Application Controls: Input, Processing and Output
Three layers, a dozen validation checks, and the questions that ask you to name them.
Application controls are the checks built into a specific business application, or performed around it, that make sure only complete, accurate, valid and authorised transactions get in, are processed correctly and come out to the right people. They sit inside the sales module, the payroll run or the core banking teller screen, not across the IT environment.
DISA covers them in two places: Module 1 as an audit review and Module 3 as something designed into a system. This page goes layer by layer, which is how the Assessment Test tends to ask about them.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Three Layers
Input
Objective
Every transaction is authorised, entered once, completely and accurately
Typical controls
Authorisation (online access, source documents), batch totals, validation checks, error handling
Processing
Objective
Processing does what it should, completely and accurately, on authorised data only
Typical controls
Run-to-run totals, programmed controls, recalculation, limit and reasonableness checks, reconciliation of file totals, exception reports, transaction logs
Output
Objective
Results are complete, accurate and reach only the right people
Typical controls
Report distribution controls, balancing and reconciliation, secure custody of negotiable forms, output error handling, retention, confirmation of receipt
| Layer | Objective | Typical controls |
|---|---|---|
| Input | Every transaction is authorised, entered once, completely and accurately | Authorisation (online access, source documents), batch totals, validation checks, error handling |
| Processing | Processing does what it should, completely and accurately, on authorised data only | Run-to-run totals, programmed controls, recalculation, limit and reasonableness checks, reconciliation of file totals, exception reports, transaction logs |
| Output | Results are complete, accurate and reach only the right people | Report distribution controls, balancing and reconciliation, secure custody of negotiable forms, output error handling, retention, confirmation of receipt |
Input Validation Checks
The background material lists these as checks on input data. Assessment Test questions often describe one and ask you to name it.
- Sequence check
- Document or transaction numbers follow in order; gaps and duplicates are flagged.
- Limit check
- A value must not exceed a set limit, such as a teller's cash withdrawal ceiling.
- Range check
- A value must fall between a lower and an upper bound.
- Validity check
- A value must be one of the accepted values or formats, such as a valid PAN structure.
- Reasonableness check
- A value is compared with what is normal, such as overtime hours in a payroll run.
- Table look-up and existence check
- The entered code must exist in a master table, such as a vendor code or IFSC.
- Check digit
- A digit calculated from the other characters of a code, so a mistyped code fails.
- Key verification
- Data is keyed twice by different people and the two entries compared.
- Hash total
- A total of a field with no financial meaning, such as account numbers, used only to prove nothing was added, lost or altered.
- Duplicate and logical relationship checks
- The same transaction is not entered twice; related fields are consistent, such as a joining date before a retirement date.
When Input Fails
The material gives four ways to handle input errors, each with a different risk:
- check_circleReject only the transactions with errors
- check_circleReject the whole batch
- check_circleHold the batch in suspense until corrected
- check_circleAccept the batch and flag the error transactions
- check_circleWhatever the method, errors go to a suspense or error log, valid transactions keep moving, and corrections are re-authorised at the original level
Quick practice on audit concepts. No signup.
Processing and Output in Practice
Processing controls protect the data files as well as the calculations. The material groups those files into system control parameters, standing data, master data and balances, and transaction files. Of these, parameters and master data deserve the most audit attention, because a single wrong interest rate parameter or a changed vendor bank account affects every later transaction without any input error appearing.
Output controls matter most where output has value in itself: printed demand drafts, cheque stock, payment files sent to a bank. The test is custody, reconciliation of control totals with the input side, and a distribution list that matches who should see the report.
Control Objectives the Material Lists
As Module 1 sets them out, an application should meet these six objectives:
- checkSource data preparation and authorisation
- checkSource data collection and entry
- checkAccuracy, completeness and authenticity checks
- checkProcessing integrity and validity
- checkOutput review, reconciliation and error handling
- checkTransaction authentication and integrity, for data passed between applications
Two Meanings of "Application Control"
Module 3's Chapter 4 opens with "application control" in a second sense: a security tool that allows only approved software to run on a device. That is an endpoint security control. The input, processing and output controls on this page are a different idea. Read which one a question means before answering.
How the DISA Assessment Test Tests This
- check_circleName-the-check questions: a scenario describes a control and the options are four validation checks
- check_circleWording questions: in a Module 1 chapter-end question, output errors in a post-implementation review are traced to input errors, and the material's answer is reconciliation (it finds the mismatch between input and output), not a limit check. Decide whether the question asks you to detect the anomaly or to prevent the error
- check_circleHash totals: the trap is treating them as financial totals
- check_circlePreventive versus detective: validation at entry prevents; reconciliation and exception reports detect
FAQs
What are input, processing and output controls?expand_more
Input controls make sure only authorised, complete and accurate data enters the application. Processing controls make sure it is processed correctly. Output controls make sure results are accurate and reach only the right people.
What is a hash total?expand_more
A total of a non-financial field, such as invoice or account numbers, used to prove that a batch was not changed, added to or truncated between two points.
What is the difference between a limit check and a range check?expand_more
A limit check tests one boundary, usually a maximum. A range check tests that a value lies between a lower and an upper bound.
Are application controls manual or automated?expand_more
Both. Many are programmed, like validation checks, but follow-up of exception reports and review of overrides are manual parts of the same control.
Next steps
- ITGC vs Applicationarrow_forward
- ERP Auditarrow_forward
- Data Migrationarrow_forward
- CAATs & Evidencearrow_forward
Assessment Test format, timed and scored.
