Test of Controls vs. Substantive Test (2026): The Same 25 Purchase Orders, Tested Twice

Kyle Ashcraft, CPA · 2019 CPA Exam Scores · 95 FAR · 98 BEC · 91 REG · 90 AUD

Here is the difference students mix up the most on the audit exam: a test of controls versus a substantive test. The easiest way to see it is to test the same 25 purchase orders twice.

Coffee Co., the example client from my Auditing 101 videos, has a rule. Before any purchase order goes out, the purchasing manager has to approve it and sign it. That signature is a control. So I pull 25 purchase orders from the year and open a work paper.

Quick answer: a test of controls asks whether a control worked, and the answer is a rate, such as an 8% deviation rate. A substantive test asks whether an amount is right, and the answer is a dollar amount. If the result is a dollar amount, it is substantive. If it is a rate, it is a test of controls.

This is the test-of-controls chapter of my Auditing 101 video on what auditors actually do in the field. The page below covers the same 25 purchase orders in writing.

Last updated October 2026. Coffee Co. and every figure in it are the example from my Auditing 101 video, not a real client. Standards referenced: AICPA AU-C 330 and AU-C 530.

What is the difference between a test of controls and a substantive test?

They answer two different questions about the same population.

Test of controlsSubstantive test
The questionDid the control work?Is the amount right?
What you look atAn attribute, such as an approval signatureThe amount recorded in the books
The answer you getA percentage: how often the control failedA dollar amount: how much the balance is wrong
ProceduresInquiry, observation, inspection, reperformanceTests of details (vouching to an invoice, confirming a balance) and substantive analytical procedures

That is the board I draw for every student. Substantive procedures are about dollars. Tests of controls are about percentages.

Test 1: did the control work?

For each of the 25 purchase orders I look at one thing: the approval signature. That is an attribute. Either it is there or it is not.

Purchase orderApproval signatureResult
2204SignedTick mark
2213SignedTick mark
2219SignedTick mark
2261No signatureDeviation
2347No signatureDeviation
25 tested2 deviationsDeviation rate: 8%

The other 20 purchase orders are not shown, and none of them had a deviation. So that is 2 deviations out of 25, a deviation rate of 8%. Notice that the answer to a test of controls is not a dollar amount. It is a percentage: how often the control failed.

My tolerable rate was 5%. That is the highest deviation rate I would accept and still rely on the control. 8% is higher, so the control is not working and I cannot rely on it. This means control risk goes up, and I have to get more of my evidence from the amounts themselves. (I cover the sampling side in sampling and the risk side in control risk.)

Test 2: is the amount right?

Now the second test, on the same 25 purchase orders. This time I compare the amount recorded in the books to the vendor's invoice.

Purchase orderSigned?RecordedVendor invoiceResult
2318Yes$4,800$4,080$720 overstatement
2261NoAgrees to the invoiceNo misstatement

Purchase order 2318 was signed by the manager, but it was recorded at $4,800 and the invoice says $4,080. That is a $720 overstatement. And 2261, the one with no signature? Its amount is exactly right.

A deviation is not a misstatement. A signed purchase order can still be recorded wrong, and an unsigned one can be recorded right. The answer to a substantive test is a dollar amount: how much the balance is wrong.

Same 25 purchase orders, two questions. Test 1 asked whether the control worked and got a rate. Test 2 asked whether the amount is right and got a dollar figure. Neither test replaces the other.

What does the auditor do when the control fails?

At Coffee Co., the 8% deviation rate pushed control risk up. Here is the chain: higher control risk means I can accept less detection risk, and less detection risk means I need more evidence from substantive procedures.

What I did not do is go back and test more signatures. The control already failed, so testing it again does not help. Instead I went to the amounts, which means I increased the extent of my tests of details.

How does the AUD exam test this?

The question says an auditor increases control risk because the control activities were ineffective, and asks what the auditor would most likely increase. That is exactly what happened at Coffee Co.

  • Answer B is correct: the extent of tests of details. The control failed, so the evidence has to come from the amounts.
  • Answer D is the trap, and the most common wrong answer: the extent of tests of controls. Once a control has failed, more testing of it does not help.
  • Answer C, the level of inherent risk, cannot be it. Inherent risk is the risk before any controls. Finding that controls do not work raises control risk, not inherent risk, so the auditor cannot change inherent risk in response.
  • Answer A is backwards. It has the level of detection risk going up. When control risk goes up, detection risk goes down, so you do more work, not less.

Remember: control risk up, detection risk down, extent of substantive tests up. A failed control is not a reason to test the control again.

For more on each side, see test of controls and substantive procedures. And if you have not seen how a single transaction is traced before any sampling begins, start with the audit walkthrough example.

Sources: AICPA AU-C 330, Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained; AICPA AU-C 530, Audit Sampling. Standards checked October 2026. Coffee Co. figures are illustrative.

Frequently asked questions

What is the difference between a test of controls and a substantive test?

A test of controls asks whether a control worked, looks at an attribute such as an approval signature, and produces a rate. A substantive test asks whether an amount is right, looks at the recorded amount, and produces a dollar figure.

What is a deviation rate and what is a tolerable rate?

The deviation rate is how often a control failed in your sample: 2 unsigned purchase orders out of 25 is 8%. The tolerable rate is the highest deviation rate the auditor will accept and still rely on the control. If the deviation rate is higher than the tolerable rate, the control cannot be relied on.

Is a deviation the same as a misstatement?

No. A deviation is a failure of a control, such as a missing signature. A misstatement is a wrong amount in the records. A signed purchase order can still be recorded at the wrong amount, and an unsigned one can be recorded correctly.

What does the auditor do when a test of controls fails?

Control risk goes up, so the auditor accepts less detection risk and gets more evidence from the amounts, increasing the extent of substantive tests such as tests of details. The auditor does not repeat the failed control test.

Is an analytical procedure a test of controls or a substantive test?

A substantive analytical procedure is a substantive test. It works on amounts and relationships between amounts, so its result is about dollars, not about how often a control operated.

Start the free AUD 101 course

A full free outline and official AICPA questions you can practice, so you can see whether the explanations work for you. No credit card required.

Start AUD 101 free

Kyle Ashcraft, CPA scored 90 or above on every section of the CPA exam in 2019, including a 90 on AUD. He is the founder and sole instructor of Maxwell CPA Review, where he creates every lecture, textbook and study outline himself.

Reach him at MaxwellCPAreview@gmail.com.

Double-click to edit...

Previous
Previous

Audit Confirmations (2026): Positive vs. Negative, and What to Do When a Customer Never Replies

Next
Next

Audit Walkthrough Example (2026): Follow One Purchase From Requisition to Check