The virtual controller or master is elected using an election process that involves all IAPs in the group. If there is a contention, the IAP with the highest uptime will win.
There are no tunnels built for control traffic. The IAPs communicate using layer 2 broadcast and this is very lightweight.
There are additional details that can't be shared externally, but if there are specific questions or issues that the customer is concerned about, I will be happy to discuss those.
Thanks,
Shashi