Skip to main content
Category: Controls Management

Manual Control

Simply put

A manual control is a check or safeguard that a person performs by hand, rather than one carried out automatically by a system. Examples include reviewing and approving a transaction, reconciling records, or verifying that a process meets a requirement. Because a human carries out the step, manual controls depend on the individual performing the task consistently and correctly.

Formal definition

A manual control is an internal control activity executed by individuals to verify financial transactions, operational processes, or compliance requirements, in contrast to automated controls performed by information systems. It relies on human performance to detect or prevent errors, exceptions, or non-conformities, and its effectiveness is therefore contingent on the competence, diligence, and consistency of the person performing it. Because manual controls are typically more susceptible to human error and less consistently applied than automated controls, assessing their operating effectiveness commonly requires evidence that the control was performed as designed across the relevant period. This entry addresses the control-activity meaning within a GRC context and does not cover unrelated engineering or process-control senses of the term.

Why it matters

Manual controls remain pervasive across governance, risk, and compliance environments because many verification steps, reviewing and approving a transaction, reconciling records, or confirming that a process meets a requirement, still depend on human judgment and action. Their significance lies in this dependence: because a person carries out the step, the control's reliability is contingent on that individual's competence, diligence, and consistency. A well-designed manual control can be entirely ineffective in practice if the person responsible performs it inconsistently, skips it under time pressure, or lacks the training to recognize an exception.

This human dependence is why manual controls are commonly regarded as more susceptible to error and less consistently applied than automated controls that a system performs the same way every time. For risk managers and internal auditors, that distinction shapes how assurance is obtained. Assessing whether a manual control operated effectively typically requires evidence that it was actually performed as designed throughout the relevant period, not merely that the control exists on paper. A single review or reconciliation performed once does not demonstrate consistent operation across many transactions or reporting cycles.

Understanding manual controls also informs decisions about where automation may reduce residual risk and where human oversight remains necessary. Recognizing which controls in an organization are manual, and therefore more exposed to variability in human performance, helps prioritize monitoring, training, and control-improvement efforts.

Who it's relevant to

Internal Auditors
Internal auditors evaluate whether manual controls operate effectively, which typically requires gathering evidence that the control was performed as designed across the relevant period rather than at a single point in time. The human dependence of manual controls affects sampling and testing approaches, since consistency of execution cannot be assumed.
Risk Managers
Risk managers consider manual controls when assessing how uncertainty is being treated, recognizing that human-performed checks are commonly more susceptible to error and inconsistency than automated equivalents. This informs where residual risk may be higher and where additional monitoring or automation might be warranted.
Compliance Officers
Compliance officers rely on manual controls to verify that processes meet regulatory and internal policy requirements. Because effectiveness depends on the competence and diligence of the person performing the control, compliance teams often focus on training, documentation, and evidence of consistent execution.
Control and Process Owners
Individuals responsible for performing or overseeing manual controls, such as those approving transactions or performing reconciliations, bear direct responsibility for consistent, correct execution, since the control's reliability rests on their performance.

Inside Manual Control

Human execution
A manual control relies on a person to perform the control activity, as distinct from an automated control executed by a system without human intervention. Examples commonly include a supervisor's review and sign-off, a manual reconciliation, or an authorization performed by an individual.
Control objective
The objective the manual control is intended to support, such as accuracy, completeness, validity, or authorization of a transaction or process. The control is the activity performed; the control objective is the outcome it is designed to help achieve, and the two should not be conflated.
Preventive or detective purpose
Manual controls may be preventive, aiming to stop an error or exception before it occurs, or detective, aiming to identify an issue after the fact. A single control's classification depends on how and when it operates within the process.
Evidence of performance
Manual controls typically generate documentary evidence such as sign-offs, checklists, annotations, or dated records that demonstrate the control was performed. This evidence commonly supports later testing by assurance functions.
Frequency and timing
The cadence at which a manual control operates, for example per transaction, daily, monthly, or on an event-driven basis. Frequency affects how the control is designed, staffed, and tested.
Ownership and segregation of duties
A defined person or role responsible for performing the control, considered against segregation of duties so that, where appropriate, the individual performing an activity is not the same person reviewing or approving it.

Common questions

Answers to the questions practitioners most commonly ask about Manual Control.

Are manual controls inherently less reliable than automated controls?
Not inherently, though they carry different risk characteristics. Manual controls depend on human performance and are therefore more susceptible to inconsistency, oversight, fatigue, and override than automated controls, which execute uniformly once configured. However, manual controls can apply judgment to novel or ambiguous situations that automated logic may not accommodate. The appropriate choice typically depends on the nature of the risk, the volume and consistency of transactions, and the cost of implementation. Reliability is better assessed control by control rather than assumed from the manual or automated classification alone.
Does classifying a control as manual mean no technology is involved?
No. A control is commonly classified as manual when a person performs the key decision or action that determines whether the control operates, even if that person uses systems, reports, or tools to do so. For example, a reviewer comparing a system-generated report against source data is typically performing a manual control, because human judgment drives the outcome. Controls that rely partly on system functionality and partly on human action are often described as IT-dependent manual controls, distinguishing them from fully automated controls.
How should a manual control be documented so it can be tested?
Documentation commonly specifies who performs the control, what action they take, the frequency, the source information used, the criteria for a pass or fail outcome, and how performance is evidenced. Clear documentation supports both operating effectiveness testing and consistency across performers. Note that documentation practices vary by organization and framework, and this entry does not prescribe specific templates or tooling.
What evidence typically demonstrates that a manual control operated?
Evidence often includes sign-offs, initials or dates on reviewed documents, annotations showing items examined, records of exceptions identified and their resolution, and related workpapers or logs. Because manual controls depend on human action, retaining contemporaneous evidence of performance is generally important, as an undocumented review can be difficult to substantiate during testing or assurance activities.
How do assurance functions test the operating effectiveness of a manual control?
Assurance functions commonly examine a sample of instances over the relevant period to assess whether the control operated as designed and consistently. Because manual controls vary with the performer, testing may consider whether different individuals applied the criteria uniformly. Testing approaches, sample sizes, and methodologies differ across frameworks and by the assessed risk. This activity is distinct from, and independent of, the management activity of performing the control itself.
What factors influence whether to retain a manual control or automate it?
Considerations typically include transaction volume and frequency, the degree of judgment required, the consistency achievable by human performers, the cost and feasibility of automation, and the residual risk that remains after the control operates. High-volume, rules-based activities may favor automation, while activities requiring interpretation of ambiguous circumstances may retain a manual element. Such decisions are context-specific and fall outside the scope of this entry, which does not offer implementation or tooling advice.

Common misconceptions

Manual controls are inherently weaker or less reliable than automated controls.
Manual and automated controls each have different characteristics. Manual controls may be more exposed to human error, fatigue, or override and can be harder to perform consistently at scale, while automated controls carry configuration and change-management risks. Relative reliability depends on design, operation, and the specific context rather than being universally lower for manual controls.
Performing a manual control guarantees the control objective is met.
A control is an activity intended to support a control objective; it reduces but does not eliminate the risk of error or misstatement. Even a well-designed manual control that operates as intended provides reasonable, not absolute, assurance over its objective.
Testing that a manual control was performed is the same as management performing the control.
Executing the manual control is a management activity within the process, whereas testing whether it operated effectively is typically an assurance activity carried out with independence and objectivity. The two should be kept distinct to preserve the separation between the control and its examination.

Best practices

Document each manual control clearly, including its objective, owner, frequency, whether it is preventive or detective, and the evidence expected to be retained when it is performed.
Design manual controls with segregation of duties in mind, so that, where appropriate, the person performing an activity is not the same person reviewing or approving it.
Require and retain consistent evidence of performance, such as dated sign-offs or completed checklists, so the control's operation can be examined later by assurance functions.
Assess where manual controls may be exposed to human error, fatigue, or override, and consider whether automation or additional review is warranted based on the risk involved.
Keep the distinction between performing the control and testing it clear, ensuring that examination of control effectiveness is carried out with appropriate independence.
Review manual controls periodically to confirm they still address the intended objective as processes, systems, or risks change.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps