evidence should a review keep?
The expectation and its source, the threshold, the items over it, the inquiries made, the corroborating support, the conclusions and any adjustments, and evidence that the reports reviewed were complete and accurate. A dated signature alone is not sufficient.
Can a management review control replace transaction-level controls?
Sometimes. AS 2201 allows an auditor to reduce testing of other controls where an entity-level control operates at sufficient precision for the assessed risk. In practice that requires disaggregation, independent expectations and a low threshold — the same factors that make the review precise enough to stand alone.
Where this leaves you
Design management review controls to the six precision factors and document them to the four questions: what the review would catch, what it compared to, what it found and did, and whether the information was reliable. A review that can answer those is a control an auditor can rely on and an inspector cannot dismiss; a review that cannot is a signature.
References
- PCAOB Staff Audit Practice Alert No. 11 — Considerations for Audits of Internal Control Over Financial Reporting (24 October 2013) — Testing management review controls: the precision factors, design and operating effectiveness, and system-generated information.
- PCAOB AS 2201 — An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements — Entity-level controls and precision (.22–.24); testing design and operating effectiveness (.42–.46).
- COSO — Guidance on Internal Control — The framework’s control activities and monitoring components.
More on internal control
- Management review controls — you are here
- Entity-level controls
- SOX 404: management assessment and auditor attestation
- SOX compliance: the complete guide
- Material weakness vs significant deficiency
- The COSO 17 principles
The management review control design template with the six precision factors, the review evidence file layout, the information-produced-by-entity checklist and the control testing workpapers are in the COSO ERM & Internal Control Toolkit, or start with the free templates.