How internal controls are operated and monitored, step by step

Control owners run each control as designed and keep proof that they did. A separate internal control team tests that proof, logs failures as deficiencies, and tracks each fix until the owner shows the control works again. Management signs off on the results, and auditors rely on the same evidence.

The steps in order

  1. Keep the control inventory current. The internal control team owns this register, working with process owners. Each entry names the risk, the owner, how often the control runs and what evidence should exist. Cycle memos or process narratives sit alongside it so anyone can see where the control fits in the flow.
  1. Build preventive rules into the systems. Finance systems staff configure what the software enforces on its own. Typical examples are budget checks that block spending beyond available funds, tolerances between order and invoice amounts, approval routing by value and user access that keeps incompatible duties apart.
  1. Perform the control. This falls to whoever sits closest to the transaction. An accounts payable supervisor matches invoices to orders and receipts, then holds anything that fails. A general ledger accountant reconciles cash in the ledger to the bank or treasury record. A payroll lead ties the payroll summary back to the books.
  1. Retain the evidence. The performer saves a signed or system-stamped record showing who did the work, when, and who reviewed it. Screenshots, reconciliation workpapers and approval trails all count. Without this record, a control that ran is treated as one that did not.
  1. Attest. At set points, each owner confirms in writing that their controls operated. This self-assessment is cheap to collect and easy to rubber-stamp, so it never replaces testing.
  1. Test independently. Someone outside the line of work, usually the internal control team or internal audit, picks samples and inspects the evidence. Where the evidence is thin, testers reperform the control themselves.
  1. Judge the exceptions. Testers sit down with the owner to decide whether an exception is a one-off or a real deficiency. The controller, and for serious cases the finance director, rates its severity. A gap in design is handled differently from a well-designed control that people skipped.
  1. Log and assign the fix. The deficiency goes into a tracking log with a named owner, a remediation plan and a target date. Vague owners such as "finance" are a warning sign.
  1. Remediate. The owner carries out the plan. That might mean redesigning the control, retraining staff, tightening a system setting or adding a review. Any misstatement the failure caused is corrected through an adjusting entry, documented and approved like any other journal.
  1. Retest before closing. Testers check enough fresh occurrences to show the repaired control now holds. Only then is the log item closed. Closing on the strength of a new procedure document alone is a common shortcut.
  1. Report and certify. The internal control lead summarises open and closed deficiencies for senior management and the audit committee. The finance director signs the assurance statement on that basis.
  1. Support the external audit. Finance staff answer the auditors' prepared-by-client requests, supplying samples, cycle memos and reconciliations. Audit findings feed straight back into step eight.
  1. Feed changes back. When a process, system or organisation changes, the inventory and the system rules are updated. This step is the one most often missed.

Where it tends to break

Evidence is the weak point. Controls are often performed but not recorded in a form a tester can use. The second weak point is the handoff between finding a deficiency and fixing it. Logs fill up with items whose owners have moved on or whose target dates keep sliding.

System rules also drift. Tolerances get widened to clear a backlog and are never narrowed again. Approval limits stay set for people who left long ago.

Questions to ask the people who run it

  • Which controls do you actually perform, and are any done by someone other than the named owner?
  • What do you keep as proof, and where would a tester find it?
  • When a control is skipped because of time pressure, what happens next?
  • Have any system tolerances or approval limits been changed informally?
  • Which exceptions do you clear without telling anyone?
  • Who decides that a deficiency is fixed, and do they retest it?
  • Are there workarounds, such as offline spreadsheets or manual overrides, that the documentation does not mention?
  • When the auditors ask for something, who scrambles to produce it, and why?
  • Which controls feel pointless to you, and which risks do you think nobody covers?

Before changing anything

Walk one real transaction through the process with the people who touch it. Compare what they do against the inventory and the cycle memo. Gaps between the two usually point to the controls that need redesign first, and they show which evidence auditors will struggle to find.

Sources

APQC's Process Classification Framework® (PCF) is an open standard developed by APQC, a nonprofit that promotes benchmarking and best practices worldwide. To download the full PCF or to view definitions and measures, please visit www.apqc.org/pcf.