Establishing internal controls, policies and procedures: the steps in order

Internal controls are built from the top down. The board sets oversight and the audit committee, leadership issues a code of ethics, and named owners take responsibility. Each process then gets objectives, risks and tolerances. Controls are designed and tested against those, and the findings are fixed.

The steps in order

  1. Constitute the board and its audit committee. The board chair and the company secretary or governance counsel do this. They draft a charter for the audit committee and decide which members are independent. They also decide who has financial expertise. The charter states what the committee oversees and who reports to it.
  1. Write and approve the code of ethics. The general counsel or ethics officer drafts it. The board approves it. The text covers conflicts of interest, gifts, data handling and how to report concerns without retaliation.
  1. Communicate the code and collect acknowledgements. Human resources distributes the approved code through onboarding and ongoing training. Every employee signs an acknowledgement. Managers handle questions from their own teams. A confidential reporting channel is opened and publicised at this point.
  1. Assign ownership of controls. The chief financial officer and the controller decide who owns what. Each business process gets a named process owner. Each control gets a named control owner. Internal audit is kept independent of both, so it can test without testing its own work. The assignments go into a responsibility matrix that the audit committee sees.
  1. Define objectives and risks for each process. Process owners lead this in workshops facilitated by the risk or internal control team. For purchasing, an objective might be that only approved suppliers are paid. The matching risk is a fictitious vendor slipping into the master file. Every objective is paired with what could stop it being met.
  1. Set risk tolerances by entity and unit. The chief financial officer proposes them and the audit committee approves. A tolerance might define how far an invoice can differ from its purchase order before payment stops. Smaller units with thinner staffing often receive different tolerances from headquarters.
  1. Design controls and write the policies. Control owners work with the controller's team. Each risk gets at least one preventive or detective control. The team writes the policy that requires the control and the procedure that explains how to perform it. They then prepare cycle memos that walk through each transaction flow from initiation to the ledger.
  1. Configure controls in the systems. System administrators and the finance systems team build approval limits and segregation of duties into the software. Where budgets apply, they set funds control rules that block or flag spending above authorised levels. Changes to these settings go through change management, never through direct edits.
  1. Test whether controls operate. Internal audit or a compliance function selects samples and checks the evidence. External auditors then send prepared-by-client requests. The controller's team answers them with the sample documentation, the cycle memos and the reconciliations.
  1. Remediate findings and report. Control owners fix the deficiencies. The controller documents and books any accounting adjustments the findings require. Internal audit reports status to the audit committee, which decides when an item can close. Policies are then revised to reflect what changed.

Where handoffs tend to fail

The gap between steps six and seven is the usual weak point. Tolerances get approved at board level but never reach the people configuring systems. The software then enforces whatever default the vendor shipped.

Ownership also drifts. Someone named in step four changes roles, and nobody updates the matrix. When auditors ask who performs a review, the answer is a person who left.

Cycle memos age quickly. A memo describing a manual approval is misleading once that approval moves into a workflow tool.

Questions to ask the people who run the process

Documented procedures and daily practice often diverge. These questions surface the difference.

  • When an approver is out, who signs instead, and is that delegation written down anywhere?
  • Which controls get performed in a batch just before the auditors arrive?
  • Have any system approval limits been raised informally to keep work moving?
  • What evidence is kept when a review finds nothing wrong?
  • Who actually decides whether an exception falls within tolerance?
  • Are there spreadsheets outside the main system that feed figures into the ledger?
  • When the code of ethics changed last, how did staff hear about it?
  • Which audit findings keep coming back after being closed?
  • Does anyone both create vendors and approve payments to them?
  • If a control failed tomorrow, how would the control owner find out?

Answers that hesitate, or that differ between people doing the same job, mark the places where the documented design and the real process have separated. Those are the controls to redesign first.

Sources

APQC's Process Classification Framework® (PCF) is an open standard developed by APQC, a nonprofit that promotes benchmarking and best practices worldwide. To download the full PCF or to view definitions and measures, please visit www.apqc.org/pcf.