CORAA
CORAA University / Free control gap register

Internal audit control design gap register

Capture design gaps before they disappear into meeting notes: condition, risk, evidence seen, severity, RCM action, owner, target date and management response.

Register profile

The defaults are illustrative. Replace the sample entity, references, evidence and responses before including the export in an internal audit file.

Total gaps
3
High severity
1
Open items
3
Evidence to strengthen
1
Control design gap register
RefCycleProcess areaGap typeGap titleConditionRisk / impactEvidence seenEvidence strengthSeverityRCM actionOwnerTarget dateStatusManagement response
Draft summary

3 control gap item(s) were captured for ABC Private Limited for FY 2026-27.

1 high-severity gap(s) and 3 open item(s) require management attention.

3 gap(s) have an RCM handoff action; 1 item(s) need stronger evidence before final reporting.

Control design discipline

Fix the design before testing

A design gap is not just a failed sample. It is a weakness in how the control is intended to prevent or detect risk. Capture it before operating-effectiveness testing, otherwise the RCM may test a control that cannot be relied on.

Use this after the walkthrough memo and before finalising the RCM builder. Confirm testing coverage through the sampling plan.

How a control design gap register should work

A control design gap exists when the control, as designed, is not capable of preventing or detecting the relevant risk at the right point in the process. It should be separated from an operating-effectiveness failure, where the design may be adequate but execution failed.

The register should connect the gap to evidence seen during walkthrough or fieldwork, record why the design is insufficient, identify whether the RCM needs a new or revised control, and assign ownership for remediation.

This generator creates a gap register, RCM handoff, management action plan and audit committee summary. It is useful for P2P, O2C, R2R, H2R, cash, inventory, treasury, compliance, ITGC and continuous monitoring reviews.

Worked example - payment authority gap

During a P2P walkthrough, the auditor finds that bank portal approvers are not periodically reconciled to the ERP approval matrix.

Inputs
Gap typeAccess / authority gap
Evidence strengthStrong
SeverityHigh
Output
RCM actionAdd bank access review control
Management actionMonthly reconciliation of bank portal users to authority matrix
The gap is a design issue because the process does not define a control that keeps payment authority aligned across ERP and bank portal. Testing payment samples alone will not fix the missing design.

Common mistakes

Mixing design gaps with sample failures
A failed sample may show operating failure. A design gap asks whether the control would work even if performed exactly as intended.
No evidence reference
A gap title is not enough. Record the document, screenshot, walkthrough item or report inspected so the reviewer can trace the basis.
No RCM consequence
Each gap should tell the audit team whether to add a control, change a test, avoid reliance or design alternate procedures.
Weak management action
Management response should identify the owner, due date, design change and closure evidence, not just say noted.

Frequently asked questions

What is a control design gap in internal audit?+
A control design gap is a weakness in how a control is structured, owned, timed or evidenced, meaning it may not prevent or detect the relevant risk even if performed as written.
Is a design gap the same as control failure?+
No. A design gap relates to whether the control is capable of addressing the risk. A control failure usually relates to whether an otherwise adequate control operated consistently.
What should a design gap register include?+
Include gap reference, cycle, process area, gap type, condition, risk, evidence seen, evidence strength, severity, RCM action, owner, target date, status and management response.
When should internal audit raise a design gap?+
Raise it when walkthrough, process understanding, system review or fieldwork shows the existing control design does not address the risk or does not create reviewable evidence.

Authoritative sources

ICAI
ICAI IASB - Compendium of Standards on Internal AuditApplicable from April 1, 2026; supports planning, evidence, documentation, review and reporting for internal audit work.
ICAI
ICAI IASB - Standards on Internal Audit publicationsLists current and legacy standards covering internal controls, planning, evidence, documentation, review and reporting.
The IIA - Global Internal Audit StandardsThe 2024 standards became effective for internal audit functions on January 9, 2025.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
Walkthrough memo generatorInternal audit RCM builderSampling plan generatorObservation report generatorCORAA Internal Audit
Share this tool
Last reviewed: 2026-08-30 · For informational purposes only — not professional advice.