What Are Internal Controls?
Internal controls are the policies, procedures, and systems a business uses to safeguard its assets, ensure the accuracy of its financial records, promote operational efficiency, and encourage compliance with laws and policy. They are the mechanisms that make it difficult for errors and fraud to occur undetected.
The Five COSO Components
The COSO framework is the standard reference model for internal control, and the structure auditors work from. It defines five interdependent components:
- Control environment.
The tone set by leadership: ethical standards, organizational structure, and whether policy is genuinely enforced. - Risk assessment.
Identifying what could go wrong, and how likely and severe each risk is. - Control activities.
The specific procedures that address those risks: approvals, reconciliations, segregation of duties, access limits. - Information and communication.
Ensuring the right people receive accurate information in time to act on it. - Monitoring activities.
Ongoing checks that controls are still operating as designed rather than quietly lapsing.
The first component is the one most often underweighted. Control activities layered on top of a weak control environment tend to be bypassed, because staff take their cue from whether management treats the rules as real.
Types of Internal Controls
- Preventive controls:
stop a problem before it happens, such as requiring approval before a payment is released. - Detective controls:
identify a problem that has already occurred, such as a bank reconciliation or an exception report. - Corrective controls:
fix an identified problem and stop it recurring, such as recovering a duplicate payment and adding a duplicate check.
A working control system needs all three. Preventive controls alone will eventually be circumvented, and detective controls alone only tell you about losses after they have happened.
Examples of Internal Controls in Accounting
- Segregation of duties:
no one person authorizes, executes, records, and reconciles the same transaction. - Authorization limits:
spending thresholds requiring escalating levels of approval. - Reconciliations:
bank, subledger, and intercompany accounts agreed on a set schedule. - Physical safeguards:
restricted access to cash, inventory, check stock, and signature plates. - System access controls:
permissions matched to role, reviewed when people change jobs. - Documentation requirements:
supporting evidence retained for every entry and payment. - Independent review:
someone other than the preparer checks the work. - Mandatory vacation and rotation:
schemes needing constant maintenance surface when the person maintaining them is away.
Internal Controls in Accounts Payable
AP concentrates several risks in one function: it holds vendor bank details, creates payment obligations, and moves cash out. The core controls address each of those points.
- Vendor master controls:
adding a vendor or changing bank details requires independent verification, ideally by phone to a known number. - Three-way matching:
invoices validated against the purchase order and goods receipt before approval. - Duplicate detection:
incoming invoices checked against what has already been processed. - Approval thresholds:
payment authority tiered by amount and enforced by the system. - Payment review:
the payment register reviewed by someone outside AP before release. - Positive pay:
the bank verifies presented items against an issued-payment file. - Statement reconciliation:
supplier statements reviewed on a schedule rather than reactively.
EXAMPLE
A business with approval limits but no vendor master control has a gap that matters. A clerk who cannot approve a $50,000 payment may still be able to change an existing approved vendor's bank details, redirecting payments that were legitimately authorized.
Internal Controls and SOX
For US public companies, Sarbanes-Oxley Section 404 requires management to assess and report on the effectiveness of internal control over financial reporting (ICFR), with the external auditor attesting to that assessment for larger filers.
What this means practically is that controls must be documented, operating, and evidenced. A control that exists in a policy document but leaves no record of having been performed is difficult to rely on, which is why logged and attributable actions carry more weight in an examination than written procedures.
Private companies are outside SOX, but the same expectations frequently arrive through other routes: lender covenants, insurance underwriting, audit requirements, and acquirer diligence.
How Internal Controls Are Tested
Testing distinguishes two questions that are easy to conflate: whether a control is designed to address the risk, and whether it is operating as designed throughout the period.
- Inquiry.
Ask the people who perform the control how it works. Weakest evidence on its own. - Observation.
Watch the control being performed. Only evidences the moment observed. - Inspection.
Examine documentation showing the control was carried out, such as signed approvals or reconciliations. - Reperformance.
Independently redo the control and compare results. Strongest evidence.
A control can be well designed and still fail testing if it was not performed consistently, which is the most common finding in practice: reconciliations skipped during busy periods, approvals granted retroactively, and access reviews that lapsed.
Frequently Asked Questions About Internal Controls
1. What are internal controls?
Internal controls are the policies, procedures, and systems a business uses to safeguard assets, ensure accurate financial records, promote efficiency, and encourage compliance. They make errors and fraud harder to commit and easier to detect.
2. What are the five components of internal control?
Under the COSO framework: control environment, risk assessment, control activities, information and communication, and monitoring activities. The control environment is foundational, since specific controls tend to be bypassed where leadership does not enforce policy.
3. What are the three types of internal controls?
Preventive controls stop problems before they occur, such as requiring approval before payment. Detective controls find problems that already happened, such as reconciliations. Corrective controls fix an issue and prevent recurrence. A working system needs all three.
4. What are examples of internal controls in accounting?
Segregation of duties, tiered authorization limits, scheduled bank and subledger reconciliations, physical safeguards over cash and check stock, role-based system access, documentation requirements, independent review, and mandatory vacation or job rotation.
5. What are internal controls in accounts payable?
Verification before vendor bank details are changed, three-way matching against the purchase order and receipt, duplicate invoice detection, tiered approval thresholds, review of the payment register by someone outside AP, positive pay, and scheduled supplier statement reconciliation.
6. What does SOX require for internal controls?
Section 404 requires management to assess and report on the effectiveness of internal control over financial reporting, with auditor attestation for larger filers. Controls must be documented, operating, and evidenced, since unrecorded controls are hard to rely on.
7. How are internal controls tested?
Through inquiry, observation, inspection of documentation, and reperformance, in increasing order of evidential strength. Testing addresses two separate questions: whether the control is designed to address the risk, and whether it operated consistently all period.