Jul 8

The Federal ICFR Assessment Cycle: A Quarter-by-Quarter Guide

The federal ICFR assessment cycle is the annual, year-round process by which federal agencies evaluate the effectiveness of their internal controls over financial reporting under OMB Circular A-123. The cycle runs on the federal fiscal year (October through September) and produces the annual assurance statement the agency head signs. It breaks naturally into four quarterly phases: planning and risk assessment (Q1), walk-throughs and test of design (Q2), operating effectiveness testing (Q3), and findings classification and assurance (Q4). Agencies that treat ICFR as a year-end scramble consistently underperform those that stay on cycle.

Key takeaways

The ICFR cycle runs year-round. Not just year-end. The assessment starts as soon as the prior year's close wraps up.
Four quarters, four themes. Q1 is planning. Q2 is walk-throughs and design testing. Q3 is operating effectiveness testing. Q4 is findings and assurance.
The assurance statement is the end deliverable. Everything in the cycle exists to make that statement defensible.
Falling behind cascades. Missing Q1 planning means Q2 walk-throughs get compressed. Compressed walk-throughs produce weak process narratives, which weakens Q3 testing, which weakens Q4 findings.
Q3 is the busiest quarter. Operating effectiveness testing requires the most sample transactions, the most control owner time, and the most work paper review.

Why the cycle matters

Our federal ICFR pillar post explains what ICFR is and why federal agencies are required to do it. Our post on A-123 explains the operational framework. This post covers the practical question that comes up right after those foundational ones: what actually happens during the year?
The A-123 assessment methodology has a rhythm. It is not something you do once at year-end. It is a year-long process of scoping, testing, evaluating, and documenting, structured to produce a defensible assurance statement by the September deadline. Understanding the rhythm is how new internal control assessors avoid the traps that catch first-year teams: unrealistic scoping, missed walk-through opportunities, rushed testing, and findings that surface too late to address.

The four-quarter view at a glance

Quarter Timeframe Primary activities
Q1 Oct-Dec Year-end close wrap-up, risk assessment, planning and scoping
Q2 Jan-Mar Kickoff with owners, walk-throughs, test of design
Q3 Apr-Jun Operating effectiveness testing, preliminary findings
Q4 Jul-Sep Testing completed, findings classified, assurance statement

Q1 (October - December): planning and risk assessment

Q1 is the setup quarter. It starts with wrapping up the prior year (signing the assurance statement, submitting to OMB, closing out the prior cycle) and quickly transitions into planning for the new one. Most of the leverage in the entire assessment happens here. A well-scoped, well-planned assessment runs smoothly. A poorly scoped one struggles all year.

Year-end close wrap-up

The assurance statement for the fiscal year that just ended goes to OMB in mid-November. That means October is heads-down finalization of prior-year testing results, findings classification, and assurance statement drafting. The agency head signs, and the statement goes through the OMB Director to the President. Once that is done, the prior cycle is officially closed and the new cycle begins.

Risk assessment

Risk assessment is where the team identifies what could go wrong with the agency's financial reporting this year. This is not a generic risk register exercise. It focuses on the specific accounts, processes, and controls that materially affect the financial statements. The 2025 Green Book (GAO-25-107721) explicitly requires agencies to consider risks related to fraud, improper payments, and information security, so those three areas need direct attention in the risk assessment. Prior year findings are reviewed. Changes in the agency (new systems, new leadership, reorganizations, new authorities) are analyzed for their control implications. Trends in the USSGL trial balance (accounts with unusual movement, high volume, or historical error) get flagged.

Planning and scoping

Scoping decisions get made here. Which processes are in scope? Which are out? What is the materiality threshold this year? Which significant line items require testing? What controls will be tested and to what depth? These decisions get documented in a scoping memo that becomes the foundation for everything that follows. Scoping too tightly means missing something material. Scoping too broadly means burning team capacity on things that do not matter.
Q1 common pitfalls. Rolling forward last year's scope without a real risk-based reassessment. Skipping the materiality recalculation. Failing to identify new processes that came online during the year. Deferring the scoping memo to Q2. Each of these creates rework later and weakens defensibility.
2025 Green Book impact on the cycle. For fiscal year 2026 and beyond, the 2025 Green Book (GAO-25-107721) shapes what the assessment must cover. Two implications for the cycle: (1) risk assessment must explicitly consider fraud, improper payments, and information security, so those risk analyses should be documented at the same rigor as financial statement account risks; and (2) a new change assessment process must be documented, so any significant agency change during the year triggers a re-evaluation of controls. A-123 continues to require evaluation against all 17 Green Book principles, which drives the scope of walk-throughs and testing across the cycle.

Q2 (January - March): walk-throughs and test of design

Q2 is where the assessment moves from planning to fieldwork. The team meets with control owners, walks through the actual processes, and evaluates whether the controls are designed well enough to be worth testing for operating effectiveness. This is often the most collaborative quarter, because it involves interviews across the agency and produces the process narratives and flowcharts that document how work actually gets done.

Kickoff with control owners

The internal control team meets with the leaders of each in-scope process, explains what the assessment will cover, sets expectations for interviews and document requests, and establishes the schedule. This is also where the team confirms who the actual control owners and operators are. Titles on org charts do not always match reality. Kickoff surfaces those gaps early.

Walk-throughs

A walk-through is a structured conversation with the control operator, tracing a single transaction from start to finish through the process. The assessor asks open-ended questions: "Show me how you do this. What happens next? What could go wrong here?" The output is a process narrative and flowchart that document what actually happens, not what the standard operating procedure says should happen. Walk-throughs are labor-intensive but produce the foundation for everything that follows.

Test of design

Test of design asks a simple question: if this control operates as documented, would it actually address the risk it is supposed to address? A control that looks good on paper but operates at the wrong precision, frequency, or by the wrong person is not a well-designed control. Test of design happens before test of operating effectiveness because you cannot rely on a control that was never properly designed. If design fails, you either redesign the control or find a compensating control before you spend time testing operation.
Q2 common pitfalls. Interviewing only supervisors instead of the people who actually operate the controls. Accepting written procedures as the reality without verifying through walk-through. Skipping test of design and going straight to operating effectiveness. Documenting narratives that are too high-level to identify specific risks.

Q3 (April - June): operating effectiveness testing

Q3 is the busiest quarter. This is when the team tests whether controls that passed design evaluation are actually operating effectively across a sample of transactions over the year. Sample sizes are meaningful (typically 25 or more transactions per control, depending on frequency). Work papers accumulate quickly. Control owners are pulled into evidence requests and follow-up questions.

Test of operating effectiveness

For each in-scope control, the team selects a sample of instances where the control should have operated, obtains evidence that it did, and evaluates whether the evidence demonstrates effective operation. For a monthly reconciliation, this might mean pulling the reconciliation for a sample of months and verifying the reviewer's signature, the date, the resolution of variances, and the propagation of any adjustments. For an automated control, this might mean re-performing the calculation against sample transactions and verifying no exceptions were suppressed.

Sample selection

Sample sizes depend on control frequency. A daily control might be sampled at 25 instances or more. A monthly control might be sampled at all 12 months, or a subset if warranted. A quarterly control at all four quarters. An annual control at the single instance. The sample should span the year (not just one quarter) so the operating effectiveness conclusion covers the whole reporting period.

Preliminary findings

As testing progresses, preliminary findings emerge. A control operator missed a review. A reconciliation was not completed. A system change removed an edit check. These findings get logged, discussed with the control owner, and evaluated for classification. Not every deficiency is a finding. Not every finding rises to the level of significant deficiency or material weakness. This is where judgment starts to matter.
Q3 common pitfalls. Under-sampling because the team is behind schedule. Accepting incomplete evidence rather than pushing back. Delaying discussion of preliminary findings until Q4, which limits management's ability to remediate before year-end. Not documenting testing procedures in enough detail that a reviewer can retrace the work.

Q4 (July - September): findings and assurance statement

Q4 is where testing wraps up, findings get classified, and the assurance statement gets drafted. Everything the team did during the year comes together into a single deliverable that goes to the President through the OMB Director. This is the highest-stakes quarter, because the classification of findings determines the type of assurance conclusion the agency head can sign.

Testing completed

Any remaining operating effectiveness testing gets finished. Rollforward procedures address the period between when testing ended and September 30 (Was a control that was working in June still working in September?). Work papers are reviewed, referenced, and finalized. The team confirms that every in-scope control has been tested and evaluated.

Findings classified

Each finding gets classified using A-123 and Green Book criteria. A deficiency is any weakness in the design or operation of a control that does not rise to a higher level. A significant deficiency is a deficiency, or combination of deficiencies, that merits the attention of those charged with governance. A material weakness is a deficiency, or combination of deficiencies, that could result in a material misstatement of the financial statements not being prevented or detected on a timely basis. The classification drives the assurance conclusion.

Assurance statement drafted

The assurance statement is drafted in the format required by OMB, addressed to the President through the Director of OMB. The agency head reviews the statement, the underlying findings, and any material weaknesses identified. Depending on the classification of findings, the agency head signs one of three possible conclusions: unqualified (no material weaknesses or significant deficiencies), qualified (specific exceptions noted), or no assurance (material weakness prevents providing reasonable assurance).
Q4 common pitfalls. Rushing findings classification without enough analysis of severity and pervasiveness. Assuming a first-year finding is automatically a significant deficiency. Under-reporting findings to protect the assurance conclusion. Failing to document remediation plans for identified deficiencies. Missing the OMB submission deadline.

How to keep the cycle on schedule

Front-load Q1. The team's temptation is to defer planning until the prior year wraps up. Resist it. Start risk assessment and scoping in October, in parallel with prior-year closeout.
Book control owner time early. Q2 walk-throughs and Q3 evidence requests need control owner availability. Get those calendar holds in place before people fill their schedules with other work.
Set findings-review cadence in Q3, not Q4. Preliminary findings should be socialized with control owners as they emerge, not saved for a Q4 reveal. Early conversation gives management time to remediate before year-end.
Use standardized templates. Scoping memos, walk-through notes, test of design work papers, test of operating effectiveness work papers, findings write-ups. Templates save time and make review easier.
Build in review checkpoints. Have a senior reviewer look at completed work at the end of each quarter, not just at year-end. Errors caught in Q2 are cheap to fix; errors caught in Q4 are expensive.

Frequently asked questions

When does the federal ICFR assessment cycle start?

The cycle runs on the federal fiscal year, October 1 through September 30. Practically, the new cycle's planning work begins in October alongside prior-year wrap-up. Risk assessment and scoping happen in Q1 (Oct-Dec). Walk-throughs and test of design happen in Q2 (Jan-Mar). Operating effectiveness testing happens in Q3 (Apr-Jun). Findings classification and the assurance statement happen in Q4 (Jul-Sep).

What is a walk-through in ICFR?

A walk-through is a structured conversation with the control operator that traces a single transaction through the process from start to finish. The assessor asks open-ended questions ("Show me how you do this. What happens next?"), verifies documentation against actual practice, and identifies where controls exist to address risks. The output is a process narrative and flowchart. Walk-throughs happen in Q2 of the ICFR cycle and produce the foundation for design and operating effectiveness testing.

What is the difference between test of design and test of operating effectiveness?

Test of design (TOD) evaluates whether the control, as documented, would address the risk it is supposed to address if it operated. Test of operating effectiveness (TOE) evaluates whether the control actually operated as designed over a sample of transactions during the year. TOD comes first because you cannot rely on a control that was never properly designed. If TOD fails, redesign the control or find a compensating control before spending time on TOE.

When is the assurance statement due?

The assurance statement is submitted to the OMB Director as part of the annual financial report, typically in mid-November for the fiscal year ending September 30. Agencies with early-submission requirements or accelerated reporting deadlines may need to finalize the assurance statement even earlier. The exact date is set in OMB guidance each year.

What is a significant deficiency vs. a material weakness?

A significant deficiency is a deficiency, or combination of deficiencies, in internal control that is less severe than a material weakness but merits the attention of those charged with governance. A material weakness is a deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented or detected on a timely basis. The distinction affects the type of assurance conclusion the agency head can sign. A material weakness generally requires a "no assurance" conclusion.

Can findings identified in Q3 be remediated before year-end?

Sometimes, depending on the nature of the finding and how much of the year has already passed. A design deficiency (bad control) can potentially be redesigned and re-tested if enough time remains. An operating deficiency (control failed multiple times during the year) generally cannot be un-done, though the agency can document the corrective action for the next cycle. Early identification is the key: findings raised in Q3 have more remediation options than findings raised in Q4.

Who runs the ICFR cycle at a federal agency?

The Chief Financial Officer is typically the senior accountable official for the ICFR program, supported by an internal control office or Senior Assessment Team. Day-to-day execution is done by internal control assessors who plan, walk-through, test, and document. Control owners across the agency provide evidence, respond to inquiries, and remediate findings. The agency head personally signs the final assurance statement, per FMFIA.

What to learn next

Sources

• OMB Circular A-123 (Revised 7/15/2016), including Appendix A (Management of Reporting and Data Integrity Risk, Revised 6/6/2018)
• GAO Standards for Internal Control in the Federal Government (Green Book), 2025 Revision, GAO-25-107721 (effective FY 2026)
• GAO Financial Audit Manual (FAM)
• Federal Managers' Financial Integrity Act of 1982, 31 U.S.C. § 3512