Suggested: controller reviewing an approval workflow and risk-control matrix on a laptop.
–>
Accounting Advanced Complexity Guide
Internal Controls for Small and Growing Businesses
A risk-based framework for protecting assets, producing reliable reporting and scaling accountability
Internal controls are the policies, approvals, system restrictions, reviews and evidence that help a business protect assets, produce reliable reporting and meet compliance obligations and reduce errors, unauthorized activity.
For growing businesses, the goal is a practical, risk-based control system with clear ownership and evidence that controls are working.
A control is complete only when the business can identify the risk it addresses, the person responsible, how often it operates, the evidence retained and who reviews exceptions. A policy without execution or evidence provides limited assurance.
1. Begin With the Control Framework
The COSO Internal Control—Integrated Framework organizes internal control into five connected components supporting operations, reporting and compliance. Small businesses can apply it practically rather than as a compliance exercise.
| Component | Management Question | Practical Evidence |
|---|---|---|
| Control environment | Are authority, ethics and accountability clear? | Organization chart, job responsibilities, approval policy, code of conduct |
| Risk assessment | What could prevent the business from meeting its objectives? | Risk register, fraud-risk discussion, process and system inventory |
| Control activities | What prevents or detects the identified risks? | Approvals, reconciliations, access limits, exception reports |
| Information and communication | Do the right people receive complete information in time to act? | Close calendar, reporting package, escalation rules, documented procedures |
| Monitoring | How does management know the controls continue to operate? | Review sign-offs, sample testing, issue log, remediation follow-up |
Internal control provides reasonable—not absolute—assurance. Human error, collusion, management override and system changes can still cause failure, so businesses need both preventive controls and ongoing monitoring.
2. Build a Risk-Control Matrix
An effective control program starts with risk, not a generic checklist. For each significant process, document what could go wrong, the financial or compliance exposure, and the control designed to address it. A practical risk-control matrix should identify:
- Risk and control objective: Describe the specific failure the control is intended to prevent or detect, such as an unauthorized vendor payment or an incomplete revenue cutoff.
- Control activity: State exactly what the preparer or reviewer does. “Management reviews” is not sufficient unless the review criteria, information used and follow-up are defined.
- Owner, frequency and evidence: Assign responsibility, establish when the control occurs and retain proof such as an approval record, reconciliation, exception report or review notation.
- Reviewer and escalation: Specify who evaluates exceptions, how quickly they must be resolved and when an issue is reported to senior management.
Design effectiveness asks whether the control could address the risk if performed as written. Implementation asks whether it has been placed in operation. Operating effectiveness asks whether it worked consistently, by the right person, during the period reviewed.
3. Use Layers of Control
A reliable system combines entity-level, process-level and IT general controls. Together, they support governance, transaction accuracy, system access, change management, backups and data interfaces.
Controls may be preventive, detective or corrective, and manual or automated. Automation improves consistency only when access, configuration and system-generated reports are also controlled.
4. Segregation of Duties in a Small Team
Ideally, no one person should control authorization, custody, recording and reconciliation. When staffing is limited, management should identify the conflict and add an independent compensating control.
Useful compensating controls include owner or Controller review of bank activity, dual approval above defined thresholds, independent verification of vendor bank changes, alerts for new payees, review of manual journal entries and periodic access reports. Review must be detailed enough to identify unusual items.
5. Focus on the Highest-Risk Processes
- Cash, payments and vendors: Separate vendor setup from payment release, verify bank changes independently, restrict payment access, and reconcile bank accounts promptly.
- Revenue and receivables: Control customer setup and pricing, reconcile billings to contracts, and review credit memos, write-offs, aging, and cutoff.
- Payroll: Approve employees and pay changes, restrict system access, reconcile payroll to the general ledger and cash, and review unusual activity.
- Journal entries and close: Use a close calendar, require support and approval for manual entries, and closely review estimates, related parties, and late entries.
- Systems and data: Use role-based access and MFA, remove access promptly, review privileged users, protect backups, and reconcile key system interfaces.
6. Monitor Performance and Control Changes
Controls can weaken as the business changes systems, adds entities, expands operations, or loses key staff. Management should reassess controls whenever significant changes occur.
Monitoring may include dashboards, evidence reviews, sample testing, exception analysis, and remediation tracking. Deficiencies should be prioritized based on risk, impact, fraud exposure, and compliance consequences.
A useful dashboard should track due and completed controls, late items, exceptions, owners, and remediation status. Completion rates alone are not enough if exceptions or missing evidence remain unresolved.
7. Common Mistakes
- Writing broad policies without assigning an owner, frequency, evidence requirement and reviewer.
- Treating segregation of duties as the entire control system instead of one part of a broader framework.
- Allowing the same person to create a vendor, change banking information and release payment without independent review.
- Relying on system reports without confirming that the report is complete, accurate and protected from unauthorized change.
- Collecting approvals but failing to investigate exceptions or document the resolution.
- Keeping controls unchanged after a system conversion, restructuring, acquisition or significant growth.
8. Practical Implementation Checklist
Work through these steps when building or reassessing the control program.
0 of 7 complete
How PNJ Can Help
PNJ helps businesses assess control risks, document processes, build practical risk-control matrices, strengthen close and reporting controls, evaluate segregation-of-duties conflicts, design compensating reviews and establish monitoring appropriate to the organization’s size and complexity.
Current Reference Points
- COSO — Internal Control—Integrated Framework
- NIST — Cybersecurity Framework 2.0: Small Business Quick Start Guide
- NIST — Multi-Factor Authentication guidance for small businesses
Disclaimer
This article is for general informational purposes only and does not constitute accounting, audit, tax, legal, regulatory or cybersecurity advice. It is not a Sarbanes-Oxley compliance program or an audit of internal control. Control design should be tailored to the organization’s facts, systems, risks and reporting obligations with qualified advisers.