Overview
The difference between manual and automated controls completed by the service organization is pretty self-explanatory. Manual controls rely on a human action (e.g., review, signature), while automated controls are system-driven (e.g., configurations, rules), with a human only getting involved if/when there’s an error notification.
Using control 1.02 as an example, a manual control would be the hiring manager and application/data owner approval signature. Evidence of approval can be stored in a system (e.g., electronic signature in a service desk ticket), but it still requires a person to perform the action of approving access.
A simple to understand automated control would be user password settings. The settings are configured at the network or application level and apply to all users. Using control 1.03 as a more complicated example, an automated control would be disabling employee access on their last day of employment through integrations built into the Human Resources Information System (HRIS) and relevant applications/systems.
It’s also possible for a control to be both automated and manual if there are multiple aspects to the control. Continuing with control 1.03, additional steps might be needed to disable access for systems not integrated with the HRIS (e.g., facility access system).
Aside: I try to use separation instead of termination nowadays, but they are interchangeable.

Testing
The type and extent of testing performed can be drastically different depending on if the control is automated or manual. Prior to testing, the service auditor will inquire with the control owner(s) to obtain an overview of the control, determine how the control is performed, and ascertain what evidence is available for inspection.
Continuing with control 1.02 as a manual control example, the service auditor will request a population of personnel hired during the period and select a sample from the population for testing. The larger the population, the larger the sample size selected for testing. There are upper limits to samples sizes, but that’s a topic for another day. The service auditor will rely on spreadsheets, exports from the ticketing system, and/or screenshots as evidence for testing to ensure approvals were obtained prior to granting system access.
Continuing with control 1.03 as an automated control example, the service auditor will still request a population of personnel separated during the period. However, since the control is automated, the service auditor will inspect automation criteria (system configuration, rules) and system logs/records for a sample of 1-2 transactions during the period. A full sample from the population based on sample selection guidelines isn’t generally required.
AI
It’s important to keep in mind when implementing AI into the internal control environment, the system should still log how and/or why decisions were made. From an internal controls and audit perspective, there needs to be evidence available to prove a control was working as expected and was effective. If there’s no proof, then it didn’t happen.

