← All postsHow-to

Internal controls: the ones that work are the ones that leave evidence

A control that happens but leaves no trace cannot be relied on by anyone outside the room. Designing for evidence is what separates a control from a habit.

How-toI

Internal controls are the checks a business builds into its own processes so that errors and fraud are prevented, or caught quickly enough to matter. They are not a compliance layer bolted on afterwards — they are the parts of the process that exist because someone might get it wrong, or might not want to get it right.

The working definition worth adopting is narrow: a control is something that happens, that someone is responsible for, and that leaves evidence it happened. Anything failing the third test may still be good practice, but nobody outside the room can rely on it — including the auditor, the buyer in a due diligence, and you in twelve months.

Types of internal controls that actually help

  • Preventive controls stop a bad outcome before it happens: approval limits, segregation of duties, system permissions, mandatory fields.
  • Detective controls find it afterwards: reconciliations, exception reports, variance analysis, spot checks.
  • Corrective controls fix it and stop the recurrence: error logs with owners, process changes, retraining.
  • Manual controls depend on a person doing something; automated controls are enforced by a system and fail differently — silently, and for everyone at once.

Most functions are over-weighted towards detective controls, because they are easier to add. Finding the same error every month is not control, it is monitoring — the question a detective control should provoke is why the preventive one is missing.

The controls small finance teams actually need

  1. Approval before commitment: purchase orders raised and authorised before spending, not after the invoice arrives.
  2. Three-way match on payables, so invoices are paid against an order and a receipt rather than a memory.
  3. Bank payments released by someone other than the person who set them up.
  4. Monthly reconciliation of every material balance sheet account, reviewed by a second person.
  5. A vendor master that only a named person can change, with changes logged.
  6. Access removed the day someone leaves, verified rather than assumed.

The smaller the team, the more the controls should be visible rather than segregated. Where one person genuinely has to do everything, the substitute control is transparency: a monthly review by the owner or a non-executive of the actual bank statement, not a summary prepared by the person being checked.

Designing for evidence

When a control is designed, write down what it produces. An approval leaves an approval record with a name and a timestamp. A reconciliation leaves a signed schedule with reconciling items aged. An access review leaves a list of who was reviewed and what changed. If a control produces nothing, either add an output or stop calling it a control.

This is also the cheapest way to make an audit painless. The evidence exists as a by-product of the work rather than being reconstructed in a scramble the week the auditor arrives — which is when reconstruction is both most expensive and least convincing.

Because most financial controls live where the transactions are, the evidence belongs there too. Ettex Books keeps approvals, payment releases and the reconciliation trail against the records they relate to, so demonstrating a control means opening the transaction rather than searching an inbox. The internal audit checklist then tests what the system already holds instead of asking people what they remember doing.

Testing them honestly

A control is only as good as the last time someone checked it operates. Pick a sample, follow it end to end, and record what you found — including nothing. Tests that only ever confirm the control works are usually testing the documentation rather than the process, and the difference shows up the first time something goes wrong.

Frequently asked

What are the five components of internal control?

Under the COSO framework: control environment, risk assessment, control activities, information and communication, and monitoring activities. Most practical work happens in control activities, but weaknesses usually originate in the environment.

What is the difference between preventive and detective controls?

Preventive controls stop the error occurring — an approval limit, a system permission. Detective controls find it after the fact — a reconciliation, an exception report. A healthy process needs both, weighted towards prevention.

Do small companies need internal controls?

Yes, and often more urgently: losses are proportionally larger and segregation is harder. The controls differ in form — owner review rather than segregation — but not in purpose.

Who is responsible for internal controls?

Management designs and operates them. Internal audit evaluates them. External audit considers them when planning. Responsibility for the control itself never moves to the auditor.

SL
Written by Sofia L.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.