How Costpoint Controls Testing Works
A practical testing program begins by identifying the control objective, the related Costpoint process, the population of transactions, and the evidence required to demonstrate operation. The tester then selects appropriate samples or performs a full-population review when the nature of the control supports it.
For each test, the reviewer compares the expected control procedure with what actually occurred. Evidence may include transaction records, approval histories, user permissions, configuration settings, reports, reconciliations, and supporting documentation. Exceptions should be documented with enough detail to explain what happened and why the result differs from the control requirement.
- Define the control: Identify the risk addressed and the expected control activity.
- Establish the population: Determine which transactions, users, or configurations are subject to testing.
- Select evidence: Gather records that demonstrate whether the control operated.
- Execute the test: Compare actual activity against the documented control requirement.
- Document results: Record exceptions, conclusions, and required follow-up actions.
Testing Accounting and Transaction Controls
Accounting controls testing should follow the transaction from initiation through posting. For invoices, testing may examine capture, extraction, validation, matching, chart of accounts selection, approval, posting, and the accuracy of resulting accounting entries. This approach helps determine whether controls are operating at the points where financial information enters and moves through Costpoint.
Receivables controls can be tested in a similar way. Reviewers may examine whether customer payments were correctly matched with remittances, whether unapplied cash was investigated, whether deductions were appropriately handled, and whether receipts were posted to the correct accounts. These procedures are central to effective cash application controls and accurate customer-account balances.
Invoice workflows can also be assessed for authorization and processing accuracy. Testing invoice processing may involve verifying that required validation, matching, coding, approval, and posting steps occurred according to established procedures.
Testing ERP and System Controls
Costpoint controls testing extends beyond individual transactions to the ERP environment itself. Reviewers can examine user access, role assignments, configuration changes, interfaces, system-generated reports, and controls surrounding integrations with other applications.
When evaluating deltek Costpoint within a broader finance architecture, testing should consider how ERP integrations, migrations, and extensions affect existing control procedures. A control that works correctly inside one application may require additional testing when financial data moves between systems.
Configuration testing is particularly relevant when organizations modify approval workflows, account structures, security permissions, or integration rules. Testers should confirm that changes produce the intended business result without altering unrelated control behavior.
Compliance and Audit Testing
Costpoint controls testing is closely connected to broader Compliance Testing, which evaluates whether established requirements and control procedures are being followed. The testing scope can include financial reporting controls, approval requirements, access restrictions, documentation standards, and contractual obligations.
For organizations subject to Sarbanes-Oxley requirements, SOX Testing provides a related framework for evaluating controls that support reliable financial reporting. Costpoint evidence can contribute to this work when the tested control directly supports a relevant financial reporting objective.
Expense-related controls may also require dedicated testing. Expense Compliance Testing examines whether employee expenses follow applicable policies, approval requirements, documentation standards, and other control expectations. Within Costpoint, this can include reviewing expense transactions and verifying that required approvals and supporting records are present.
Interpreting Test Results
A successful test demonstrates that the control operated according to its defined requirement for the transactions or evidence examined. An exception indicates that the expected procedure was not demonstrated for the selected item and should be investigated before drawing a broader conclusion about the control.
Test results should distinguish isolated documentation issues from recurring control exceptions. Reviewers can consider the nature of the exception, its frequency, the financial process affected, and whether compensating controls provide additional evidence. Clear documentation makes results easier for control owners, internal audit teams, and external reviewers to evaluate.
Best Practices for Costpoint Controls Testing
Testing is most useful when procedures are tied directly to documented control objectives. Organizations should maintain clear descriptions of each control, identify responsible owners, define evidence requirements, and establish consistent testing criteria.
Testers should also preserve evidence that allows another reviewer to understand the population examined, sample selected, procedure performed, result obtained, and conclusion reached. Where exceptions occur, management can determine appropriate remediation and establish follow-up testing to verify that the control operates as intended after changes are implemented.
Regular testing can also reveal opportunities to strengthen process documentation, user responsibilities, approval workflows, and system configurations. This makes controls testing a practical component of ongoing financial governance rather than a review performed only for an audit event.
Summary
Costpoint Controls Testing evaluates whether financial, operational, access, and compliance controls within Costpoint are properly designed and operating as expected. Effective testing combines defined control objectives, appropriate evidence, transaction and configuration reviews, documented exceptions, and follow-up procedures to support reliable financial reporting and stronger control governance.