METHODS FOR EVALUATING THE INTERNAL CONTROL SYSTEM OF AN ECONOMIC ENTITY DURING THE AUDIT PROCESS
Keywords:
internal control system, audit, COSO framework, risk-based approach, internal audit, audit risk, control environment, digital audit, INTOSAI, IIA standards, artificial intelligence.Abstract
This article examines the theoretical and methodological foundations and practical methods for evaluating the functioning of an economic entity's internal control system during an audit. It substantiates the decisive role of internal control assessment in determining the sufficiency of audit evidence, the level of audit risk, and the nature, timing, and extent of audit procedures. The study comparatively analyzes the COSO conceptual framework, INTOSAI internal control standards for the public sector, the international professional standards of the Institute of Internal Auditors (IIA), and risk-based, test-of-controls, questionnaire, matrix, scoring, and digital assessment methods. Particular attention is paid to digitalization and the use of artificial intelligence in state audit and financial control in the context of Presidential Decree No. PF-252 of the Republic of Uzbekistan dated 18 December 2025. The results show that no single method provides a sufficiently comprehensive and objective assessment in isolation; therefore, a combined multi-stage approach is required. Practical recommendations are proposed for economic entities and audit organizations to standardize internal control assessment, expand data analytics and continuous auditing, and improve auditors' digital competencies.
References
President of the Republic of Uzbekistan. (2025, December 18). Decree No. PF-252, "On Additional Measures to Further Improve State Audit and Financial Control Activities." Tashkent: National Database of Legislation, No. 06/25/252/1176, 19.12.2025. Available at: lex.uz/docs/7926706.
Republic of Uzbekistan. (2025, December 25). Law No. O'RQ-1105, "On the State Budget of the Republic of Uzbekistan for 2026." Available at: lex.uz/docs/7949060.
Regulation on the Procedure for Evaluating the Performance of Employees of Internal Audit Services. (2024, December). Available at: uza.uz/uz/posts/ichki-audit-xizmati-xodimlarining-faoliyati-samaradorligini-baholash-tartibi-tasdiqlandi_668151.
Committee of Sponsoring Organizations of the Treadway Commission (COSO). (2013). Internal Control - Integrated Framework. Durham, NC: AICPA.
Committee of Sponsoring Organizations of the Treadway Commission (COSO). (2017). Enterprise Risk Management - Integrating with Strategy and Performance. Durham, NC: COSO.
INTOSAI. (2004). Guidelines for Internal Control Standards for the Public Sector (INTOSAI GOV 9100). Vienna: INTOSAI Professional Standards Committee.
The Institute of Internal Auditors (IIA). International Standards for the Professional Practice of Internal Auditing (Standards). Lake Mary, FL: IIA, latest edition cited in the source manuscript.
Arens, A. A., Elder, R. J., & Beasley, M. S. Auditing and Assurance Services: An Integrated Approach (16th ed.). Harlow: Pearson Education.
Robertson, J. C., & Davis, T. J. Auditing. Business Publications Inc.
Ways to Improve the Effectiveness of State Financial Control. (2024). Scientific article. Available at: zenodo.org/records/13935222.
Tillashaykhov, M. (2026). Analysis of institutional factors in the development of the corporate governance system in joint-stock companies of the Republic of Uzbekistan. Conference proceedings. Available at: zenodo.org/records/19000380.
President of the Republic of Uzbekistan. (2021, August 27). Decree No. PF-6300, "On Measures to Further Improve the State Financial Control System." Available at: lex.uz.
Republic of Uzbekistan. Law "On Auditing Activity" (current edition). Available at: lex.uz.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 GEJournals

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.